TT Lab
Get started
Learn Learning paths Courses

Package Management

Building an Offline Transfer Bundle

Continue in TT Lab

Goal

You bundle one package and all of its dependencies into an "import bundle", verify it with a checksum manifest, and reproduce the installation from that bundle alone. It is a scaled-down version of the procedure for importing into an air-gapped network.

Why it matters

The most common failure on an air-gapped network is "I took it in but the dependencies were short, so I have to go back out". In an organization where the import review happens only once a day, one round trip is a day. That is why an experienced person goes in carrying the result of solving the dependency graph in full on the outside. And you need a way to confirm that the files that passed through the medium are intact — a checksum catches corruption in transit, and a signature guarantees the origin. This lab gets the skeleton of that procedure into your hands.

Steps

  1. Create the /root/offline directory and save the list of URIs of the files you would need to download to install cowsay to /root/offline/uris.txt. (You must not actually install it.)
  2. Only download cowsay and its dependencies, and gather the downloaded .deb files in /root/offline/pool/. There must be at least 2.
  3. Create a SHA-256 manifest for all the .deb files in /root/offline/pool as /root/offline/manifest.sha256.
  4. Run the verification with that manifest and save the result to /root/offline/verify.txt. Every line must be OK.
  5. To turn /root/offline/pool into a repository, generate Packages and Packages.gz.
  6. Register this repository as /etc/apt/sources.list.d/labhub-airgap.list and refresh the index.
  7. Reinstall cowsay to confirm that the install also works from the imported files, and after installing, save the result of running cowsay labhub to /root/offline/run.txt.
  8. Make /root/offline/report.txt with the following 4 lines. PACKAGES=<pool 안 .deb 개수> / BYTES=<pool 안 .deb 파일 크기 합계(바이트)> / VERIFY=OK / SNAPSHOT=<오늘 날짜 YYYY-MM-DD> (that is, the number of .deb files in the pool, the total size in bytes of the .deb files in the pool, OK, and today's date)

Notes

First calculate what must be downloaded

Create the /root/offline directory and save the list of URIs of the files you would need to download to install cowsay to /root/offline/uris.txt. (You must not actually install it.)

apt-get install has an option that does not actually download and only prints the list of URIs to download. Look for the simulation-family options.

Downloading the packages

Only download cowsay and its dependencies, and gather the downloaded .deb files in /root/offline/pool/. There must be at least 2.

There is an option that only downloads without installing. The downloaded files pile up in the apt cache directory.

Creating the checksum manifest

Create a SHA-256 manifest for all the .deb files in /root/offline/pool as /root/offline/manifest.sha256.

If you run sha256sum on several files at once, you get the 'hash, space, file name' format. It is a format you can use as is for verification later.

Verifying with the manifest

Run the verification with that manifest and save the result to /root/offline/verify.txt. Every line must be OK.

sha256sum has an option that reads a manifest instead of a file and checks against it. You have to run the verification in the directory that holds the manifest for the paths to match.

Making a repository index from the imported files

To turn /root/offline/pool into a repository, generate Packages and Packages.gz.

It is the same method as in the previous lab. This time, though, there are several files, so check the number of Package entries in the index.

Registering the import repository

Register this repository as /etc/apt/sources.list.d/labhub-airgap.list and refresh the index.

Give the repository a name different from the previous lab. It is fine if both repositories are valid at the same time.

Reinstalling from the import repository

Reinstall cowsay to confirm that the install also works from the imported files, and after installing, save the result of running cowsay labhub to /root/offline/run.txt.

To install an already installed package again at the same version, you need the reinstall option.

Import report

Make /root/offline/report.txt with the following 4 lines. PACKAGES=<pool 안 .deb 개수> / BYTES=<pool 안 .deb 파일 크기 합계(바이트)> / VERIFY=OK / SNAPSHOT=<오늘 날짜 YYYY-MM-DD> (that is, the number of .deb files in the pool, the total size in bytes of the .deb files in the pool, OK, and today's date)

Just gather the number of manifest lines, the total bytes, and the verification result. You can get the total bytes with du or stat.