Debark
Get Debark
Browse docs

Include vendor .deb files

Add downloaded or local .deb packages to a bundle along with their apt dependencies.

How-to guideUpdated

On this page

You can include vendor .deb files alongside packages from Debian or Ubuntu. Debark reads their dependencies and asks apt to download the ones missing from the target.

Choose a vendor package built for your target’s release and architecture. A .deb that works on the online computer may not be compatible with the offline machine.

Add a local file

debark build --snapshot target.tar.zst --out ./bundle \
  --sign operator.key ./downloads/agent.deb

Replace the path with your downloaded file. You can include several files and ordinary package names in the same command.

Download from a URL

Replace this example URL with the vendor’s actual .deb download:

debark build --snapshot target.tar.zst --out ./bundle \
  --sign operator.key https://vendor.example/agent.deb

If the download requires a browser login or an expiring link, download it yourself and use a local file.

Add a directory

debark build --snapshot target.tar.zst --out ./bundle \
  --sign operator.key --local-dir ./vendor jq

--local-dir includes .deb files directly in the directory, not its subdirectories. Repeat the flag for additional directories.

URLs and local paths also work in package list files.

Check a download against the vendor’s checksum

For a URL input, supply the expected SHA-256 checksum with --digest. Obtain the expected value from a trusted vendor source; calculating a checksum from your own download does not confirm who published it.

In this Bash example, replace both placeholder values:

PACKAGE_URL='https://vendor.example/agent.deb'
EXPECTED_SHA256='replace-with-the-vendor-64-character-sha256'
debark build --snapshot target.tar.zst --out ./bundle \
  --sign operator.key --digest "$PACKAGE_URL=$EXPECTED_SHA256" "$PACKAGE_URL"

A package-list URL line can instead end with sha256= followed by the expected checksum. The command-line --digest option applies to URL inputs; it does not add verification to a local file.

Understand publisher verification

The lock records how each package was checked:

  • apt-signed: checked through a signed apt repository.
  • url-unverified: a URL or local file without additional publisher verification.
  • user-digest: a URL download matched the checksum you supplied.

A bundle signature protects the assembled bundle during transfer. It does not change the publisher-verification status of a vendor package.

If you need to reject unverified inputs, use a policy file with require_signed_publisher: true and default_severity: deny. This rejects url-unverified and accepts user-digest, despite the setting’s name.

Check versions and installation requirements

Use debark inspect ./bundle to review the selected versions. When a vendor package and an apt repository provide the same package name, apt’s selection rules still apply; including a file does not by itself force installation of that file’s version.

Run debark doctor ./bundle to look for setup scripts that need internet access, DKMS requirements, and other common issues.

If an input fails

Exit 3 means the bundle is incomplete. A download may have failed or disagreed with its expected checksum, or apt may be unable to satisfy the vendor package’s dependencies.

Check the error for the affected input. Try a package matching the target release, enable the required apt source on the target and take a new snapshot, or supply a missing vendor dependency as another .deb. Rebuild and check the result before transferring it.

Some packages carry redistribution restrictions. Review the package terms when sharing bundles. --acknowledge-redistribution suppresses Debark’s prompt and retains the recorded warnings.