More ways to install: vendor repos, Snap, Flatpak, AppImage
dnf and apt install what your distribution packages. But plenty of software isn't in there: it's too new, the license is different, or the company prefers to ship it itself. So there are other ways in: the company's own repository, the Snap store, Flathub, and single-file AppImages. Each one trusts someone different, and knowing who you're trusting is the real lesson.
You will learn
- Adding a vendor's repository safely, with its signing key (HashiCorp's, for
terraform) - Snaps:
snap find,install,list, and automatic updates - Flatpak and Flathub: sandboxed desktop apps and their permissions
- AppImages: download,
chmod +x, run, and why they need FUSE - Why
curl … | sudo bashdeserves a second look
Who are you trusting?
| Way | You trust | Updates | Good for |
|---|---|---|---|
distro repos (dnf/apt) | Rocky / Ubuntu, who build and test everything | with the rest of the system | almost everything on a server |
| vendor repo | the company (Docker, HashiCorp, Microsoft, Google…) | with dnf/apt, once added | newer or not-in-the-distro software |
| Snap | the publisher, via Canonical's Snap Store | automatic, in the background | Ubuntu, servers and desktops |
| Flatpak | the publisher, via Flathub | flatpak update | desktop apps on any distro |
| AppImage | whoever made that one file | by hand (download again) | trying a program without installing it |
Vendor repositories, and why keys matter
A repository signs its package lists with a GPG key. Your package manager checks every download against that key, so nobody can slip in a fake package, even through a hacked mirror. Adding a repo therefore always has two parts: where to download from, and which key to trust.
sudo dnf config-manager --add-repo \ https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo cat /etc/yum.repos.d/hashicorp.repo # baseurl + gpgkey sudo dnf install terraform # first install: "Importing GPG key 0xA621E701 …" # check the fingerprint, then answer y
curl -fsSL https://apt.releases.hashicorp.com/gpg \ | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] \ https://apt.releases.hashicorp.com noble main" \ | sudo tee /etc/apt/sources.list.d/hashicorp.list sudo apt update sudo apt install terraform
The signed-by= part says "only trust this key for this repo". Without the key, apt update refuses with NO_PUBKEY. That's the system protecting you, not a bug. Copy these commands from the vendor's own website, and compare the key's fingerprint with the one they publish (gpg --show-keys).
curl … | sudo bash
Some install guides say curl https://example.com/install.sh | sudo bash. That runs a script you haven't read, as root, straight from the internet. From a well-known vendor over HTTPS it's often fine, but download it first (curl -O), read it (less install.sh), then run it. Never do it with a link from a random forum post.
Snap
snap find hello sudo snap install hello-world hello-world # Hello World! snap list sudo snap refresh # snaps update themselves ~4 times a day anyway sudo snap remove hello-world
A snap carries its own libraries, so the same snap runs on any Ubuntu version (and other distros). Most snaps are confined: they only see the files and devices they declare. --classic snaps (like certbot) aren't confined, which is why snap makes you type it.
Not built in. EPEL has it: sudo dnf install epel-release, sudo dnf install snapd, sudo systemctl enable --now snapd.socket. Red Hat's family generally prefers Flatpak.
snapd is installed on Ubuntu, and some Ubuntu tools themselves come as snaps (like LXD). Debian doesn't include it by default.
Flatpak
sudo flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo flatpak search calculator sudo flatpak install flathub org.gnome.Calculator flatpak list flatpak info --show-permissions org.gnome.Calculator flatpak run org.gnome.Calculator
Flatpak is made for desktop apps: each one runs in a sandbox with the permissions it asks for (network, your Downloads folder, the screen…). Apps share runtimes (a big shared base like the GNOME Platform), so the first app downloads a lot and the next ones much less. On a server there's no screen, so apps can't open. That's fine: you're learning the tool here.
AppImage
curl -LO https://github.com/neovim/neovim/releases/latest/download/nvim-linux-x86_64.appimage chmod u+x nvim-linux-x86_64.appimage ./nvim-linux-x86_64.appimage --version
One file, the whole program inside. Nothing gets installed: delete the file and it's gone. AppImages mount themselves using FUSE 2. If that library is missing you get "dlopen(): error loading libfuse.so.2". Install it (fuse-libs on Rocky, libfuse2t64 on Ubuntu 24.04), or unpack the file instead with --appimage-extract.
Practice: install four ways 🧰
Install Terraform from HashiCorp's repository, a snap, a Flatpak app, and Neovim as an AppImage (a vim-person's treat).
Quick check
1. apt update says NO_PUBKEY AA16FCBCA621E701 for a repo you just added. What's wrong?
✓ Download the vendor's key, dearmor it into that path, and update again.
2. What's special about a Flatpak app compared with one from dnf or apt?
✓ flatpak info --show-permissions shows what it may do.
3. A guide says curl https://get.example.sh | sudo bash. What's the careful way?
✓ You're about to give a stranger's script root. Look first.