Options include:
- Installing them through
brew
; this is setup, enabled and configured correctly by default on uBlue projects like Aurora, Bazzite and Bluefin. - Installing them within a container; be it though Toolbx or Distrobox. This is what Fedora Atomic initially intended (and probably still does).
- Some users got a lot of mileage from utilizing
nix
to this effect. - If all else fails (or if you outright prefer it this way), you can always layer it through
rpm-ostree
.
I daily drive secureblue.
Long story short; I love me some security. Unfortunately, My device is far from ideal for running Qubes OS. From within the remaining options, secureblue comes out on top for me.