Every Linux server you manage runs on packages - the installable units of software that make up the operating system and its applications. This lesson teaches you how package managers work, how to use apt, snap, and dpkg to install, update, and remove software, and how to troubleshoot the package conflicts every DevOps engineer eventually faces. By the end, you will be able to provision a fresh server with exactly the software it needs and keep it patched and healthy.
1. Learning Objectives
By the end of this lesson, you will be able to:
- Explain what a package is and why dependency resolution matters
- Refresh package lists and upgrade installed software safely with
apt - Search for, inspect, install, and remove packages using
apt - Work directly with
.debfiles usingdpkg - Manage sandboxed applications with
snap - Add and manage software repositories, including PPAs
- Troubleshoot the most common package errors: lock conflicts, missing candidates, and broken packages
2. Why This Matters
Imagine you have just received a fresh Ubuntu server from your cloud provider. Before it can do anything useful, it needs an SSH hardening audit, a web server, a runtime, and monitoring agents. Every one of those components is shipped as a package. Package management is how you install that software, how you patch it when a critical CVE is announced, and how you reproduce the same server configuration on staging and production.
Without a package manager you would be downloading random binaries from websites, compiling from source, and hoping that nothing conflicts with anything else. That approach is slow, insecure, and impossible to audit. Linux package managers solve this with three ideas: repositories (trusted, curated sources of software), metadata (versions, descriptions, dependencies), and dependency resolution (automatic installation of everything a package needs to run). Master these three ideas and you can provision any Debian-based server with confidence.
3. Core Concepts
What is a package? On Debian-based systems (Ubuntu, Debian, Pop!_OS), a package is a single archive file with a .deb extension that contains the program's files, its metadata (name, version, description, maintainer), and a list of its dependencies. The .deb format is the building block of the entire system.
Three tools, three layers. You will meet three package tools constantly:
dpkg- the low-level tool that installs, removes, and inspects individual.debfiles. It knows nothing about repositories and does no automatic dependency resolution.apt- the high-level tool (Advanced Package Tool) that talks to repositories, resolves dependencies, and then hands the actual install/remove work todpkg. It is the tool you will use 95% of the time.snap- a modern, sandboxed packaging format developed by Canonical. Snaps bundle the application and all its dependencies together, auto-update, and run confined from the rest of the system.
Repositories. An apt repository is a directory of .deb files plus index files that describe them. Your system lists its repositories in /etc/apt/sources.list and the files under /etc/apt/sources.list.d/. Ubuntu's main repositories are split into components: main (officially supported free software), universe (community-maintained free software), restricted (proprietary drivers), and multiverse (software with legal restrictions). A PPA (Personal Package Archive) is a repository hosted on Launchpad, often used to get newer versions of a single application.
deb http://archive.ubuntu.com/ubuntu jammy main universe restricted multiverse
deb http://security.ubuntu.com/ubuntu jammy-security main universe restricted multiverse
Dependency resolution. Most packages depend on shared libraries and helper programs. When you run apt install nginx, apt reads the repository metadata, builds a dependency graph, and installs every missing dependency automatically. This is the superpower of apt over dpkg: one command, correct result, every time.
4. Hands-On Practice
4.1 Refreshing Package Lists
Your system does not know about new package versions until you download the latest repository indexes. apt update fetches those indexes and never installs anything itself. Run it first, always, especially on a fresh server.
sudo apt update
Hit:1 http://archive.ubuntu.com/ubuntu jammy InRelease
Get:2 http://archive.ubuntu.com/ubuntu jammy-updates InRelease [119 kB]
Get:3 http://security.ubuntu.com/ubuntu jammy-security InRelease [110 kB]
Fetched 1,240 kB in 2s (612 kB/s)
Reading package lists... Done
Building dependency tree... Done
All packages are up to date.
4.2 Upgrading Installed Packages
apt upgrade installs newer versions of every package you already have. It will never remove packages or install new ones on its own. apt full-upgrade (formerly dist-upgrade) is more aggressive: it may install or remove packages when that is required to satisfy a change in dependencies. On a production server, review what apt wants to change before confirming.
sudo apt upgrade # safe: only updates existing packages
sudo apt full-upgrade # aggressive: may add/remove packages for dependencies
4.3 Searching and Inspecting Packages
Before installing, find out what is available. apt search matches package names and descriptions; apt show prints detailed metadata; apt list filters installed or available packages.
apt search nginx # search names and descriptions
apt show nginx # show version, deps, size, description
apt list --installed | wc -l # how many packages are installed?
apt list --upgradable # what has updates pending?
