Packages & Repositories
Software on a server comes from a signed catalogue, not from a download page. Learn to read what apt does, and what it leaves behind.
An interactive Linux lesson: 23 steps, about 32 minutes, on a live simulation in your browser.
web01 is a new server for an online shop. The deploy script needs jq, a tool for reading JSON, and it is not here. On a laptop you might search the web, download an installer and click through it. On a server you do not: nobody checked that file, nothing records what it changed, and nothing will ever update or remove it.
Try to pull one field out of a line of JSON and the shell cannot find jq. But Ubuntu knows where it comes from: the error names a package, and apt show prints that package's label without installing anything.
What you will learn
What a package is
- Command not found: A package is files, plus a label (name, version, dependencies), plus scripts that run at install and removal.
- Install it, and read what apt says
The repository and its catalogue
- apt reads a local catalogue: apt install never asks the repository what exists. It reads the copy of the catalogue on your own disk.
- What does apt update change?: apt update refreshes the catalogue. apt install and apt upgrade act on the catalogue. So: update first.
- You asked for one package: Each package declares what it depends on. apt turns one name into the whole set, downloads it and installs it in order.
What an install really did
- Every file, accounted for: A package does not live in one folder. Its files are spread over /usr, /etc and /var, and dpkg's database is the only record of which belong to it.
- Which package owns this file?: dpkg -L goes from a package to its files. dpkg -S goes from a file to its package. A file with no owner was not installed by the package system.
- The install also started a server
- Drill: name the owner
Finding things, reading versions
- Find a package you cannot name
- Installed versus candidate: Installed is what dpkg has on disk. Candidate is the newest version your catalogue lists. An upgrade is the gap between the two.
- upgrade, full-upgrade and holding back: upgrade moves every package to its candidate but removes nothing. full-upgrade may remove. hold keeps one package where it is.
Taking software off
- Remove nginx. What is left?: remove takes the programs and leaves /etc. Your configuration outlives the package.
- autoremove: the packages nobody asked for: apt remembers which packages you asked for and which only came along. autoremove deletes the ones that came along and are no longer needed.
- purge: the configuration too: purge is remove plus everything the package owns under /etc. It is the only way back to a default configuration.
- Drill: leave nothing behind
Where repositories come from
- Where repositories are configured: A repository is trusted because its index is signed by a key you already hold. The key named in Signed-By is the entire trust decision.
- Adding someone else's repository
dpkg, and what goes wrong
- dpkg -l: the machine's inventory: In dpkg -l the first letter is what you asked for and the second is what is true. ii is healthy; anything else is a package stuck between states.
- Break it: a .deb installed by hand: dpkg installs one file and resolves nothing. apt resolves dependencies and then calls dpkg. Give a local .deb to apt, with ./ in front of the name.
- Break it: the lock
Recap & playground
- Cheat sheet
- Playground