Atomic vs traditional Linux: what changes, what doesn’t
Atomic (immutable) Linux updates the whole OS as one image you can roll back. How updates, apps, and rollbacks differ from a traditional distro.
An atomic Linux distro installs and updates the core operating system as one complete, read-only image, instead of upgrading hundreds of packages one by one. Each update becomes a new version of the system that you boot into, and the previous version stays available so you can roll back. You still install apps, change settings, and keep your files as usual; what changes is how the base system is updated and where apps live.
Atomic distros are often called "immutable", although that word oversells it: parts of the system remain writable. This guide uses Fedora Silverblue as the main example, because its documentation describes the model clearly, and explains where NixOS fits.
How a traditional distro updates
On a traditional distro such as Fedora Workstation or Ubuntu, the package manager (DNF or APT) replaces files on the running system package by package. This is flexible and fast, and it works well almost all the time.
The weak point is the update itself. If it is interrupted, or if two packages conflict, the system can end up in a half-updated state. Undoing a bad update means downgrading individual packages or restoring a backup or snapshot, if you set one up beforehand.
How an atomic distro updates
On Fedora Silverblue, the operating system under / is deployed as an image by ostree, and /usr is mounted read-only. According to the Silverblue documentation, updates download in the background, and you start using the new version by rebooting. Nothing gets installed during that reboot, because the new deployment is already prepared.
From the terminal, the same thing is done with rpm-ostree upgrade, and rpm-ostree status lists the deployments on your machine. Major version upgrades (for example from Fedora 43 to 44) use rpm-ostree rebase and work the same way: the new system is prepared next to the old one, and you boot into it when it is ready.
The practical result is that an update either applies completely or not at all. A power cut halfway through a download leaves you on your current, working system.
Where apps go on an atomic desktop
Because the base system is read-only, software is installed in three main ways. The Silverblue documentation recommends:
- Flatpak for graphical apps, usually from Flathub. This is the main way to install apps.
- Toolbox containers for command-line and development tools. Inside a toolbox you can use dnf install as on a normal Fedora system, without touching the base OS.
- Package layering with rpm-ostree install for things that must be part of the system, such as drivers, virtualization (libvirt), or an alternative shell.
Layering creates a new deployment and needs a reboot, unless you add --apply-live. The documentation says to use it sparingly. Layering everything brings back much of the complexity that atomic systems are designed to avoid.
Before switching, check how your essential tools are delivered. VPN clients, printer drivers, proprietary GPU drivers, and specialist software are the usual friction points. Some atomic distros, such as Bazzite, ship common drivers in the image so you do not have to layer them.
Rollback: what it undoes and what it doesn’t
Silverblue offers two kinds of rollback, according to its documentation:
- Temporary: reboot and choose the previous version in the boot menu.
- Permanent: run rpm-ostree rollback to make the previous deployment the default.
By default only the two most recent deployments are kept. To keep a version you know works, pin it with sudo ostree admin pin followed by its index number from rpm-ostree status -v.
Rollback changes the operating system image, not your data. Your home folder lives under /var/home, and /var and /etc are writable and are not part of the image. Flatpak apps and files in your home folder stay as they are when you roll back. So rollback is a safety net for bad updates, not a backup: keep separate backups of your files.
Where NixOS fits
NixOS reaches a similar result in a different way. You describe the whole system (packages, services, and settings) in configuration files, and nixos-rebuild switch builds a new system generation from them. According to the NixOS manual, every change adds a new entry to the boot menu, and nixos-rebuild switch --rollback returns to the previous generation.
This is closer to infrastructure-as-code than to Silverblue's image model: it is very reproducible, but you have to learn the Nix language to make changes. Our Fedora Silverblue vs NixOS comparison sets the two side by side.
Should you use an atomic distro?
An atomic distro is a good fit if you mainly use graphical apps that are available on Flathub, want updates that cannot leave you half-upgraded, or manage computers for family members who will never open a terminal. It is also popular for gaming PCs and handhelds.
A traditional distro is still the easier choice if you rely on software that ships only as native packages, install kernel modules or custom drivers often, or follow guides that assume you can edit system files directly.
Browse every option in our best immutable and atomic Linux distros, or compare the two Fedora editions directly in Fedora Workstation vs Fedora Silverblue. New to Linux? Start with how to choose your first Linux distro.