Linux Basics 2 · Lesson 7 · 35 min

More ways to install: vendor repos, Snap, Flatpak, AppImage

dnf and apt install what your distribution packages. But plenty of software isn't in there: it's too new, the license is different, or the company prefers to ship it itself. So there are other ways in: the company's own repository, the Snap store, Flathub, and single-file AppImages. Each one trusts someone different, and knowing who you're trusting is the real lesson.

You will learn

  • Adding a vendor's repository safely, with its signing key (HashiCorp's, for terraform)
  • Snaps: snap find, install, list, and automatic updates
  • Flatpak and Flathub: sandboxed desktop apps and their permissions
  • AppImages: download, chmod +x, run, and why they need FUSE
  • Why curl … | sudo bash deserves a second look

Who are you trusting?

WayYou trustUpdatesGood for
distro repos (dnf/apt)Rocky / Ubuntu, who build and test everythingwith the rest of the systemalmost everything on a server
vendor repothe company (Docker, HashiCorp, Microsoft, Google…)with dnf/apt, once addednewer or not-in-the-distro software
Snapthe publisher, via Canonical's Snap Storeautomatic, in the backgroundUbuntu, servers and desktops
Flatpakthe publisher, via Flathubflatpak updatedesktop apps on any distro
AppImagewhoever made that one fileby hand (download again)trying a program without installing it

Vendor repositories, and why keys matter

A repository signs its package lists with a GPG key. Your package manager checks every download against that key, so nobody can slip in a fake package, even through a hacked mirror. Adding a repo therefore always has two parts: where to download from, and which key to trust.

Rocky / RHEL
sudo dnf config-manager --add-repo \
  https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo
cat /etc/yum.repos.d/hashicorp.repo   # baseurl + gpgkey
sudo dnf install terraform
# first install: "Importing GPG key 0xA621E701 …"
# check the fingerprint, then answer y
Ubuntu / Debian
curl -fsSL https://apt.releases.hashicorp.com/gpg \
  | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] \
https://apt.releases.hashicorp.com noble main" \
  | sudo tee /etc/apt/sources.list.d/hashicorp.list
sudo apt update
sudo apt install terraform

The signed-by= part says "only trust this key for this repo". Without the key, apt update refuses with NO_PUBKEY. That's the system protecting you, not a bug. Copy these commands from the vendor's own website, and compare the key's fingerprint with the one they publish (gpg --show-keys).

curl … | sudo bash

Some install guides say curl https://example.com/install.sh | sudo bash. That runs a script you haven't read, as root, straight from the internet. From a well-known vendor over HTTPS it's often fine, but download it first (curl -O), read it (less install.sh), then run it. Never do it with a link from a random forum post.

Snap

snap find hello
sudo snap install hello-world
hello-world                     # Hello World!
snap list
sudo snap refresh               # snaps update themselves ~4 times a day anyway
sudo snap remove hello-world

A snap carries its own libraries, so the same snap runs on any Ubuntu version (and other distros). Most snaps are confined: they only see the files and devices they declare. --classic snaps (like certbot) aren't confined, which is why snap makes you type it.

Rocky / RHEL

Not built in. EPEL has it: sudo dnf install epel-release, sudo dnf install snapd, sudo systemctl enable --now snapd.socket. Red Hat's family generally prefers Flatpak.

Ubuntu / Debian

snapd is installed on Ubuntu, and some Ubuntu tools themselves come as snaps (like LXD). Debian doesn't include it by default.

Flatpak

sudo flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
flatpak search calculator
sudo flatpak install flathub org.gnome.Calculator
flatpak list
flatpak info --show-permissions org.gnome.Calculator
flatpak run org.gnome.Calculator

Flatpak is made for desktop apps: each one runs in a sandbox with the permissions it asks for (network, your Downloads folder, the screen…). Apps share runtimes (a big shared base like the GNOME Platform), so the first app downloads a lot and the next ones much less. On a server there's no screen, so apps can't open. That's fine: you're learning the tool here.

AppImage

curl -LO https://github.com/neovim/neovim/releases/latest/download/nvim-linux-x86_64.appimage
chmod u+x nvim-linux-x86_64.appimage
./nvim-linux-x86_64.appimage --version

One file, the whole program inside. Nothing gets installed: delete the file and it's gone. AppImages mount themselves using FUSE 2. If that library is missing you get "dlopen(): error loading libfuse.so.2". Install it (fuse-libs on Rocky, libfuse2t64 on Ubuntu 24.04), or unpack the file instead with --appimage-extract.

Practice: install four ways 🧰

Install Terraform from HashiCorp's repository, a snap, a Flatpak app, and Neovim as an AppImage (a vim-person's treat).

Quick check

1. apt update says NO_PUBKEY AA16FCBCA621E701 for a repo you just added. What's wrong?

2. What's special about a Flatpak app compared with one from dnf or apt?

3. A guide says curl https://get.example.sh | sudo bash. What's the careful way?

Finished the missions and the quiz? Mark it done to track your progress.