Linux packages (apt)
Set up apt
Point apt at a ForgeRepo™ mirror of Debian or Ubuntu, and give it your token.
Your admin tells you the mirror address. Put it in your sources in place of the distro's own, and your login in /etc/apt/auth.conf.d/:
$ cat /etc/apt/sources.list deb https://packages.example.com/apt/debian/ bookworm main $ cat /etc/apt/auth.conf.d/company.conf machine packages.example.com/apt/ login your-user-name password <your token> $ apt-get update Get:1 https://packages.example.com/apt/debian bookworm InRelease [151 kB] Get:2 https://packages.example.com/apt/debian bookworm/main amd64 Packages [8790 kB] Fetched 8941 kB in 2s (5825 kB/s) Reading package lists...
Captured by running these commands against a real ForgeRepo™.
- apt still checks the distro's signature on the index, so nothing changes about trust.
- Make the auth file readable only by root:
chmod 600, since it holds your token. - Remove the distro's own sources, so every package comes through packages.example.com.
- A bare Debian or Ubuntu image has no CA certificates, so apt can not reach an https mirror. Install ca-certificates in your base image, or point
Acquire::https::CAInfoat your company CA.
Then install as usual:
$ apt-get install -y tree ... 0 upgraded, 1 newly installed, 0 to remove and 0 not upgraded. Need to get 52.5 kB of archives. After this operation, 116 kB of additional disk space will be used. Get:1 https://packages.example.com/apt/debian bookworm/main amd64 tree amd64 2.1.0-1 [52.5 kB] Fetched 52.5 kB in 1s (40.1 kB/s) Preparing to unpack .../tree_2.1.0-1_amd64.deb ... Unpacking tree (2.1.0-1) ... Setting up tree (2.1.0-1) ...
Captured by running these commands against a real ForgeRepo™.
Note
If your admin set the mirror to a filtered index, it is signed by ForgeRepo™ instead of the distro. Fetch the key from https://packages.example.com/apt/signing-key.asc into /etc/apt/keyrings/ and add [signed-by=/etc/apt/keyrings/forgerepo.asc] to the line.