Say where the publishing pipeline lives, and which key to check - #35
Merged
Merged
Conversation
Two gaps that only became visible once the key rotation landed. The pipeline is a separate project now. `archivist` was extracted from this repository's publishing half and is MIT-licensed, but nothing here said so - someone who wants a signed apt repository of their own would have to read this repo's workflows to discover that the interesting part has already been pulled out for them. The README and the landing page now point at it, and both say plainly that it is pre-release and that this repository still publishes with reprepro directly. An open-source callout that overstates what you can install today is worse than none. The other gap is the key. The primary now certifies one signing subkey per project, so `gpg --show-keys` lists a subkey belonging to `archivist` that has nothing to do with this repository. We ask people to check a fingerprint without saying which of the three it should be, and the answer is the primary - it is what stays constant across rotations. The landing page reaches the bucket on the next `Publish APT repository` run, which copies apt/index.html to the bucket root.
Cam8863
added a commit
to Guys-Inc-Public/archivist
that referenced
this pull request
Aug 27, 2026
A `## Why` that only describes a problem asks a reader to take the design on faith. This adds the provenance, which is the strongest thing the project has and was missing from the front page. ### What it adds A short **Where it came from** subsection under `## Why`: - This is the publishing half of [github-desktop-linux](https://github.com/Guys-Inc-Public/github-desktop-linux), serving signed packages for three architectures from [apt.guysinc.pub](https://apt.guysinc.pub). - It names the specific failures the design has already absorbed — a passphrase-protected key that cannot sign in CI, a state pull that swallowed its own failure and silently unlisted every prior version, a signing-key rotation, and the armour-checksum mismatch between Go's `clearsign` and GnuPG. Specific beats "battle-tested". ### What it is careful not to claim The extraction framing invites the assumption that working code was lifted. It was not — the survey in [Extraction-Inventory.md](https://github.com/Guys-Inc-Public/archivist/blob/main/docs/Extraction-Inventory.md) found no file worth taking unchanged, and ADR 0001 records the clean-room decision. The new text says the *design* carried over and the code did not, and that the original repository still publishes with `reprepro` until `v0.1.0` ships. Pairs with Guys-Inc-Public/github-desktop-linux#35, which adds the link in the other direction. Co-authored-by: guys-inc-ops[bot] <321481384+guys-inc-ops[bot]@users.noreply.github.com> Co-authored-by: Cam8863 <96192092+Cam8863@users.noreply.github.com>
Cam8863
approved these changes
Aug 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documentation follow-up to the key rotation and the
archivistextraction. No code, no workflow changes.1. The pipeline is a separate, open-source project — and nothing said so
archivistis the publishing half of this repository, extracted into its own MIT-licensed repo so other projects can stop putting loose.debfiles on a Releases page. Until this PR, the only way to discover that was to read.github/workflows/publish-apt.ymland notice it had been generalised elsewhere.The README gains a short How the repository is published subsection, and
apt/index.htmlgains a How this repository is built card.Both are explicit that it is pre-release.
archivist build/publish/verifycurrently exit 2, and this repository still publishes withrepreprodirectly. A callout that reads as "go install this" would send people to a tool that does not run yet, which costs more goodwill than staying quiet would have. The wording is "being extracted into" and "follow along there", and it links the roadmap as the status of record.2. Which fingerprint to check
The rotated primary certifies one signing subkey per project. So a user who follows our own advice and runs
gpg --show-keyssees three keys, one of which belongs toarchivist:Neither the README nor the landing page said which one the published fingerprint was. Both now say: the primary, because it certifies the subkeys, stays offline, and survives their rotation.
Note on rollout
apt/index.htmlis copied to the bucket root by thePublish APT repositoryworkflow, so the landing page changes go live on the next publish run rather than on merge.