Skip to content

Software Object Warehouse

Build Package Repos Ship What Changed

Create YUM and APT indexes from local RPM and DEB packages. Use Plain mode for an existing package directory, or Managed mode for package policy, snapshots, signing, and incremental publication.

SOW 0.5.0 · Linux + macOS · RPM + DEB · Apache-2.0

Core capabilities

Flat or Managed

One command builds a local repository; a Managed workspace keeps membership, generations, and publication history.

01 / CREATE

Create repo in one command

◇ Point SOW at a directory of packages

  • sow create indexes top-level RPM and DEB files in place
  • Produces rpm-md metadata and APT Packages indexes
  • Explicit publication timestamps support existing YUM clients

From package files to repository metadata, no daemon or toolchain.

create.sh
$ sow create /srv/repo --jobs 8
✓ repodata/repomd.xml
✓ Packages
✓ Packages.gz

03 / READY TO RUN

Self-contained builds, checked output

◇ The same CLI on macOS and Linux

  • Self-contained CGO_ENABLED=0 archives for amd64 and arm64
  • The release pipeline builds RPM and DEB packages for Linux
  • Validates generated metadata; Managed mode adds recoverable writes

No repository daemon and no language runtime to operate.

04 / INCREMENTAL

Publish only the change set

◇ Inspect first, then synchronize

  • sow changes reports payload, metadata, pointer, and removal records
  • The operation log preserves who changed what and when
  • Publication uploads the delta, not every repository object

Small repository changes stay small on filesystem and cloud targets.

publish.sh
$ sow changes -r pgsql
+ pool/p/postgresql-18/...
~ dists/el9/x86_64/repodata/...
$ sow publish prod
✓ changed objects verified

Operating model

Simple at the start, explicit under control

SOW keeps the easy path rebuildable and makes every managed delivery decision visible.

01

Rebuild derived state

Plain mode rebuilds indexes from the package directory. The same package bytes and options produce the same metadata, including any explicit publication timestamp.

02

Own managed intent

Managed mode separates Desired Membership from immutable Built Generations, so policy and publication never become hidden side effects.

03

Verify before delivery

Verify package and metadata integrity before serving clients. Managed mode also records operations and recovers interrupted writes.

Common questions

Choose the smallest workflow that fits

Plain and Managed use the same binary, but solve different operating problems.

Should I start with Plain or Managed mode?

Start with Plain mode when the directory already contains exactly what you want to serve. Use a Managed workspace when SOW must own membership, policy, signed metadata, immutable generations, audit history, or publication targets.

Can I replace an existing createrepo_c workflow?

For a flat RPM directory, use sow create with the publication-time option added in 0.5. Keep the publication history and index-signing steps in your maintenance script, then test with clients that retain their old metadata cache. Follow the YUM migration guide; Plain does not generate legacy SQLite metadata or module streams.

Does RPM signing also sign the repository index?

--sign-with signs unsigned RPM packages. In Plain mode, sign repomd.xml separately after the final metadata build. Managed mode provides configured metadata-signing policies. See Signing for both workflows.

Can SOW handle RPM and DEB packages together?

Yes. A Plain directory can contain both RPM and DEB packages. In Managed mode, each Dist has one format, while one Repository can expose multiple RPM and DEB Dists from its shared public tree.

Does SOW need a daemon or database service?

No. SOW is a self-contained CLI and emits static repository files. Managed workspaces keep their embedded state locally; serve only the generated public tree with the HTTP server you already operate.

Where can a Managed repository be published?

A configured target can be a local or mounted filesystem, or Cloudflare R2 object storage. sow changes shows the delta before publication, and SOW records the target state for the next incremental run.

Build the first repository now.Start with sow create; move to a Managed workspace when you need policy, snapshots, and publication history.