NikOS

Light system · Heavy thinking

An AI workstation, assembled on the machine you already have.

NikOS is an Ansible playbook that takes an Ubuntu LTS install and turns it into a local-first AI development workstation — Xfce on top, Ollama and a conda AI environment underneath, and the developer tooling that usually takes an afternoon to assemble.

NikOS logo
It is a playbook, not an ISO. There is nothing to burn and nothing to reinstall. You run it against a working Ubuntu 22.04, 24.04 or 26.04 system and it converges that system to a defined state. Run it twice and the second run changes almost nothing.
A NikOS desktop: the Xfce panel across the top with a browser and a terminal open, and the NikOS logo wallpaper on the Nord dark background.
A finished install — Xfce with the Nord palette, the generated wallpaper, and the panel NikOS configures.

What it actually does to the machine

Worth reading before you run it, because some of this is not cosmetic.

ChangeWhat that means
Switches the display manager GDM3 is disabled and LightDM takes over display-manager.service. On an Ubuntu host this needs a reboot to take effect. GDM3 is disabled, not removed.
Changes your default session The account's session is set to Xubuntu (Xfce). GNOME stays installed and selectable from the greeter unless you set nikos_remove_gnome: true.
Installs the Xubuntu desktop xubuntu-desktop-minimal by default, with the Xubuntu greeter and artwork. xubuntu-full and bare xfce are the other options.
Applies a Nord theme GTK theme, icons, a generated wallpaper, GRUB theme and a Plymouth boot splash. The splash is GPL-3.0-or-later, being derived from Xubuntu's theme; everything else is MIT.
Adds apt repositories GitHub CLI and Microsoft (VS Code), each with its own keyring. Each signing key is checked against a pinned fingerprint before apt trusts it. Node is not installed from apt - see below.
Provides Node without touching apt Two CLIs are published only through npm. Rather than replacing the distribution's Node - which would remove npm, eslint, webpack and a dozen Debian node-* packages - NikOS uses your Node when it is new enough, and otherwise installs a pinned one under your home with nvm.
Installs Ollama From its pinned, sha256-checked release archive (not a piped install script). Runs as a system service on 127.0.0.1:11434 and pulls one model by default (qwen3.5:4b, 3.4 GB). Nothing else is downloaded unless you ask for it. On an NVIDIA GPU with no driver loaded, Ubuntu's ubuntu-drivers install adds one (turn off with nikos_nvidia_drivers: false).
Creates a conda environment Miniforge under ~/.local/share/nikos-adjacent paths, with a nikos-ai environment holding PyTorch (CPU), the LangChain and LlamaIndex stacks, and an image analysis stack.
Clones tools into ~/.local/share/nikos-tools distrodeck, image-view, git-lantern and ai-runner are built or installed from source, each at a pinned release tag.
Installs only from verified sources Every download is pinned to a version and checked against a sha256, every apt key against a fingerprint, every npm/pip/go install to an exact version. The pins live in one file, vars/versions.yml. nikos update treats them as minimums and never downgrades something newer you installed yourself.
Themes your browsers Firefox gets the built-in Dark theme and a userChrome.css that paints the window in the desktop colour, with the open tab in the NikOS accent; Chromium and Google Chrome a dark theme seeded with that accent. Only existing profiles, and your own lines in those files are kept. Off with nikos_firefox_dark: false / nikos_chromium_dark: false.

Everything it does is in the roles, in plain YAML, in the repository. If a line above matters to you, you can read the task that performs it.

Companion tools

Distrodeck

Portable Linux workstation management.

IsoForge

Linux image download and USB flashing.

ai-runner

Archive landing page for a local Ollama runner.

KioskFrame

Photo-frame and dashboard appliance.

How it works

Install flow: the installer resolves a version, syncs a checkout, then runs Ansible against the local machine install.sh curl or checkout resolve version latest tag / --ref / --dev sync checkout fetch, switch, submodules ansible-playbook 27 roles against localhost --dev skips the sync entirely
The installer picks a version, brings a persistent checkout to it, then hands off to Ansible. --dev runs the checkout you launched it from instead.

What it is for

Running models locally

Ollama with model groups you opt into by capability — reasoning, coding, text, vision, embeddings. The default model, qwen3.5:4b, is 3.4 GB and runs on an 8 GB laptop.

Building on top of them

A conda environment with PyTorch, LangChain, LlamaIndex, Chroma, Qdrant and sentence-transformers, plus llama.cpp for direct inference.

Image analysis

OpenCV, Pillow, scikit-image, timm and Tesseract OCR in the same environment, alongside vision models that read documents and images.

Ordinary development

VS Code, the GitHub CLI, Node, Rust and Go toolchains, and optional bundles for Postgres, Redis, Kubernetes tooling, Podman and more.

The constraint it is built around

A 250 MB idle RAM target. Xfce rather than GNOME, an idle Ollama service that holds no model in memory, and every heavyweight component opt-in. Models load when you call them and unload afterwards, so a 19 GB model on disk costs nothing while you are not using it.

That target is also why the optional bundles exist rather than a single "install everything" default. A base install pulls one model. The rest is yours to choose.

Requirements