Research: Gitea 1.27 Debian + RPM package registry feasibility #35
Notifications
Due Date
No due date set.
Blocks
#38 Grilling: Lock channel + toolchain
xavierk/Fenris
Reference: xavierk/Fenris#35
Reference in New Issue
Block a user
Parent map: Fenris deb + rpm release plan
Question
Verify the Gitea 1.27.1 instance at git.bongbetic.com can serve as the deb + rpm distribution channel: publish path (API PUT per format), apt sources.list + dnf repo config users need, repo metadata signing support vs passthrough, multi-distro metadata (apt distributions/suites fields, rpm distro tags), package version retention, and whether packages can attach to releases. Deliver exact client-side setup commands.
Verdict: feasible — git.bongbetic.com (Gitea 1.27.1) can serve as the deb+rpm channel.
Everything below was verified live with throwaway packages (deleted afterward; package list confirmed empty).
Full findings: branch
research/gitea-registry→docs/research/gitea-package-registry.md(https://git.bongbetic.com/xavierk/Fenris/src/branch/research/gitea-package-registry.md — pending merge)
curl -u xavierk:$TOKEN --upload-file f.deb …/api/packages/xavierk/debian/pool/{distribution}/{component}/uploadcurl … --upload-file f.rpm …/api/packages/xavierk/rpm/{group}/upload(group optional:el9,rocky/el9, …)…/debian/repository.key→/etc/apt/keyrings/gitea-xavierk.asc, thendeb [signed-by=…] https://git.bongbetic.com/api/packages/xavierk/debian {distribution} mainin sources.list.d.sudo dnf config-manager --add-repo https://git.bongbetic.com/api/packages/xavierk/rpm/el9.repo(generated .repo already setsgpgcheck=1+ gpgkey).InRelease) and rpmrepomd.xml.ascwith per-instance auto-generated PGP keys; both verifiedgpg --verify→ Good signature. No bring-your-own-key option in 1.27.bookworm+noblesimultaneously; each gets its owndists/tree). RPM groups likewise (el9tested) with independentrepodata/.All test packages deleted; instance left clean.
xavierk referenced this issue2026-09-02 18:43:43 +00:00