Outcome
Publish supported amd64 and arm64 Debian packages through a signed APT repository for the desktop client and advanced headless server entrypoints.
Scope
Produce architecture-specific Debian packages from the canonical release artifacts.
Install the repository key through a dedicated keyring and use a signed-by source definition; never use deprecated global apt-key trust.
Separate desktop-client and headless remote-server packaging when that produces safer dependencies and clearer operator intent.
Do not bundle or silently install a container daemon; declare supported prerequisites and provide actionable checks.
Reuse [DIST-01] Define the cross-platform package-manager bootstrap contract #358 for Local Desktop, Connect to Remote Server, and advanced Host Remote Server behavior.
Make maintainer scripts minimal, idempotent, non-interactive-safe, and data-preserving.
Security and privacy requirements
Serve repository metadata and artifacts over TLS and verify signed Release/InRelease metadata plus package hashes.
Scope repository trust to the AncestryLLM source; do not add a globally trusted package key.
Do not open firewall ports, create public listeners, generate weak credentials, or select server mode during package installation.
Keep secrets out of package configuration, debconf output, process arguments, and logs.
Normal purge behavior must distinguish application files from encrypted user data and require explicit confirmation before destroying data.
Acceptance criteria
amd64 and arm64 packages install and upgrade on the supported Debian and Ubuntu matrix.
APT repository metadata is reproducible, signed for 1.0, and validated in release automation.
Repository onboarding uses a scoped keyring and signed-by source configuration.
Desktop and server package boundaries, dependencies, services, upgrade behavior, rollback, and removal are documented and tested.
No install path produces an unauthenticated listener or silently selects remote-server mode.
User, advanced-operator, release, privacy, and troubleshooting documentation is complete.
Dependencies
Depends on #132 , #355 , #356 , #358 , and the Linux container-runtime validation work.
Reference
Debian guidance for third-party repositories: https://wiki.debian.org/DebianRepository/UseThirdParty
Outcome
Publish supported amd64 and arm64 Debian packages through a signed APT repository for the desktop client and advanced headless server entrypoints.
Scope
Security and privacy requirements
Acceptance criteria
Dependencies
Depends on #132, #355, #356, #358, and the Linux container-runtime validation work.
Reference
Debian guidance for third-party repositories: https://wiki.debian.org/DebianRepository/UseThirdParty