Skip to content

Provide a signed APT repository for one-command native installation #35

Description

@dskvr

Follow-up to #34. Ubuntu and Debian users currently download a .deb, checksum manifest, signature, and public key before invoking the package manager. Provide a maintained signed APT repository so, after a documented one-time bootstrap, installation is sudo apt install loopwire and updates use normal APT commands.

Initial scope: Ubuntu 24.04 and Debian 13, amd64, using their existing separate native packages. Other releases and architectures remain outside this issue until separately tested. Keep the signed automatic installer available as a fallback.

Development implementation and evidence: #45. Production activation remains tracked by the Human operational tasks below.

Development tasks

  • Define the repository layout and configuration contract. Record separate Ubuntu/Debian suites, component and architecture paths, package-version ordering, retention policy, and required publishing variables/secrets. Use the existing recipes under packaging/deb/ and scripts/build-deb-package.sh.
  • Implement repository generation. Produce Packages indexes, package hashes, Release, and OpenPGP-signed InRelease metadata from the validated release .deb files. Preserve the exact tested package bytes. APT authenticates packages through signed repository metadata and hashes; an embedded .deb signature is not the acceptance criterion.
  • Implement safe publication and rollback. Stage a complete repository revision, upload immutable packages before exposing their indexes, and promote each suite without advertising missing files. Make repeated publication idempotent; retain the previous package set and provide rollback with valid signed metadata. Handle metadata cache invalidation if the host uses a CDN.
  • Integrate protected release automation. Add generation/signing/publication after the existing artifact checks, restrict publication to the intended release entrypoint, and fail on incomplete uploads or signing errors. Wire affected scripts/configuration into CI and provide a fixture/dry-run path requiring no production credentials.
  • Provide one-time APT bootstrap instructions/assets. Install the public key under /etc/apt/keyrings, reference it with Signed-By in the repository source, select the matching suite, and refresh indexes. Document the fingerprint, repeat-safe setup, repository removal, and key rotation; do not use apt-key or authentication-bypass options.
  • Add repository regression tests. Check suite/architecture selection, package checksums and version ordering. Prove that unsigned/tampered metadata, modified packages, and a wrong signing key are rejected; interrupted publication and retry must leave a usable repository.
  • Add matching-guest lifecycle tests. On clean Ubuntu 24.04 and Debian 13 guests, use the generated bootstrap and repository to test fresh install, reinstall, upgrade from an older published version, removal, and the documented rollback. Capture repository origin, installed version, GUI/provider smoke results, and commands/logs; local .deb installation alone is insufficient.
  • Update the user and maintainer documentation after public verification. Update both homepage platform tabs, the install guide, support matrix, release guide, and unreleased notes. Show bootstrap separately from sudo apt install loopwire, document updates/troubleshooting, and retain the automatic-installer fallback. Do not imply availability in Ubuntu/Debian's default repositories.

Human operational tasks

These require maintainer access to hosting, signing material, or GitHub settings. Development and fixture tests can proceed before production credentials are available.

  • Choose the public repository location and owner. Record the HTTPS base URL, hosting account, responsible maintainer, and storage/retention budget if applicable.
  • Provision the hosting resources. Set up the storage location, DNS/TLS where needed, staging/production separation, and an upload credential limited to the repository's storage scope. Confirm unauthenticated clients can fetch public repository files over HTTPS.
  • Provision the APT signing identity. Create or select the OpenPGP signing key, record its public fingerprint/expiry and recovery owner, and arrange private-key backup and rotation. The existing checksum-signing PEM is a different signing mechanism; commit only public material.
  • Configure the protected GitHub environment. Add the publisher's documented upload/signing secrets and public variables, set the intended release permissions, and verify the workflow can access them without exposing their values.
  • Complete the first production publication. Run the tested publication workflow, execute the lifecycle smoke against the public URL on both supported guests, and attach the workflow run, repository URL, public fingerprint, installed versions, and verification logs to this issue or its PR.

Done when: the public signed repository serves both supported suites; release publication is repeatable and recoverable; clean-guest lifecycle and tamper tests pass; and the homepage/docs match the verified public setup. Joining the old commands into one shell line does not meet this goal.

Implementation references: APT archive authentication and repository-scoped Signed-By configuration. Related RPM channels: #36 and #37; reuse applicable publishing/test machinery without coupling distro releases.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions