Skip to content

FAQ

Frequently asked questions

Everything you need to know about VelaOS.

Getting started

What hardware do I need?

Any UEFI x86-64-v2 thin client, mini-PC or desktop with ≥ 4 GB RAM and ≥ 32 GB storage. No specific model is required or certified. TPM 2.0 is needed for TPM-sealed disk encryption, and Secure Boot must be enabled.

How do I install VelaOS?

Write the installer ISO to an 8 GB+ USB stick with Rufus (Windows) or dd (macOS/Linux), plug it into the target device, and boot. An unattended kickstart partitions with LUKS2 + TPM sealing, installs the minimal base, runs bootc switch to the signed VelaOS image, and reboots.

What is a VelaOS Code?

A 7-character string that identifies your tenant. When you sign up you get one unique code per org. On device first boot the screen shows a rotating device-side code; you enter both in the console's Devices → Pending screen to enrol the device into your fleet. No certificates to pre-stage, no TLS fingerprints to copy.

Is VelaOS ready for production?

VelaOS is in public beta. Start with test devices, and expect changes before general availability.

Do I need to install anything on my computer?

No. The VelaOS Console runs entirely in your browser. Nothing to install on your admin machine.

VDI + browsers

Which VDI platforms does VelaOS support?

Azure Virtual Desktop, Citrix Workspace, Microsoft RDP (classic), Omnissa Horizon and Windows 365. Each ships as a separately-subscribed VelaApp — you enable them per tenant through policy. Teams optimisation packs (HDX, AVD) slot in alongside.

Can I use VelaOS as a browser kiosk?

Yes. Set a policy to point to a managed Chrome, Edge, or Firefox ESR VelaApp and specify the URL. The device boots straight to a locked-down browser on your chosen page. You can use it for check-in screens, dashboards, digital signage, and POS terminals.

Does VelaOS support dual monitors?

Yes, as far as the device's graphics hardware allows. Policy controls whether monitors extend or mirror.

What about webcams, smart cards, and headsets?

USB webcams, headsets and smart-card readers (including CAC and PIV cards) work out of the box. USB sticks and external drives are blocked unless your policy allows them. VDI clients can pass cameras and smart cards through to the remote session. See peripheral compatibility.

Management

How do I push apps to devices?

Through the Vela Catalog in the console. Subscribe to a VelaApp (for example AVD, Chrome, Citrix, Edge, Firefox ESR, Horizon, Windows 365), scope it to device groups or smart labels, and the agent pulls the cosign-signed OCI image on the next policy tick.

How do OS updates work?

bootc A/B deployments with Greenboot health gating. You pick a ring (canary 5% → pilot 20% → broad 100%), the rollout engine pushes the new image to A/B slot B, Greenboot runs 10 required health checks on first boot, and a failed check rolls the device back to the previous slot on its own.

Can I reboot or wipe a device remotely?

Yes. Reboot, shutdown, log collection and screenshots — all from the console. Factory reset is not available for Linux devices yet. Destructive actions ask you to confirm first, and each one lands in the audit log.

What happens if a device goes offline?

Agents send a heartbeat every 60 seconds. Missing heartbeats for 5 minutes marks the device offline in the console; it keeps running its cached policy + app subscriptions, and reconnects automatically when the network returns. LUKS unlock works offline because the key seals to the TPM, not to a cloud call.

Can I group devices by location or department?

Yes. Hierarchical groups (Hospital → Emergency department → nursing stations) each carry their own policy, which the tri-state resolver walks from leaf to root. Plus smart groups that select devices by their labels, for rules like tag=lab AND site=north AND os IN (26.04, 26.04.1).

Security

Is VelaOS secure?

The base image locks the kernel against tampering, enforces SELinux, only runs software the image trusts, blocks all inbound network connections, blocks unknown USB devices, and encrypts the disk with a key sealed to the TPM on devices with TPM 2.0. Health checks after every reboot roll back a bad update. Every control is built into the image, so it survives every update. VelaOS holds no security certification today; see the security model for what ships and what is pending.

How does enrolment security work?

On first boot the device posts its public key and a short VelaOS Code to the cloud over HTTPS, and an admin approves it in the console. MQTT (port 8883) runs over TLS, and sensitive commands are ed25519-signed and checked on the device. Per-device broker credentials are built but not active yet.

Is my data isolated from other customers?

Yes. Row-level security keeps each organisation's devices, policies and audit trail separate.

Pricing + comparison

How much does VelaOS cost?

Community is free for up to 3 devices. Flex is $2.40 per device per month, billed monthly. Committed Annual is $2.00 (17% less than Flex), with a further 2% off when paid annually. Enterprise 3-year is $1.70 and Enterprise 5-year is $1.50.

How does VelaOS compare with other thin-client operating systems?

We don't publish claims about other vendors. What VelaOS offers: an immutable image with signed updates and automatic rollback, apps that install separately as signed packages, and per-device prices on the pricing page.

Can I try before I buy?

Yes. Community is free for up to 3 devices. No card needed, no sales call.