diff --git a/README.md b/README.md index 9c9289f029..92e2247dac 100644 --- a/README.md +++ b/README.md @@ -57,9 +57,28 @@ echo "deb [signed-by=/etc/apt/keyrings/guysinc-apt.gpg] https://apt.guysinc.pub/ sudo apt update && sudo apt install github-desktop ``` -The repository is GPG-signed; the signing key fingerprint is +The repository is GPG-signed; the fingerprint to verify is `F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8`. +That is the *primary* key. `gpg --show-keys` will also list signing subkeys — one per +project — and it is a subkey that signs this repository. The primary certifies the +subkeys, stays offline, and survives their rotation, which is why it is the one +published here. + +### How the repository is published + +The signing and publishing half of this pipeline is being extracted into +**[archivist](https://github.com/Guys-Inc-Public/archivist)**, a separate MIT-licensed +project: point it at a directory of `.deb` files and get a signed apt repository on +storage you own. If you have been putting loose `.deb` files on a Releases page because +`reprepro`, GPG-in-CI and repository metadata looked like too much work, that is the +problem it exists to remove. + +It is **pre-release** — the design and the decision records are written down, the CLI is +not finished, and this repository still publishes with `reprepro` directly today. Nothing +to install yet; the [roadmap](https://github.com/Guys-Inc-Public/archivist/blob/main/docs/Roadmap.md) +is the honest status. + ## Other distributions Prebuilt packages for every release are on the diff --git a/apt/index.html b/apt/index.html index c9ff0a6142..b87e2b7b79 100644 --- a/apt/index.html +++ b/apt/index.html @@ -76,8 +76,21 @@

Why this build?

Verify the signing key

-

Fingerprint of the repository signing key:

+

Fingerprint of the primary key — this is the one to check:

F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8

+

gpg --show-keys will also list signing subkeys, one per project, and it is a + subkey that actually signs this repository. The primary certifies them, stays offline, and does not change when a + subkey is rotated — so it is the fingerprint worth writing down.

+
+
+ +
+

How this repository is built

+
+

Nothing here is hand-rolled per release. The signing and publishing steps are being extracted into + archivist — an MIT-licensed tool that turns a directory of + .deb files into a signed apt repository on storage you own. It is still pre-release; if you want the same setup + for your own project, follow along there.