Building Your Own Repository
Goal
You build an apt repository that works without the internet from scratch and install packages from it. You confirm by hand that a repository is, in fact, "a directory + an index file".
Why it matters
Whether it is an air-gapped network, an internal standard image, or a CI cache, what you ultimately need is a controllable repository. All apt reads from a repository is the Packages index and the Release metadata, so if you make just those two, even a file:/// path becomes a complete repository. Once you know this structure, the cause of "I added the package but it doesn't show up" splits immediately into a missed index rebuild or a client cache. A production repository adds a GPG signature to this, but to focus on the structure, this lab substitutes a trust option.
Steps
- Create the
/root/repodirectory, build/opt/fixtures/pkg/labhub-tooland/opt/fixtures/pkg/labhub-extraeach into a.deb, and put them inside/root/repo. - Create the
/root/repo/Packagesindex. It must contain thePackage:entries of both packages. - Create the compressed
/root/repo/Packages.gz. - Create the
/root/repo/Releasefile. The six keysOrigin,Label,Suite,Codename,Architectures, andComponentsmust each have one line, and theArchitecturesvalue must includeall. - Register this repository in
/etc/apt/sources.list.d/labhub-local.list. The path is/root/repo, in flat format. - Refresh the index, and save the output of
apt-cache policy labhub-extrato/root/repo-check/policy.txt. - Install
labhub-extrawith apt. Because of the dependency relationship,labhub-toolmust be installed along with it. - Make
/root/repo-check/origin.txtwith two lines.labhub-tool=<설치된 버전>/labhub-extra=<설치된 버전>(each followed by the installed version)
Notes
- You build the index in the form
dpkg-scanpackages /root/repo /dev/null > /root/repo/Packages. TheFilename:value differs depending on how you write the path, so read the error message afterapt-get updatecarefully. - The format of a sources.list line is
deb [옵션] <URI> <suite> [component...](the option and the URI are placeholders), and for a flat repository you write./in the suite position. - Common mistake 1: you did not run
apt-get updateafter creating the index, so "not found" keeps appearing. - Common mistake 2: a
NO_PUBKEY/not signederror appears because there is no signature. In this lab you get past it with a trust option.
Preparing the package pool
Create the /root/repo directory, build /opt/fixtures/pkg/labhub-tool and /opt/fixtures/pkg/labhub-extra each into a .deb, and put them inside /root/repo.
Build the two fixtures separately and gather them in the same directory. The file names are up to you, but the extension must be .deb.
Creating the Packages index
Create the /root/repo/Packages index. It must contain the Package: entries of both packages.
dpkg-scanpackages takes the directory to scan as its first argument and the override file as its second. If there is no override file, give /dev/null.
Creating the compressed index
Create the compressed /root/repo/Packages.gz.
apt looks for Packages.gz first. It is handier for debugging to keep the original as well.
Writing the Release file
Create the /root/repo/Release file. The six keys Origin, Label, Suite, Codename, Architectures, and Components must each have one line, and the Architectures value must include all.
The six keys Origin, Label, Suite, Codename, Architectures, and Components go in one line each. Choose the values freely, but Architectures must include all.
Registering the repository
Register this repository in /etc/apt/sources.list.d/labhub-local.list. The path is /root/repo, in flat format.
For a flat repository, add ./ after the path. There is no signature, so a trust option is needed.
Refreshing the index and checking
Refresh the index, and save the output of apt-cache policy labhub-extra to /root/repo-check/policy.txt.
After apt-get update, use apt-cache policy to see which repository the candidate came from. The repository path must be visible in the output.
You get stuck here once. If Could not open file ... (13: Permission denied) appears, it is a permissions problem. apt drops only the download part to an unprivileged user called _apt (APT::Sandbox::User), and /root is 700, so that user cannot go inside. Since the repository is under /root, you only need to open traverse permission — chmod o+x /root. The permission to list the contents (r) is still closed.
There is also a way to turn off the sandbox (-o APT::Sandbox::User=root), but that covers up the problem. This is exactly why real-world repositories are placed in /srv or /var/www.
Installing from my repository
Install labhub-extra with apt. Because of the dependency relationship, labhub-tool must be installed along with it.
If you install the one that has the dependency, apt pulls in the rest on its own. This is where it differs from dpkg -i.
Origin verification report
Make /root/repo-check/origin.txt with two lines.
labhub-tool=<설치된 버전> / labhub-extra=<설치된 버전> (each followed by the installed version)
The repository path appears in the version table of apt-cache policy. Check that both packages came from the local repository.