Skip to content

[DIST-05] Publish the Debian and Ubuntu APT repository #362

Description

@sodejm

Outcome

Publish supported amd64 and arm64 Debian packages through a signed APT repository for the desktop client and advanced headless server entrypoints.

Scope

  • Produce architecture-specific Debian packages from the canonical release artifacts.
  • Install the repository key through a dedicated keyring and use a signed-by source definition; never use deprecated global apt-key trust.
  • Separate desktop-client and headless remote-server packaging when that produces safer dependencies and clearer operator intent.
  • Do not bundle or silently install a container daemon; declare supported prerequisites and provide actionable checks.
  • Reuse [DIST-01] Define the cross-platform package-manager bootstrap contract #358 for Local Desktop, Connect to Remote Server, and advanced Host Remote Server behavior.
  • Make maintainer scripts minimal, idempotent, non-interactive-safe, and data-preserving.

Security and privacy requirements

  • Serve repository metadata and artifacts over TLS and verify signed Release/InRelease metadata plus package hashes.
  • Scope repository trust to the AncestryLLM source; do not add a globally trusted package key.
  • Do not open firewall ports, create public listeners, generate weak credentials, or select server mode during package installation.
  • Keep secrets out of package configuration, debconf output, process arguments, and logs.
  • Normal purge behavior must distinguish application files from encrypted user data and require explicit confirmation before destroying data.

Acceptance criteria

  • amd64 and arm64 packages install and upgrade on the supported Debian and Ubuntu matrix.
  • APT repository metadata is reproducible, signed for 1.0, and validated in release automation.
  • Repository onboarding uses a scoped keyring and signed-by source configuration.
  • Desktop and server package boundaries, dependencies, services, upgrade behavior, rollback, and removal are documented and tested.
  • No install path produces an unauthenticated listener or silently selects remote-server mode.
  • User, advanced-operator, release, privacy, and troubleshooting documentation is complete.

Dependencies

Depends on #132, #355, #356, #358, and the Linux container-runtime validation work.

Reference

Debian guidance for third-party repositories: https://wiki.debian.org/DebianRepository/UseThirdParty

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions