Skip to content

Say where the publishing pipeline lives, and which key to check - #35

Merged
Cam8863 merged 1 commit into
linuxfrom
docs/archivist-callout
Aug 27, 2026
Merged

Cam8863 merged 1 commit into
linuxfrom
docs/archivist-callout

Conversation

@guys-inc-ops

@guys-inc-ops guys-inc-ops Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Documentation follow-up to the key rotation and the archivist extraction. No code, no workflow changes.

1. The pipeline is a separate, open-source project — and nothing said so

archivist is the publishing half of this repository, extracted into its own MIT-licensed repo so other projects can stop putting loose .deb files on a Releases page. Until this PR, the only way to discover that was to read .github/workflows/publish-apt.yml and notice it had been generalised elsewhere.

The README gains a short How the repository is published subsection, and apt/index.html gains a How this repository is built card.

Both are explicit that it is pre-release. archivist build / publish / verify currently exit 2, and this repository still publishes with reprepro directly. A callout that reads as "go install this" would send people to a tool that does not run yet, which costs more goodwill than staying quiet would have. The wording is "being extracted into" and "follow along there", and it links the roadmap as the status of record.

2. Which fingerprint to check

The rotated primary certifies one signing subkey per project. So a user who follows our own advice and runs gpg --show-keys sees three keys, one of which belongs to archivist:

pub   rsa4096 F45BB6D34D82EF56BB97FBE0F305FB33592B46C8  [C]   <- what we publish
sub   rsa4096 63029D0D...B498960D                       [S]   <- archivist releases
sub   rsa4096 65B6F556...5F23DEEE                       [S]   <- signs this repository

Neither the README nor the landing page said which one the published fingerprint was. Both now say: the primary, because it certifies the subkeys, stays offline, and survives their rotation.

Note on rollout

apt/index.html is copied to the bucket root by the Publish APT repository workflow, so the landing page changes go live on the next publish run rather than on merge.

Two gaps that only became visible once the key rotation landed.

The pipeline is a separate project now. `archivist` was extracted from this
repository's publishing half and is MIT-licensed, but nothing here said so -
someone who wants a signed apt repository of their own would have to read
this repo's workflows to discover that the interesting part has already been
pulled out for them. The README and the landing page now point at it, and
both say plainly that it is pre-release and that this repository still
publishes with reprepro directly. An open-source callout that overstates
what you can install today is worse than none.

The other gap is the key. The primary now certifies one signing subkey per
project, so `gpg --show-keys` lists a subkey belonging to `archivist` that
has nothing to do with this repository. We ask people to check a fingerprint
without saying which of the three it should be, and the answer is the
primary - it is what stays constant across rotations.

The landing page reaches the bucket on the next `Publish APT repository`
run, which copies apt/index.html to the bucket root.
@guys-inc-ops
guys-inc-ops Bot requested a review from Cam8863 as a code owner August 27, 2026 04:17
Cam8863 added a commit to Guys-Inc-Public/archivist that referenced this pull request Aug 27, 2026
A `## Why` that only describes a problem asks a reader to take the
design on faith. This adds the provenance, which is the strongest thing
the project has and was missing from the front page.

### What it adds

A short **Where it came from** subsection under `## Why`:

- This is the publishing half of
[github-desktop-linux](https://github.com/Guys-Inc-Public/github-desktop-linux),
serving signed packages for three architectures from
[apt.guysinc.pub](https://apt.guysinc.pub).
- It names the specific failures the design has already absorbed — a
passphrase-protected key that cannot sign in CI, a state pull that
swallowed its own failure and silently unlisted every prior version, a
signing-key rotation, and the armour-checksum mismatch between Go's
`clearsign` and GnuPG. Specific beats "battle-tested".

### What it is careful not to claim

The extraction framing invites the assumption that working code was
lifted. It was not — the survey in
[Extraction-Inventory.md](https://github.com/Guys-Inc-Public/archivist/blob/main/docs/Extraction-Inventory.md)
found no file worth taking unchanged, and ADR 0001 records the
clean-room decision. The new text says the *design* carried over and the
code did not, and that the original repository still publishes with
`reprepro` until `v0.1.0` ships.

Pairs with Guys-Inc-Public/github-desktop-linux#35, which adds the link
in the other direction.

Co-authored-by: guys-inc-ops[bot] <321481384+guys-inc-ops[bot]@users.noreply.github.com>
Co-authored-by: Cam8863 <96192092+Cam8863@users.noreply.github.com>
@Cam8863
Cam8863 merged commit 8ea2888 into linux Aug 27, 2026
6 checks passed
@Cam8863
Cam8863 deleted the docs/archivist-callout branch August 27, 2026 09:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant