One signed source and one key, however many of our packages you end up
running. Debian and Ubuntu, on amd64 and
arm64.
Once per machine. Every Stack256 package is served from this one source, so you never do this again for the next one.
# fetch the signing key
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://apt.stack256.org/stack256-archive-keyring.gpg \
| sudo tee /etc/apt/keyrings/stack256-archive-keyring.gpg > /dev/null
# add the source, pinned to that key
echo "deb [signed-by=/etc/apt/keyrings/stack256-archive-keyring.gpg] \
https://apt.stack256.org stable main" \
| sudo tee /etc/apt/sources.list.d/stack256.list
sudo apt update
Products that ship an installer do all of the above for you —
curl -fsSL https://apt.stack256.org/paco/install.sh | sudo sh
for Paco, for instance. Both routes write the same source file and
the same keyring path, so mixing them will not leave you with the
repository configured twice.
Generated from the published index, so this is what
apt install can actually reach right now — not a list kept
up by hand.
Not every Stack256 product ships a Debian package — some are distributed as container images and are documented in their own repositories. The full catalogue is at stack256.org. The authoritative machine-readable list for this repository is the index itself.
stable, component main, for
amd64 and arm64
InRelease (inline-signed) and Release.gpg
(detached), for modern and older clients
stack256-archive-keyring.gpg — the public key, exported
from the very key that signs the index, so the two cannot drift apart