I "upgraded" to fedora 41 and liking it, I guess its my fav. In the hardening context my lynis index is 77 and iirc
@Vitali Ortzi mentioned Silverblue "
atomic" so I created a new VM running Silverblue41 and its immutable linux architecture and using Gnome DE. Less than 24 hours running Silverblue, even though it is "fedora" it seems a tad restrictive, at least at first. I'll keep it, but now thinking to return to fedora workstationand maybe install wazuh.
PS Chatgpt suggested firejail could also run in Silverblue to firejail firefox, but that suggestion did not work correctly, not saying it cannot be done, but it seemed like Silverblue architecture crushed firejail, and would not properly load firefox. So for now ended up uninstalling (ostree firejail) from Sillverblue. (or how many sandboxes do you need, apparently 1 less