You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Follow-up to #34. Ubuntu and Debian users currently download a .deb, checksum manifest, signature, and public key before invoking the package manager. Provide a maintained signed APT repository so, after a documented one-time bootstrap, installation is sudo apt install loopwire and updates use normal APT commands.
Initial scope: Ubuntu 24.04 and Debian 13, amd64, using their existing separate native packages. Other releases and architectures remain outside this issue until separately tested. Keep the signed automatic installer available as a fallback.
Development implementation and evidence: #45. Production activation remains tracked by the Human operational tasks below.
Development tasks
Define the repository layout and configuration contract. Record separate Ubuntu/Debian suites, component and architecture paths, package-version ordering, retention policy, and required publishing variables/secrets. Use the existing recipes under packaging/deb/ and scripts/build-deb-package.sh.
Implement repository generation. Produce Packages indexes, package hashes, Release, and OpenPGP-signed InRelease metadata from the validated release .deb files. Preserve the exact tested package bytes. APT authenticates packages through signed repository metadata and hashes; an embedded .deb signature is not the acceptance criterion.
Implement safe publication and rollback. Stage a complete repository revision, upload immutable packages before exposing their indexes, and promote each suite without advertising missing files. Make repeated publication idempotent; retain the previous package set and provide rollback with valid signed metadata. Handle metadata cache invalidation if the host uses a CDN.
Integrate protected release automation. Add generation/signing/publication after the existing artifact checks, restrict publication to the intended release entrypoint, and fail on incomplete uploads or signing errors. Wire affected scripts/configuration into CI and provide a fixture/dry-run path requiring no production credentials.
Provide one-time APT bootstrap instructions/assets. Install the public key under /etc/apt/keyrings, reference it with Signed-By in the repository source, select the matching suite, and refresh indexes. Document the fingerprint, repeat-safe setup, repository removal, and key rotation; do not use apt-key or authentication-bypass options.
Add repository regression tests. Check suite/architecture selection, package checksums and version ordering. Prove that unsigned/tampered metadata, modified packages, and a wrong signing key are rejected; interrupted publication and retry must leave a usable repository.
Add matching-guest lifecycle tests. On clean Ubuntu 24.04 and Debian 13 guests, use the generated bootstrap and repository to test fresh install, reinstall, upgrade from an older published version, removal, and the documented rollback. Capture repository origin, installed version, GUI/provider smoke results, and commands/logs; local .deb installation alone is insufficient.
Update the user and maintainer documentation after public verification. Update both homepage platform tabs, the install guide, support matrix, release guide, and unreleased notes. Show bootstrap separately from sudo apt install loopwire, document updates/troubleshooting, and retain the automatic-installer fallback. Do not imply availability in Ubuntu/Debian's default repositories.
Human operational tasks
These require maintainer access to hosting, signing material, or GitHub settings. Development and fixture tests can proceed before production credentials are available.
Choose the public repository location and owner. Record the HTTPS base URL, hosting account, responsible maintainer, and storage/retention budget if applicable.
Provision the hosting resources. Set up the storage location, DNS/TLS where needed, staging/production separation, and an upload credential limited to the repository's storage scope. Confirm unauthenticated clients can fetch public repository files over HTTPS.
Provision the APT signing identity. Create or select the OpenPGP signing key, record its public fingerprint/expiry and recovery owner, and arrange private-key backup and rotation. The existing checksum-signing PEM is a different signing mechanism; commit only public material.
Configure the protected GitHub environment. Add the publisher's documented upload/signing secrets and public variables, set the intended release permissions, and verify the workflow can access them without exposing their values.
Complete the first production publication. Run the tested publication workflow, execute the lifecycle smoke against the public URL on both supported guests, and attach the workflow run, repository URL, public fingerprint, installed versions, and verification logs to this issue or its PR.
Done when: the public signed repository serves both supported suites; release publication is repeatable and recoverable; clean-guest lifecycle and tamper tests pass; and the homepage/docs match the verified public setup. Joining the old commands into one shell line does not meet this goal.
Follow-up to #34. Ubuntu and Debian users currently download a
.deb, checksum manifest, signature, and public key before invoking the package manager. Provide a maintained signed APT repository so, after a documented one-time bootstrap, installation issudo apt install loopwireand updates use normal APT commands.Initial scope: Ubuntu 24.04 and Debian 13, amd64, using their existing separate native packages. Other releases and architectures remain outside this issue until separately tested. Keep the signed automatic installer available as a fallback.
Development implementation and evidence: #45. Production activation remains tracked by the Human operational tasks below.
Development tasks
packaging/deb/andscripts/build-deb-package.sh.Packagesindexes, package hashes,Release, and OpenPGP-signedInReleasemetadata from the validated release.debfiles. Preserve the exact tested package bytes. APT authenticates packages through signed repository metadata and hashes; an embedded.debsignature is not the acceptance criterion./etc/apt/keyrings, reference it withSigned-Byin the repository source, select the matching suite, and refresh indexes. Document the fingerprint, repeat-safe setup, repository removal, and key rotation; do not useapt-keyor authentication-bypass options..debinstallation alone is insufficient.sudo apt install loopwire, document updates/troubleshooting, and retain the automatic-installer fallback. Do not imply availability in Ubuntu/Debian's default repositories.Human operational tasks
These require maintainer access to hosting, signing material, or GitHub settings. Development and fixture tests can proceed before production credentials are available.
Done when: the public signed repository serves both supported suites; release publication is repeatable and recoverable; clean-guest lifecycle and tamper tests pass; and the homepage/docs match the verified public setup. Joining the old commands into one shell line does not meet this goal.
Implementation references: APT archive authentication and repository-scoped Signed-By configuration. Related RPM channels: #36 and #37; reuse applicable publishing/test machinery without coupling distro releases.