Skip to content

Instantly share code, notes, and snippets.

@ravengraves
Created September 25, 2026 05:02
Show Gist options
  • Select an option

  • Save ravengraves/952b41d31c312864f663d792a0116993 to your computer and use it in GitHub Desktop.

Select an option

Save ravengraves/952b41d31c312864f663d792a0116993 to your computer and use it in GitHub Desktop.

installing Parabola GNU/Linux-libre with encryption

Partitioning

First, find your disk

fdisk -l

Now, modify your disk. Set it as MBR, set a boot partition.

fdisk /dev/sdX
g
p
n (*new partition*)
2048?
+1G
t
ef # efi*)
a # bootable*)

n # main partition*)

+200G
w # write

Now, enable LUKS

cryptsetup luksFormat /dev/sdX2
YES

Unlock the drive

cryptsetup open /dev/sdX2 cryptroot

Format the partitions (if not already done)

mkfs.ext4 /dev/mapper/cryptroot
mkfs.vfat -F32 /dev/sda1

Mount the partitions

mount /dev/mapper/cryptroot /mnt
mkdir -p /mnt/boot
mount /dev/sdX1 /mnt/boot

Configuring the install disk

sudo pacman --needed -Syy archlinux-keyring parabola-keyring

Next, edit the /etc/pacman.conf. Uncomment the [nonsystemd] block.

(if you get key signature errors, you can set SigLevel = Never and LocalFileSigLevel = Never)

Installing parabola

pacstrap /mnt base libelogind udev-init-scripts
pacstrap /mnt linux-libre-lts # or other kernel: linux-libre
pacstrap /mnt openrc-init eudev networkmanager networkmanager-openrc grub syslinux linux-libre-firmware cryptsetup cryptsetup-openrc efibootmgr
pacstrap /mnt  xorg-server xorg-xinit xf86-input-synaptics xorg-drivers alsa-utils alsa-utils-openrc wpa_supplicant wpa_supplicant-openrc dialog usbutils dnsutils nano

Configuring the install

generate the fs table

genfstab -U /mnt >> /mnt/etc/fstab

Enter the container, mapping firmware files, etc.

arch-chroot /mnt

Add the following to /etc/hosts:

127.0.0.1   localhost
::1     localhost
127.0.1.1   <MY_HOSTNAME>.localdomain <myhostname>

Add the following to /etc/conf.d/hostname

hostname="<MY_HOSTNAME>"

Symlink /etc/localtime to /usr/share/zoneinfo/Zone/SubZone. Replace Zone and Subzone to your liking. For example:

ln -sf /usr/share/zoneinfo/America/Chicago /etc/localtime

Add encryption to /etc/mkinitcpio.conf

HOOKS=(<...> encrypt)

Generate the ramdisk

mkinitcpio -p linux-libre-lts # or linux-libre

Modify grub to unlock and boot your partition

blkid /dev/sda2 >> /etc/default/grub

/etc/default/grub:

GRUB_CMDLINE_LINUX_DEFAULT="quiet cryptdevice=UUID=<your-uuid>:cryptroot root=/dev/mapper/cryptroot"

Install grub

# mbr
grub-install --target=i386-pc --boot-directory=/boot </dev/sdX>
# gpt
grub-install --target=x86_64-efi --efi-directory=/boot/EFI --bootloader-id=parabola
grub-mkconfig -o /boot/grub/grub.cfg

Add opendns nameservers to /etc/resolv.conf:

nameserver 208.67.222.222
nameserver 208.67.220.220

and add them to /etc/NetworkManager/conf.d/dns-servers.conf:

[global-dns-domain-*]
servers=::1,127.0.0.1,208.67.222.222,208.67.220.220

Change root password

passwd

Create user


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment