> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/artifact-registry/new-to-artifact-registry/quickstart/debian-quickstart.md).

# Debian

{% @harness-package-selector/package-selector platforms="%5B%7B%22label%22%3A%22Docker%22%2C%22slug%22%3A%22docker%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fdocker-quickstart%22%7D%2C%7B%22label%22%3A%22Helm%22%2C%22slug%22%3A%22helm%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fhelm-quickstart%22%7D%2C%7B%22label%22%3A%22Helm%20HTTP%22%2C%22slug%22%3A%22helm-http%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fhelm-http-quickstart%22%7D%2C%7B%22label%22%3A%22Generic%22%2C%22slug%22%3A%22generic%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fgeneric-quickstart%22%7D%2C%7B%22label%22%3A%22Raw%20File%22%2C%22slug%22%3A%22raw-file%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fraw-file-quickstart%22%7D%2C%7B%22label%22%3A%22Maven%22%2C%22slug%22%3A%22maven%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fmaven-quickstart%22%7D%2C%7B%22label%22%3A%22Python%22%2C%22slug%22%3A%22python%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fpython-quickstart%22%7D%2C%7B%22label%22%3A%22NPM%22%2C%22slug%22%3A%22npm%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fnpm-quickstart%22%7D%2C%7B%22label%22%3A%22Nuget%22%2C%22slug%22%3A%22nuget%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fnuget-quickstart%22%7D%2C%7B%22label%22%3A%22RPM%22%2C%22slug%22%3A%22rpm%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Frpm-quickstart%22%7D%2C%7B%22label%22%3A%22Debian%22%2C%22slug%22%3A%22debian%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fdebian-quickstart%22%7D%2C%7B%22label%22%3A%22Alpine%22%2C%22slug%22%3A%22alpine%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Falpine-quickstart%22%7D%2C%7B%22label%22%3A%22Wolfi%22%2C%22slug%22%3A%22wolfi%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fwolfi-quickstart%22%7D%2C%7B%22label%22%3A%22Cargo%22%2C%22slug%22%3A%22cargo%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fcargo-quickstart%22%7D%2C%7B%22label%22%3A%22Conan%22%2C%22slug%22%3A%22conan%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fconan-quickstart%22%7D%2C%7B%22label%22%3A%22Go%22%2C%22slug%22%3A%22go%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fgo-quickstart%22%7D%2C%7B%22label%22%3A%22Hugging%20Face%22%2C%22slug%22%3A%22hugging-face%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fhugging-face-quickstart%22%7D%2C%7B%22label%22%3A%22Conda%22%2C%22slug%22%3A%22conda%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fconda-quickstart%22%7D%2C%7B%22label%22%3A%22Dart%22%2C%22slug%22%3A%22dart%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fdart-quickstart%22%7D%2C%7B%22label%22%3A%22PHP%20Composer%22%2C%22slug%22%3A%22php-composer%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fphp-composer-quickstart%22%7D%2C%7B%22label%22%3A%22Swift%22%2C%22slug%22%3A%22swift%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fswift-quickstart%22%7D%2C%7B%22label%22%3A%22Puppet%22%2C%22slug%22%3A%22puppet%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fpuppet-quickstart%22%7D%2C%7B%22label%22%3A%22Terraform%22%2C%22slug%22%3A%22terraform%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fterraform-quickstart%22%7D%2C%7B%22label%22%3A%22R%20(CRAN)%22%2C%22slug%22%3A%22r-cran%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Fr-cran-quickstart%22%7D%2C%7B%22label%22%3A%22RubyGems%22%2C%22slug%22%3A%22rubygems%22%2C%22path%22%3A%22artifact-registry%2Fnew-to-artifact-registry%2Fquickstart%2Frubygems-quickstart%22%7D%5D" selectedPlatform="debian" %}

Use a **Debian** registry to host, proxy, and distribute `.deb` packages compatible with Debian and Ubuntu systems. Harness Artifact Registry supports APT-based package installation, source uploads, and upstream proxying from external Debian repositories.

