TT Lab
Get started
Learn Learning paths Courses

Package Management

What Does apt Look At to Decide

Continue in TT Lab

In one line

Every decision apt makes comes from the repository index cached locally. If the index is stale, apt sees a stale world.

Why this exists

You type apt-get install nginx and get "Unable to locate package". The repository definitely has it. Nine times out of ten the cause is that you did not run apt-get update.

apt does not ask the repository when it installs. It looks only at the index files saved in /var/lib/apt/lists/ to calculate the dependencies, and only after the calculation is finished does it download the actual .deb files. This separation is what makes apt fast, but it is also the cause of "it's in the repository but I can't see it".

How it works

One installation has four steps.

  1. Read the index — It reads the Packages files of the repositories listed in /etc/apt/sources.list and sources.list.d/*.list.
  2. Choose a candidate — If the same package is in several repositories, it picks by pin priority. apt-cache policy <패키지> (the placeholder is the package name) shows the result of this decision as it is.
  3. Resolve dependencies — It follows Depends and Recommends to build the install set.
  4. Download, then unpack/configure — It hands off to dpkg.

How to read the output of apt-cache policy is the key.

nginx:
  Installed: (none)
  Candidate: 1.24.0-2ubuntu7
  Version table:
     1.24.0-2ubuntu7 500
        500 http://archive.ubuntu.com/ubuntu noble/main amd64 Packages

The number on the left is the version, and the number on the right is the priority. The default is 500, and there are two ways to touch it.

The two have different purposes. hold means "stop at the current version", and pin means "among several repositories, look at this one". In an environment that uses an internal mirror together with the official repository, pin is essential.

What it looks like in the field

kubelet on a Kubernetes node. You have to control the cluster version, so apt-mark hold kubelet kubeadm kubectl is effectively a standard procedure. If you do not set it, one day an apt-get upgrade run without thinking raises the minor version of just one node, and Pods fail to start only on that node.

The internal mirror's betrayal. You added the internal mirror to sources.list but it still fetches from the official repository. That is because when the priorities are the same, apt picks the one with the higher version. To force the mirror, you have to set a pin.

Know what an upgrade does before you run it

apt-get upgrade and apt-get dist-upgrade (these days apt full-upgrade) have similar names but do different things, and that difference leads to incidents in operations.

So on production servers you split it into two steps. First you look at what changes with -s (simulation), and run it for real only when there is nothing unfamiliar in the list. In particular, you should read the The following packages will be REMOVED line every time. There really are cases where, with the dependencies tangled, the solution apt proposes is "just remove this service".

Unattended upgrades deserve a mention too. Applying security updates automatically is usually the right choice, but if you have not decided how to handle updates that require a restart, it becomes one of two things. Either nothing restarts, and the updated library stays unapplied (the vulnerability remains), or things restart at arbitrary times and the service is cut. There are tools that check which processes are holding old libraries, so it is better to pull a list with them and restart in a planned window.

Finally, the difference between apt and apt-get. apt is convenient when a person uses it, but use apt-get in scripts. It is stated that apt may change its output format and behavior to be friendlier to humans, so if the format changes one day, a script that parses it breaks silently.

What you will do in the next lab

You search, install, and remove against the /opt/localrepo offline repository, set hold and pin yourself, and confirm how the apt-cache policy output changes.