Platform Notes
The desktop workflow depends on which operating system hosts the browser and which environment runs STATIC. These notes distinguish the managed paths described by the existing app guide from the self-hosted instructions.
Windows
The app’s managed WSL2 distribution is named 404. Windows owns the browser, host trust, and proxy settings; STATIC and the optional Linux packet program run inside the distro. Importing the CLI distro named 404-cli is unnecessary for the managed path. Windows must trust the public CA generated by its running STATIC instance.
Windows host boot path
The documented sequence is:
- Fetch a signed distro manifest and verify it using the app’s embedded public key.
- Download the referenced archive and verify its hash against the signed manifest.
- Import or update the
404WSL2 distribution. - Write runtime configuration, the Windows username, and a control token.
- Start STATIC and check the authenticated local API.
- Install host CA trust and enable routing when requested.
The archive is an Alpine userspace root filesystem containing /opt/404/static, ttl_editor.o, 404-init.sh, and version metadata. It does not contain a custom kernel. The fallback launcher in the distribution starts STATIC explicitly; entering the distro shell alone does not start it. See Distribution anatomy, eBPF packet path, and Build and release.
macOS
The documented app uses a native STATIC process rather than WSL2. The app handles local trust and proxy routing; the macOS operator bundle’s STATIC configuration uses the platform keyring backend for its private CA key. A keychain item holding a secret and a keychain trust entry for the public CA are different things. See CA and trust for that boundary and the macOS CLI guide for the manual path.
Linux
The old desktop page does not provide a complete Linux app installation or host-integration procedure. The current public pricing page contains inconsistent platform statements, so check the actual download and installed build for Linux desktop availability. The Linux CLI guide covers the source-supported path for running STATIC directly, configuring trust, and routing a browser. Linux packet shaping is a separate eBPF deployment.