Images and publishing
RPM mirrors
Mirror distro repositories like AlmaLinux 9 BaseOS for dnf and yum. Every package is checked and scanned.
- Settings, Registries: switch on RPM mirror.
- Add an RPM registry for each repository. Its address is the folder that holds repodata/, like
https://repo.almalinux.org/almalinux/9/BaseOS/x86_64/os. - Pick the advisory feed of its distro, like AlmaLinux:9, so its packages are checked against the right advisories.
- In whitelist mode, add an RPM allow rule of
*, then deny or kill what you do not want. A distro has thousands of packages. - Developers use the address the mirror shows, like
/rpm/almalinux-9-baseos/. See Set up dnf and yum.
- By default the index goes out exactly as the distro signed it, so clients keep checking its signature. Every download is checked: the rules, the kill switch, holds, advisories and cooling off.
- With Filtered index on, the index lists only what the rules and the kill switch allow, so dnf never picks a refused version. The distro did not sign that index, so clients must set
repo_gpgcheck=0. Package signatures are still checked. - Every package is checked against the checksum in the repository index before it is kept, and every metadata file against the checksum in repomd.xml.
- Only the repodata and the packages the index lists are served. Nothing else of the tree is.
- Advisories come from OSV, in the feed you picked for the mirror: ALSA for AlmaLinux, RLSA for Rocky Linux, RHSA for Red Hat.