Skip to content

Tutorials

End-to-end walkthroughs that take a pile of packages all the way to a signed repository your clients can install from.

The tutorials cover new Managed workspaces and migration of existing Plain repositories. Commands are intended to be run in order; replace uppercase placeholders and package paths for your environment.

If you have not installed SOW yet, start with Installation and Quick Start.

Replace a flat repository’s metadata generator while preserving publication time, signatures, and compatibility with clients that already have cached metadata.

A managed RPM repository with per-architecture views, noarch projection, debuginfo filtering, version limits, and a working dnf client configuration.

A managed DEB repository with a Debian-style pool, by-hash indexes, and a deb822 client configuration.

Generate a dedicated GPG key, sign repository metadata and RPM packages, and configure clients to reject anything unsigned.

Serve a Repository with Nginx and publish a verified Generation to a configured filesystem target without exposing private workspace state.

Turn existing dual-architecture infra-pkg RPMs and DEBs into a real repository, then rehearse local installation, rolling updates, Stable promotion, and monthly snapshots.

Which one first

Your situation Start here
You already maintain a flat RPM directory with createrepo_c Migrate an Existing YUM Repository
You ship RPMs to dnf clients Build a YUM Repository
You ship DEBs for Debian or Ubuntu Build an APT Repository
You need signed metadata or signed RPM payloads Sign Your Repository
The tree is built but nothing can reach it Serve Repositories
You want to turn a dual-architecture package pool into a maintained Infra repository Build the pigsty-infra Repository

The YUM and APT tutorials are independent fresh-workspace paths. A real Workspace may hold both RPM and DEB Dists in one Repository when that ownership boundary suits your operation.

Conventions used here

Shell blocks contain commands without a $ prefix so you can copy a whole block at once. Output appears in a separate block below the command, or as a comment when it is one line. Where a command needs a value you must substitute, it appears in UPPERCASE.

Every tutorial includes verification. For Managed mode, sow check returning 0 confirms that the selected Repository is complete and matches the recorded Generation. Plain mode uses metadata and signature checks plus real client acceptance, as described in the migration guide; sow check does not audit a flat directory.

Build a YUM Repository

Create a managed RPM repository, apply membership policy, serve it, and configure dnf.

Migrate an Existing YUM Repository

Move a flat RPM repository to SOW while preserving client cache compatibility, package trust, and publication time.

Build an APT Repository

Create a managed DEB repository with by-hash indexes and configure an APT client.

Sign Your Repository

Sign RPM and APT metadata, optionally sign RPM packages, and enable client verification.

Serve and Publish Repositories

Serve a public Repository with Nginx and publish verified Generations to a filesystem target.

Build the pigsty-infra Repository

Turn an existing dual-architecture RPM and DEB package pool into an infra repository, then validate installs, roll updates, promote to Stable, and take monthly snapshots.