Qubes OS

Invisible Things Labs Qubes OS is a security-focused desktop operating system that aims to provide security through isolation.

Templates provide a single, immutable root file system which can be shared by multiple qubes.

Second, shared templates can dramatically reduce storage requirements compared to separate VMs with a full operating install per secure domain.

Alternative community-supported templates include Whonix, Ubuntu, Arch Linux, CentOS, or Gentoo.

[18] As a desktop-focused operating system, Qubes OS targets personal computer hardware.

The base system requirements for Qubes OS are: Users interact with Qubes OS in much the same manner that they interact with any standard graphical desktop operating systems with some key differences: The Xen hypervisor provides strong isolation between its hosted virtual machines, called domains in Xen terminology.

The operating system hosts the user's graphical desktop and controls most hardware devices.

It launches the discrete app qubes and presents their applications on the desktop of dom0 as normal process windows.

Disk usage in dom0 is minimized by allowing multiple app qubes to share a common "template" root file system image maintained in read-only mode.

[26] Security and privacy experts such as Edward Snowden, Daniel J. Bernstein, and Christopher Soghoian have publicly praised the project.

My experience was greatly improved when I started thinking of Qubes as being multiple, separate computers which all just happened to share a display screen.

Security domains scheme