Maintain once, roll out everywhere
One well-kept golden image is enough. ThinForge brings it to every thin client and then keeps it current with signed, incremental delta updates.
Golden-image management for Linux thin clients
You set up Linux once, exactly the way your organisation needs it. ThinForge captures that state as a golden image, rolls it out to every thin client over network boot and then keeps it current with signed delta updates — on your own network, with no vendor cloud. The entire source code is open.
Unedited screenshots from a running installation. Click to enlarge.








Three things that make the difference day to day.
Distribution, software, configuration — every choice is yours. No locked vendor stack, no artificial limits, no cloud you depend on. And because ThinForge is open source, you can read exactly what the software does at any time.
One well-kept golden image is enough. ThinForge brings it to every thin client and then keeps it current with signed, incremental delta updates.
Applications run natively on the hardware — without the latency of a streaming solution and without a server farm in the background. Printers, USB devices and local peripherals just work, because they really are attached locally.
The golden-image principle comes from VDI — ThinForge takes it out of the data centre and puts it straight onto the endpoints.
One administrator maintains one master image, and everyone gets the same clean state. Only without render servers, without session brokers and without a data centre that has to keep running.
You pick the distribution, install exactly the programs your people need, and set up the desktop, printers, browser profiles, VDI clients or line-of-business software to suit your environment.
There is no prescribed software catalogue, no locked system image and no vendor cloud. The full breadth of the Linux ecosystem is open to you.
Set up Linux on a master device exactly the way your people need it — drivers, printers and line-of-business software included.
Store the finished state as a golden image on the ThinForge server. Every capture gets its own version in the tree.
Over network boot, multicast and BitTorrent to dozens of devices at once — without the server becoming the bottleneck.
Later changes go out as a signed delta only. The previous snapshot stays in the boot menu as a rollback entry.
ThinForge runs as a Docker stack on a server inside your LAN — with two separate network interfaces: one for browser-based administration, one for the thin clients. Home workplaces join over the ThinVPN service; the VPN technology behind it is NetBird, the open-source platform from the German company of the same name. Your server builds that tunnel itself, from inside the LAN. Nothing has to be opened to the outside.
On the left your LAN with the admin browser, the ThinForge server (management and client interface) and the thin clients · in the middle your firewall · on the right the NetBird-based ThinVPN relay service with attached home workplaces. The green strand is the only way out — and it is built from the inside.
Inventory, rollout and remote access in one interface. No vendor cloud, no third-party accounts, no telemetry — and because the source is open, you do not have to take our word for it.
Network boot, multicast and a built-in BitTorrent seeder with tracker distribute the golden image to dozens of devices in parallel. The server stays a distributor, not a bottleneck.
Instead of re-cloning every device, ThinForge ships only the changes made to the master. The previous state is kept as a snapshot — the rollback sits right in the boot menu.
Live inventory with status, online check, hardware detection and CSV import/export. Group and filter devices however you need.
Direct access to any client from the browser — screen and command line, without plugins and without extra software on the admin PC.
Connected over the ThinVPN service (ZTNA built on NetBird). The ThinForge server distributes configuration and keys centrally.
Build, version and roll out images directly on the server — with a version tree and snapshot history. Packages, drivers and line-of-business software stay under your control.
ThinForge relies throughout on established open protocols and formats — and is itself entirely open source. Nothing about it ties you to a vendor.
| Building block | Area | What it is used for |
|---|---|---|
| WireGuard | Network | Lean, audited VPN tunnel between sites and clients. |
| NetBird | Network | Open-source VPN platform from the German company NetBird — the basis of the ThinVPN service (ZTNA over WireGuard). |
| btrfs | Filesystem | Subvolumes, snapshots and atomic delta updates right in the filesystem. |
| Ed25519 | Cryptography | Compact, fast signatures for every update delta and every agent update. |
| Argon2id | Cryptography | Memory-hard password hashing following current OWASP recommendations. |
| Syft + Grype | Security | Built-in vulnerability scanner: produces software bills of materials (SBOM) and checks every container of the stack against known CVEs. |
| PXE / iPXE | Boot | Standardised network boot — compatible with any modern thin-client hardware. |
| GRUB | Boot | After every update the previous snapshot stays in the boot menu as a rollback entry. |
| Clonezilla · Partclone | Cloning | Clonezilla Live boots the clients over PXE, Partclone transfers the filesystems block by block. |
| EZIO · BitTorrent | Distribution | Peer-to-peer rollout with a built-in tracker and seeder — many clients at once, without the server becoming the bottleneck. |
| Docker Compose | Operations | The server stack as a readable Compose file — available as a pre-installed appliance or set up together with you. |
| Apache Guacamole | Remote | Remote desktop to the clients right in the browser — with no software on the admin PC. |
ThinForge itself costs nothing: the source code is open, and the software manages any number of thin clients — no licence file, no upper limit. If you want ongoing support, book maintenance at € 4.50 per thin client per month. If a client should also be connected over VPN, € 6.00 per VPN client per month is added for the hosted ThinVPN service — so a connected client costs € 10.50 per month.
Care for your installation: updates of the server components, security patches and our help when a rollout gets stuck. Applies to every connected thin client.
Secure access built on NetBird (WireGuard, open source) — without any open ports. Added on top of maintenance, per client with VPN. Bandwidth and traffic per site are handled by profiles A through D.
Number of thin clients under a maintenance contract.
Share of devices connected over VPN (at most the total number of devices).
Final prices · billed annually. VPN is booked per site as a profile (base fee = profile capacity × € 6) — the calculator assumes € 6 per active VPN client and leaves out setup fees and additional traffic. The setup workshop is charged once on top.
Pick a profile per remote site or home-office bundle — client capacity, monthly base fee and included traffic are fixed. Additional traffic is billed transparently.
| Profile | Up to clients | One-time setup | Base fee / month | Included traffic | Additional traffic |
|---|---|---|---|---|---|
| A · Small Office | 25 | € 180 | € 150 | 30 GB | € 0.80 / GB |
| B · Standard Branch | 50 | € 180 | € 300 | 55 GB | € 0.70 / GB |
| C · Business | 150 | € 300 | € 900 | 165 GB | € 0.70 / GB |
| D · Mid-Range | 350 | € 420 | € 2,100 | 385 GB | € 0.60 / GB |
| E · Enterprise | > 350 | on request — dedicated VPN endpoints, individual SLA | |||
Roughly 5 GB of traffic is accounted for per 50 clients. Bandwidth demand e.g. for Citrix or Horizon ≈ 5 Mbit/s per active client. The profiles are independent of thin-client maintenance — maintenance still applies per device (€ 4.50 / month).
Multiple sites, higher bandwidths, dedicated VPN endpoints, individual SLA. We tailor the profile to your infrastructure — beyond the standard profiles.
Six hours of joint work: install ThinForge on your server, set up the network and PXE, build the first golden image together.
Annual renewal. Devices can be added at any time — billing is pro-rated.
The entire source code is public at git.thinforge.org. The software stays open and usable, even if one day we are no longer around.
All prices stated are final prices.
We'll show you ThinForge live in a real golden-image rollout. Half an hour is enough — afterwards you'll know whether it fits your environment.