obpkg.org

The download domain for OpenBasalt packages: the Basalt OS package repositories, OpenBasalt tools, an apt repository for Debian and Ubuntu, and the OpenBasalt release key. Everything published here is signed with that key.

Release key

Public key: https://obpkg.org/keys/openbasalt-release-key.asc

Primary key fingerprint (OpenBasalt release key <openbasalt@openbasalt.org>):

3601 7348 42BD 4E48 2D19  DE4A E4EE D5EC A395 B302

Download the key and check that the fingerprint matches before you trust it:

curl -fsSLO https://obpkg.org/keys/openbasalt-release-key.asc
gpg --show-keys --with-fingerprint openbasalt-release-key.asc

To check packages with rpm on a system that does not have the key yet, import the file you just verified:

sudo rpm --import openbasalt-release-key.asc

Basalt OS already ships this key in its basalt-release package, so there is nothing to import there. Packages and repository metadata are both signature checked.

Repositories

The Basalt OS, Basalt tools, Basalt testing and apt repositories are live.

Path Content Status
/basalt/ Basalt OS packages. Required, enabled by default. Release 44: /basalt/44/x86_64/ and /basalt/44/source/. Available
/basalt-tools/ Official OpenBasalt tools for Basalt OS and other Fedora-based systems where they apply. Currently: Samba Conductor. Release 44: /basalt-tools/44/x86_64/. Available
/basalt-testing/ Packages on their way to /basalt/. Opt-in, off by default. Currently: the Basalt desktop shell preview. Release 44: /basalt-testing/44/x86_64/. Available
/apt/ OpenBasalt packages for Debian and Ubuntu: Debian 13, Ubuntu 26.04 and Ubuntu 24.04, amd64 and arm64. Currently: Samba Conductor. Suite stable, component main. Available

Use it

Basalt OS installs come with the repositories preconfigured by the basalt-release package, along with the release key, so there is nothing to set up there.

The [basalt] section of /etc/yum.repos.d/basalt.repo as basalt-release ships it:

[basalt]
name=Basalt OS $releasever - $basearch
baseurl=$basalt_repo_url/$releasever/$basearch/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-basalt
metadata_expire=6h

$basalt_repo_url is a dnf variable read from /etc/dnf/vars/basalt_repo_url, which contains https://obpkg.org/basalt. /etc/pki/rpm-gpg/RPM-GPG-KEY-basalt is the release key above. The same file also defines [basalt-tools], on by default, and [basalt-testing], off by default, with their base URLs in /etc/dnf/vars/basalt_tools_url and /etc/dnf/vars/basalt_testing_url.

Packages are signed by the packages subkey of the release key, with fingerprint 3024 61D2 6520 E077 D07F FCA9 AA27 C62C 36CC FC4B. Repository metadata is signed too, in a detached repomd.xml.asc next to each repomd.xml.

Basalt tools

/basalt-tools/ carries the official OpenBasalt tools for Basalt OS, and for other Fedora-based systems where they apply. More tools will be added over time. Packages are signed by the same packages subkey as /basalt/. There is no source repository; each tool's source lives in its own project.

Currently: Samba Conductor (docs), as conductor, conductor-idp, conductor-sync, conductor-backup and conductor-files, each with its -selinux policy package.

On Basalt OS this repository is enabled by default, since basalt-release 44-7. Install a tool directly, for example:

sudo dnf install conductor

To turn the repository off:

sudo dnf config-manager setopt basalt-tools.enabled=0

On other Fedora-based systems, set it up by hand: save this as /etc/yum.repos.d/basalt-tools.repo:

[basalt-tools]
name=Basalt OS tools $releasever - $basearch
baseurl=https://obpkg.org/basalt-tools/$releasever/$basearch/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=https://obpkg.org/keys/openbasalt-release-key.asc
metadata_expire=6h

Then install a tool, for example:

sudo dnf install conductor

Basalt testing

/basalt-testing/ carries packages on their way to /basalt/, for people who want to try them early. It is opt-in and off by default. Packages are signed by the same packages subkey as /basalt/.

Currently: the Basalt desktop shell preview, as basalt-shell with its basalt-shell-selinux policy package (source).

On Basalt OS, basalt-release already defines the repository. Enable it, then install the preview:

sudo dnf config-manager setopt basalt-testing.enabled=1
sudo dnf install basalt-shell

On Fedora 44, dnf is dnf5 and config-manager comes from the dnf5-plugins package; if dnf reports an unknown command, run sudo dnf install dnf5-plugins first.

To try a package without leaving the repository enabled, use it for a single command instead:

sudo dnf --enablerepo=basalt-testing install basalt-shell

To turn it off again:

sudo dnf config-manager setopt basalt-testing.enabled=0

Debian and Ubuntu

/apt/ carries OpenBasalt packages for Debian 13, Ubuntu 26.04 and Ubuntu 24.04, on amd64 and arm64. More packages will be added over time. The packages are the same for every release listed, so one suite, stable, serves all of them. The repository metadata (InRelease and Release.gpg) is signed by the same packages subkey as the other repositories, and apt checks it against the key you name for this repository only.

Currently: Samba Conductor (docs), as conductor, conductor-idp, conductor-sync, conductor-backup and conductor-files.

Download the release key, check its fingerprint against the one above, then install it as a keyring for apt:

curl -fsSLO https://obpkg.org/keys/openbasalt-release-key.asc
gpg --show-keys --with-fingerprint openbasalt-release-key.asc
sudo install -d -m 0755 /etc/apt/keyrings
sudo gpg --dearmor -o /etc/apt/keyrings/openbasalt.gpg openbasalt-release-key.asc

Save this as /etc/apt/sources.list.d/openbasalt.sources:

Types: deb
URIs: https://obpkg.org/apt
Suites: stable
Components: main
Signed-By: /etc/apt/keyrings/openbasalt.gpg

Then update and install a package, for example:

sudo apt update
sudo apt install conductor

Installing a package creates its system user and directories and starts nothing: each component needs its configuration first, described in its documentation. Older versions stay in the repository, so apt install conductor=<version> can go back to one.

Mirrors

Mirrors are not offered. obpkg.org is the single official download location. Because every package and every repository index is signed, a copy you host yourself can be checked against the release key above.

More