learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Packages & Repositories

Software on a server comes from a signed catalogue, not from a download page. Learn to read what apt does, and what it leaves behind.

An interactive Linux lesson: 23 steps, about 32 minutes, on a live simulation in your browser.

web01 is a new server for an online shop. The deploy script needs jq, a tool for reading JSON, and it is not here. On a laptop you might search the web, download an installer and click through it. On a server you do not: nobody checked that file, nothing records what it changed, and nothing will ever update or remove it.

Try to pull one field out of a line of JSON and the shell cannot find jq. But Ubuntu knows where it comes from: the error names a package, and apt show prints that package's label without installing anything.

What you will learn

  1. What a package is

    • Command not found: A package is files, plus a label (name, version, dependencies), plus scripts that run at install and removal.
    • Install it, and read what apt says
  2. The repository and its catalogue

    • apt reads a local catalogue: apt install never asks the repository what exists. It reads the copy of the catalogue on your own disk.
    • What does apt update change?: apt update refreshes the catalogue. apt install and apt upgrade act on the catalogue. So: update first.
    • You asked for one package: Each package declares what it depends on. apt turns one name into the whole set, downloads it and installs it in order.
  3. What an install really did

    • Every file, accounted for: A package does not live in one folder. Its files are spread over /usr, /etc and /var, and dpkg's database is the only record of which belong to it.
    • Which package owns this file?: dpkg -L goes from a package to its files. dpkg -S goes from a file to its package. A file with no owner was not installed by the package system.
    • The install also started a server
    • Drill: name the owner
  4. Finding things, reading versions

    • Find a package you cannot name
    • Installed versus candidate: Installed is what dpkg has on disk. Candidate is the newest version your catalogue lists. An upgrade is the gap between the two.
    • upgrade, full-upgrade and holding back: upgrade moves every package to its candidate but removes nothing. full-upgrade may remove. hold keeps one package where it is.
  5. Taking software off

    • Remove nginx. What is left?: remove takes the programs and leaves /etc. Your configuration outlives the package.
    • autoremove: the packages nobody asked for: apt remembers which packages you asked for and which only came along. autoremove deletes the ones that came along and are no longer needed.
    • purge: the configuration too: purge is remove plus everything the package owns under /etc. It is the only way back to a default configuration.
    • Drill: leave nothing behind
  6. Where repositories come from

    • Where repositories are configured: A repository is trusted because its index is signed by a key you already hold. The key named in Signed-By is the entire trust decision.
    • Adding someone else's repository
  7. dpkg, and what goes wrong

    • dpkg -l: the machine's inventory: In dpkg -l the first letter is what you asked for and the second is what is true. ii is healthy; anything else is a package stuck between states.
    • Break it: a .deb installed by hand: dpkg installs one file and resolves nothing. apt resolves dependencies and then calls dpkg. Give a local .deb to apt, with ./ in front of the name.
    • Break it: the lock
  8. Recap & playground

    • Cheat sheet
    • Playground