***

### Before you begin <a href="#before-you-begin" id="before-you-begin"></a>

* **APT package manager:** Available on any Debian or Ubuntu system by default.
* **Harness permissions:** Registry-create access in the target project. Go to [RBAC in Harness](/harness-ai/use-harness-platform/platform-access-control.md) to configure roles.

***

### Create a Debian Artifact Registry <a href="#create-a-debian-artifact-registry" id="create-a-debian-artifact-registry"></a>

{% tabs %}
{% tab title="Interactive Guide" %}
{% embed url="<https://app.tango.us/app/embed/1085f42d-c1a5-42f5-963e-e11045fbdd38>" %}
{% endtab %}

{% tab title="Step-by-Step" %}

1. Go to the Artifact Registry module in your Harness project.
2. Select **New Artifact Registry**.
3. In the Registry Type list, select **Debian**.
4. Provide a Registry Name.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>REGISTRY NAME REQUIREMENTS</strong></p><p>This registry name must start with a letter and can only contain lowercase alphanumerics, <code>_</code>, <code>.</code> and <code>-</code>, and <strong>must be unique to your Harness Account</strong>.</p></div>
5. Optionally, add a Description and Labels for better organization.
6. In the **Debian Config** section, set **Indexed Remote Architectures**. The default values are `amd64`, `i386`, and `arm64`. Select from these defaults or add any additional architectures that need to be indexed from remote repositories.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>INDEXED REMOTE ARCHITECTURES</strong></p><p><strong>Indexed Remote Architectures</strong> lists the architectures Harness indexes from remote repositories on this registry.</p><p>If you leave the field empty, Harness caches all available architectures that results in increased cold-start index generation time and costs.</p><p>If you select values (<code>amd64</code>, <code>i386</code>, <code>arm64</code>) or enter a custom architecture name, Harness indexes only those architectures.</p></div>
7. Harness generates a `.gz` index by default. In **Optional Index Compression Formats**, you can also select **XZ (.xz extension)**, that increases the cold-start index generation time and cost.
8. Choose visibility between **Public** and **Private**.
9. Select **Create Registry** to finalize.
   {% endtab %}
   {% endtabs %}

{% hint style="info" %}
**PRIVATE DEBIAN REGISTRY**

This registry will serve as your private Debian registry within Harness.
{% endhint %}

***

#### Edit Debian configuration <a href="#edit-debian-configuration" id="edit-debian-configuration"></a>

**Debian Config** appears on the registry **Configuration** tab, after Artifact Registry Definition (name, description, and labels).

1. Open the Debian artifact registry.
2. Select the **Configuration** tab.
3. In the **Debian Config**, update **Indexed Remote Architectures**.
4. Optionally, specify the **Optional Index Compression Formats**.
5. Click **Save**.

***

### Configure an upstream proxy (optional) <a href="#configure-an-upstream-proxy-optional" id="configure-an-upstream-proxy-optional"></a>

An upstream proxy allows your registry to fetch Debian packages from external repositories (such as official Debian or Ubuntu mirrors) if they are not available locally.

{% tabs %}
{% tab title="Interactive Guide" %}

#### Create the upstream proxy

{% embed url="<https://app.tango.us/app/embed/f20ab85f-36b8-43e9-88af-1e9fa1a8d46c>" %}

#### Configure the upstream proxy in your registry

{% embed url="<https://app.tango.us/app/embed/f79602c8-797d-4d55-8fe6-7cae35048473>" %}
{% endtab %}

{% tab title="Step-by-Step" %}

#### Create an upstream proxy <a href="#create-an-upstream-proxy" id="create-an-upstream-proxy"></a>

1. In the Artifact Registry module, select the dropdown next to **New Artifact Registry** and select **Upstream Proxy**.
2. Choose **Debian Registry** as the proxy type.
3. Enter an upstream proxy name.
4. Enter your remote repository URL. The URL must point to the **parent directory** of the `/dists` folder for that repository (for example, `http://deb.debian.org/debian`, where `http://deb.debian.org/debian/dists/` contains the release metadata). If you use another Debian mirror or private repository, verify the path ends at that parent level, not at a distribution or component subdirectory.
5. Choose your Authentication method (`Anonymous` by default).
6. Select **Create Proxy** to establish the connection.