4.4 Installing Packages
Install one package or several at once. Use --no-install-recommends on minimal servers to skip suggested extras and keep the footprint small. Add -y in scripts so apt does not wait for confirmation.
sudo apt install nginx
sudo apt install -y curl htop tree
sudo apt install --no-install-recommends docker.io
4.5 Removing and Cleaning Up
apt remove deletes the program but keeps its configuration files. apt purge deletes everything, including config. After removals, apt autoremove clears packages that were installed only as dependencies and are no longer needed. apt clean empties the local download cache.
sudo apt remove nginx # keep config files
sudo apt purge nginx # remove config files too
sudo apt autoremove # remove orphaned dependencies
sudo apt clean # clear cached .deb files
4.6 Working Directly with dpkg
Sometimes you download a .deb file directly (for example, a vendor's proprietary tool). dpkg handles these files but will not fetch missing dependencies for you, so run sudo apt --fix-broken install afterwards if needed. dpkg -S answers the classic question: which package owns this file?
sudo dpkg -i ./myapp_1.2.3_amd64.deb # install a .deb file
sudo dpkg -r myapp # remove (keep config)
sudo dpkg -l | grep nginx # list installed packages, filtered
dpkg -S /usr/bin/top # which package owns this file?
dpkg -L nginx # list files installed by a package
4.7 Managing Snap Applications
Snaps are self-contained and sandboxed, which makes them great for GUI applications and tools that need bleeding-edge versions. They update automatically in the background. Common snap commands mirror apt.
sudo snap install htop # install from the Snap Store
snap list # list installed snaps
sudo snap refresh # update all snaps
sudo snap remove htop # remove a snap
4.8 Adding Repositories
When a package is not in the official repositories, add a PPA (for Ubuntu) or a vendor repository. After adding any repository you must run apt update so your system learns about its contents.
sudo add-apt-repository ppa:deadsnakes/ppa # add a PPA (e.g. newer Pythons)
sudo apt update
sudo apt install python3.12 # now available from the PPA
5. Common Errors & Solutions
Error 1: "Unable to locate package nginx". Your local package index is empty or stale, so apt has nothing to search. Fix: refresh the index, then retry.
sudo apt update
sudo apt install nginx
Error 2: "Could not get lock /var/lib/dpkg/lock-frontend". Another apt process is already running (or a crashed one left the lock behind). Find it and wait for it to finish.
ps aux | grep -E 'apt|dpkg' # is an install still running?
sudo lsof /var/lib/dpkg/lock-frontend
Error 3: "Package has no installation candidate". The package is not in any enabled component. On Ubuntu, many tools live in universe, which is disabled on minimal installs.
sudo add-apt-repository universe
sudo apt update
Error 4: "dpkg: error processing package ... (--configure)". A package's post-install script failed, often after an interrupted install. Let dpkg finish configuring everything pending.
sudo dpkg --configure -a
sudo apt --fix-broken install
Error 5: "You might want to run 'apt --fix-broken install'". A partial install left broken dependencies. apt can repair itself in one command.
sudo apt --fix-broken install
6. Summary Checklist
- I can refresh package lists with
sudo apt update - I can upgrade safely with
sudo apt upgradeand know when to usefull-upgrade - I can search, inspect, and install packages with
apt search,apt show, andapt install - I can remove and purge packages and clean orphans with
autoremove - I can install and query
.debfiles directly withdpkg - I can install and refresh sandboxed apps with
snap - I can add a PPA or repository and know where my sources are configured
- I can fix lock conflicts, missing candidates, and broken packages
7. Practice Exercise
Provision a throwaway VM or container and complete these tasks end to end:
- Refresh your package lists with
apt update - Install
nginxandcurlin one command - Verify the install with
dpkg -l | grep nginxand confirm nginx is running withsystemctl status nginx - Use
dpkg -Sto find which package owns/usr/bin/curl - Remove
nginxwithapt purge, keepingcurlinstalled - Install
tree, use it, then remove it and runapt autoremove - Install one snap (for example
sudo snap install hello-world) and runsnap list
sudo apt update && sudo apt install -y nginx curl
dpkg -S /usr/bin/curl
sudo apt purge -y nginx && sudo apt autoremove -y
sudo snap install hello-world && snap list
8. Next Steps
You can now provision and maintain software on any Debian-based server: find it, install it, patch it, and remove it cleanly. That closes out the core Linux system administration loop, from files and permissions to processes, text processing, services, networking, and packages. The next lesson in the Linux series moves into Bash Scripting - Conditionals, Loops, and Functions, where you will automate everything you have learned so far: scripting file operations, checking processes, probing networks, and installing packages with a single repeatable command.
Comments (0)
This is exactly what I needed! The initContainer approach solved our migration issues completely. Thanks for the detailed guide!
ReplyLeave a Comment