Debian and Ubuntu packages for Nav’s CLI tools, served over GitHub Pages.
This repo is to apt what navikt/homebrew-tap
is to brew: it holds no source, only packages built from the tools’ own releases.
curl -fsSL https://navikt.github.io/apt/keyring/navikt-archive-keyring.gpg \
| sudo tee /usr/share/keyrings/navikt-archive-keyring.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/navikt-archive-keyring.gpg] https://navikt.github.io/apt stable main" \
| sudo tee /etc/apt/sources.list.d/navikt.list
sudo apt update
sudo apt install nav-pilot cplt
The archive is signed, so apt verifies every package against the keyring you
installed in the first command.
To install without the archive, take the .deb straight off a release. It
installs once and never updates itself:
gh release download --repo navikt/copilot --pattern '*_amd64.deb'
sudo apt install ./nav-pilot_*_amd64.deb
.github/workflows/publish.yaml runs hourly and on demand. It downloads the
.deb assets from the latest release of each tool, adds them to pool/,
rebuilds the indices under dists/stable/, signs InRelease and Release.gpg,
publishes the public key to keyring/, and commits if anything changed.
Reading public releases needs no token beyond the workflow’s own, so the tool repos dispatch nothing.
Old versions stay in the pool, so a pinned install keeps working.
Two secrets:
| Secret | What it holds |
|---|---|
APT_SIGNING_KEY |
ASCII-armoured private key for the archive |
APT_SIGNING_KEY_ID |
that key’s fingerprint |
The key signs this archive and nothing else. To rotate it, replace both secrets
and re-run the workflow. The next run republishes
keyring/navikt-archive-keyring.gpg, and clients pick the new key up on their
next apt update.
Without APT_SIGNING_KEY the workflow still builds the pool and indices, warns,
and removes any stale signature.
amd64 and arm64. Both tools build for both.