#### Configure the upstream proxy in your registry <a href="#configure-the-upstream-proxy-in-your-registry" id="configure-the-upstream-proxy-in-your-registry"></a>

1. In the Artifact Registry module, select an existing Artifact Registry.
2. Select the **Configuration** tab.
3. Under **Advanced (Optional)**, select **Configure Upstream**.
4. Select from the list of compatible proxies to add them to your registry.
5. Select **Save** to save the configuration.
   {% endtab %}
   {% endtabs %}

{% hint style="info" %}
**UPSTREAM PROXY BEHAVIOR**

When you install a package through the upstream proxy, it fetches the package from the configured external repository and caches it locally. Subsequent installs for the same package version are served from the local cache.
{% endhint %}

{% hint style="info" %}
**DEBIAN REGISTRY METADATA**

Harness regenerates Debian registry metadata when you upload or delete an artifact, or when you add or remove an upstream proxy from a registry. This operation can take a couple of minutes, so your changes might not appear in APT metadata immediately.
{% endhint %}

***

### Set up the client <a href="#set-up-the-client" id="set-up-the-client"></a>

With your Debian registry created, you can now configure APT to install packages from your Harness registry.

#### 1. Configure authentication <a href="#id-1-configure-authentication" id="id-1-configure-authentication"></a>

In your Harness Debian Artifact Registry, select **Setup Client** and then **Generate Token** to generate an identity token for authentication.

#### 2. Add the repository to APT sources <a href="#id-2-add-the-repository-to-apt-sources" id="id-2-add-the-repository-to-apt-sources"></a>

```bash
echo "deb [trusted=yes] https://pkg.harness.io/pkg/<ACCOUNT_ID>/<REGISTRY_NAME>/debian <DISTRIBUTION> <COMPONENT>" | sudo tee /etc/apt/sources.list.d/harness.list
```

#### 3. Configure authentication for APT <a href="#id-3-configure-authentication-for-apt" id="id-3-configure-authentication-for-apt"></a>

Create or edit the auth config file:

```bash
sudo vi /etc/apt/auth.conf.d/harness-<REGISTRY_NAME>.conf
```

Add the following content:

```
machine pkg.harness.io
login <USERNAME>
password <TOKEN>
```

#### 4. Update APT cache <a href="#id-4-update-apt-cache" id="id-4-update-apt-cache"></a>

```bash
sudo apt-get update
```

#### 5. Install a package <a href="#id-5-install-a-package" id="id-5-install-a-package"></a>

```bash
sudo apt-get install <ARTIFACT_NAME>=<VERSION>
```

#### 6. Upload a .deb package <a href="#id-6-upload-a-deb-package" id="id-6-upload-a-deb-package"></a>

```bash
curl --location --request PUT 'https://pkg.harness.io/pkg/<ACCOUNT_ID>/<REGISTRY_NAME>/debian/deb?distribution=<DISTRIBUTION>&component=<COMPONENT>' \
--form 'file=@"<FILE_PATH>"' \
--header 'x-api-key: <API_KEY>'
```

#### 7. Upload Debian sources (optional) <a href="#id-7-upload-debian-sources-optional" id="id-7-upload-debian-sources-optional"></a>

Upload a `.dsc` file:

```bash
curl --location --request PUT 'https://pkg.harness.io/pkg/<ACCOUNT_ID>/<REGISTRY_NAME>/debian/dsc?distribution=<DISTRIBUTION>&component=<COMPONENT>' \
--form 'file=@"<FILE_PATH>"' \
--header 'x-api-key: <API_KEY>'
```

Upload a source tarball (for upstream source tarballs, specify the upstream version):

```bash
curl --location --request PUT 'https://pkg.harness.io/pkg/<ACCOUNT_ID>/<REGISTRY_NAME>/debian/src?distribution=<DISTRIBUTION>&component=<COMPONENT>&package=<ARTIFACT_NAME>&version=<VERSION>' \
--form 'file=@"<FILE_PATH>"' \
--header 'x-api-key: <API_KEY>'
```
