From bd377d8367271299711775c1a1844b3498503539 Mon Sep 17 00:00:00 2001 From: "guys-inc-ops[bot]" <321481384+guys-inc-ops[bot]@users.noreply.github.com> Date: Thu, 27 Aug 2026 04:17:40 +0000 Subject: [PATCH] Say where the publishing pipeline lives, and which key to check Two gaps that only became visible once the key rotation landed. The pipeline is a separate project now. `archivist` was extracted from this repository's publishing half and is MIT-licensed, but nothing here said so - someone who wants a signed apt repository of their own would have to read this repo's workflows to discover that the interesting part has already been pulled out for them. The README and the landing page now point at it, and both say plainly that it is pre-release and that this repository still publishes with reprepro directly. An open-source callout that overstates what you can install today is worse than none. The other gap is the key. The primary now certifies one signing subkey per project, so `gpg --show-keys` lists a subkey belonging to `archivist` that has nothing to do with this repository. We ask people to check a fingerprint without saying which of the three it should be, and the answer is the primary - it is what stays constant across rotations. The landing page reaches the bucket on the next `Publish APT repository` run, which copies apt/index.html to the bucket root. --- README.md | 21 ++++++++++++++++++++- apt/index.html | 15 ++++++++++++++- 2 files changed, 34 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 9c9289f029..92e2247dac 100644 --- a/README.md +++ b/README.md @@ -57,9 +57,28 @@ echo "deb [signed-by=/etc/apt/keyrings/guysinc-apt.gpg] https://apt.guysinc.pub/ sudo apt update && sudo apt install github-desktop ``` -The repository is GPG-signed; the signing key fingerprint is +The repository is GPG-signed; the fingerprint to verify is `F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8`. +That is the *primary* key. `gpg --show-keys` will also list signing subkeys — one per +project — and it is a subkey that signs this repository. The primary certifies the +subkeys, stays offline, and survives their rotation, which is why it is the one +published here. + +### How the repository is published + +The signing and publishing half of this pipeline is being extracted into +**[archivist](https://github.com/Guys-Inc-Public/archivist)**, a separate MIT-licensed +project: point it at a directory of `.deb` files and get a signed apt repository on +storage you own. If you have been putting loose `.deb` files on a Releases page because +`reprepro`, GPG-in-CI and repository metadata looked like too much work, that is the +problem it exists to remove. + +It is **pre-release** — the design and the decision records are written down, the CLI is +not finished, and this repository still publishes with `reprepro` directly today. Nothing +to install yet; the [roadmap](https://github.com/Guys-Inc-Public/archivist/blob/main/docs/Roadmap.md) +is the honest status. + ## Other distributions Prebuilt packages for every release are on the diff --git a/apt/index.html b/apt/index.html index c9ff0a6142..b87e2b7b79 100644 --- a/apt/index.html +++ b/apt/index.html @@ -76,8 +76,21 @@
Fingerprint of the repository signing key:
+Fingerprint of the primary key — this is the one to check:
F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8
+gpg --show-keys will also list signing subkeys, one per project, and it is a
+ subkey that actually signs this repository. The primary certifies them, stays offline, and does not change when a
+ subkey is rotated — so it is the fingerprint worth writing down.
Nothing here is hand-rolled per release. The signing and publishing steps are being extracted into
+ archivist — an MIT-licensed tool that turns a directory of
+ .deb files into a signed apt repository on storage you own. It is still pre-release; if you want the same setup
+ for your own project, follow along there.