Aggregates Debian packages from multiple sources into signed APT repositories.
- Sources: GitHub releases, OpenBuildService (OBS) and existing APT repositories
- Signature verification of
InReleaseand.changesfiles against configured keys, GitHub releases without.changesare checked against GitHub's asset digests - Per-feed filters for distributions (with renaming), release types, tags, release assets, source and package names
- Retention policies to keep only the newest versions per version pattern
- Optional debug and source packages
- Pool modes: standard hierarchical pool, or redirect mode where only the repository metadata is hosted and pool requests are redirected to the original feed URLs
- Optional web page per repository with Markdown description, package overview and install script
- Publishing to Cloudflare Pages, or serving locally
- Each step (fetch, generate, publish) runs on its own and can be combined with other tools
go install github.com/dionysius/aarg@latestCreate a main configuration file and repository configuration file(s), refer to examples which contain detailed comments for various options.
# Complete build: fetch packages, generate repo, publish
aarg build --all
# Or run steps individually:
aarg fetch --all # Download packages
aarg generate --all # Generate APT metadata
# Serve or publish result
aarg serve # Serve locally
aarg publish # Upload to providerDirectories can also be customized in the config file.
/configured/root/
├── downloads/ # Packages downloaded by `fetch`
├── trusted/ # Verified packages, hardlinked from downloads by `fetch`
├── cache/ # Parsed package data, reused by `fetch` and `generate`
├── staging/
│ └── <timestamp>/ # One build per `generate` run, the last ones are kept
└── public -> staging/<timestamp>/
├── myrepo1/... # Standard repository structure inside
├── ...
├── keys/ # Public signing key
├── 404.html
└── index.html # With compose `web`serve serves the public directory and publish uploads it to the configured provider.
Besides cleanup, better interfacing and testing:
- Remove staging and instead cleanup public directory after generation so it doesn't need to be symlinked anymore
- Internal server should also understand redirect metadata and offer redirects
- Add more potential sources and providers
- Offer package webpage describing metadata of each package, extract man pages, licenses, etc. The usual package description page from your known distribution.
- Make web template generation customizable
- Generated install script is too opinionated by using the OS' codename as suite in the sources configuration
- When using build, do publish only if changes are detected (or enforce with flag)
- And many things I just forgot