ship’s manual · guide

Install on Windows + WSL

The Windows 11 implementation and real-host WSL lifecycle are accepted: each ordinary channel receives a separate private Ubuntu distribution rather than sharing one generic Linux service. The signed public installer ships with every release.

Implemented host contract

  • Native x64 Electron host with Squirrel update packaging.
  • Administrator approval once to enable and verify Microsoft's pinned WSL 2 runtime.
  • An immutable, SHA-256-pinned Canonical Ubuntu rootfs per resident world.
  • Windows-drive automount and Windows process interop disabled.
  • Exact installation/channel ownership checks for stop, deletion, and app removal.

The resident runs as UID/GID 1000 in /workspace. Durable 1Helm data remains outside the replaceable application directory.

Install

  1. Download the current Setup executable.
  2. Run the installer on Windows 11 x64.
  3. Open 1Helm and complete Captain → Providers → Workspace. Approve Microsoft’s pinned WSL 2 runtime once if requested.

Setup and update-feed artifacts are Authenticode-signed before publication — the release process fails closed without a valid signature. Updates arrive through the app’s update feed on the machine hosting 1Helm.