Nothing to install, and nothing kept

Build a bootable OPNsense image for a Sophos XGS

The official OPNsense image, with the os-xgs-npu coprocessor driver and plugin already laid into it. Choose how it should boot, and this page opens the build request for you.

  1. 1 Configure You are here. Nothing has started.
  2. 2 Start it From here with a token, or by filing an issue.
  3. 3 Download the image It is kept for seven days, then it expires.
This image has not been booted on any appliance. Burn one and boot it before relying on it. The build runs on a GitHub runner, which has no Sophos hardware attached to it and never will. Nothing offered on this page has been tested on a device.
You are reading the original repository's page. A build only runs for the account that owns the repository, so pressing Build it here files a request that this repository answers with a refusal - which the page will show you within seconds rather than leave you waiting. Two ways round it, and the first is one press: open Fork and build in my account below and give it a token, and it forks this repository for you and builds there. Or fork it yourself, enable Actions on the fork, turn on Pages (Settings, then Pages, branch main, folder /docs), and use your fork's copy of this page. Either way it is your build, your artifact, your storage - the licence position, and CONTRIBUTING.md says why.

The image

what gets written to the disk

Downloaded from OPNsense's own mirror when the build runs, and its checksum verified against the release's own file. No part of an OPNsense image lives in this repository.

The console

the one choice that can lock you out

An XGS has no screen, so the serial port is the only way in. Get this wrong and the appliance boots perfectly into a console you cannot read. Neither value is safer in the abstract - match whatever your terminal is set to.

On an appliance with no video output the two behave the same. Leave it on serial only unless you have a reason.

The driver

fetched at build time, not stored here

Leave this as main unless you know why not. The source is placed in the image; a built module is not, because a module has to be compiled against the kernel the appliance is actually running.