/ Rescue

NixOS live system · opencode · Claude Code · Codex

A rescue stick
with an agent inside.

Boot it on the machine that will not start. The agent mounts the installed system read-only, reads the logs with you and asks before it changes anything. Your key goes into the image before it ever boots.

x86_64 · UEFI + BIOS · MIT

Three agents, one console

opencode, Claude Code and Codex are installed and briefed: where they are, how installed systems look from the outside, and the rules.

One key for all three

2342.ai speaks the OpenAI, Responses and Anthropic formats. Groq, Google AI Studio and OpenRouter work too, with free tiers.

Configured before first boot

Key, Wi-Fi, SSH key and keyboard layout go into a 16 KiB slot in the image, right here in your browser. Nothing is sent anywhere.

Every filesystem

ZFS, Btrfs, ext4, XFS, NTFS, LUKS, LVM, mdadm. rescue-mount finds the installed system and mounts it read-only first.

Your phone as second screen

Enter a key or finish a Claude or Codex sign-in by scanning a QR code. Follow the console in your phone's browser.

Careful by default

Read-only first. Destructive commands only after an explicit yes. A backup of every file before it is edited.

Get your rescue stick

Three steps. Your key stays in this browser tab and in the file you save.

1

Choose an AI provider

Wi-Fi, SSH, keyboard (optional)
2

Download the image

3

Write your settings into the image

When the download has finished, drop the ISO here. The page finds the configuration slot and saves a copy with your key inside. Takes seconds, nothing is uploaded.

Prefer the command line?

Then write the ISO to a USB stick with dd, balenaEtcher, Rufus or Ventoy, and boot it. Whoever holds the stick holds the key: create a key just for the stick and give it a budget.

What happens at boot

  1. Console, not desktop. kmscon with a real font and truecolor, tmux underneath, a menu on top. A second boot entry without modesetting for difficult GPUs.
  2. Your settings apply. Keys become environment variables and agent configuration, Wi-Fi connects, your SSH key is authorized.
  3. Find the patient. rescue-mount unlocks LUKS, assembles LVM and RAID, imports ZFS pools and mounts the installed system read-only at /mnt.
  4. Talk it through. opencode, claude or codex. The agent reads logs, explains, proposes. Repairs run in a chroot, after your yes.

No key in the image? Press C-Space k at the console and type it on your phone via QR code. Claude and Codex subscribers sign in the same way.

Providers

ProvideropencodeClaude CodeCodexFree tier
2342.ai recommended●●●–
Groq●●
Google AI Studio●●
OpenRouter●●
OpenCode Zen●●
Anthropic●●–
OpenAI●●–

Claude Code and Codex also accept their own subscription sign-in at the console.

Build it yourself

One Nix flake. Build the image, patch the slot, or bake your configuration in at build time.

nix build github:2342-ai/agentic-rescue#iso
nix run github:2342-ai/agentic-rescue#patch -- result/iso/*.iso \
  --provider groq --key gsk_… --wifi "Home" "secret" -o my-rescue.iso