How to Point APT at Chainsaw
Configure APT on Debian/Ubuntu to fetch packages through your Chainsaw proxy via sources.list and auth.conf.
Copies the raw Markdown source of this guide, for pasting into an LLM or notes.
Overview
Point APT at your Chainsaw instance so Debian/Ubuntu package fetches
route through the firewall. This page covers sources.list and
auth.conf.
Replace
chain305.com with your own Chainsaw deployment host
and swap CLIENT_ID / CLIENT_SECRET for credentials issued from the
Access page in the dashboard. The @default segment is the org
slug — confirm yours under Settings → Organization → Slug. Legacy
non-org-scoped URLs return HTTP 400 with error CHW-4314.Prerequisites
- A running Chainsaw instance (see Tutorial 01)
- Client credentials (Client ID and Secret)
- A Debian/Ubuntu host with APT
sources.list
deb https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/apt-main/ stable main
auth.conf
machine chain305.com
login CLIENT_ID
password CLIENT_SECRET
apt auth.conf(5) supports path-scoped machine tokens
(e.g. machine chain305.com/chainproxy/repository/apt-main) if you want
to restrict these credentials to Chainsaw repositories only and share
the same auth.conf with other APT mirrors on the same host. A bare
host is fine when Chainsaw is the only thing listening there.Verify
Run apt update, then confirm with chainsaw doctor verify-hook and
the Traffic page in the dashboard.
Next Steps
- How to Configure Your Package Manager to Use Chainsaw — All ecosystems in one place
- How to Manage Repositories and Upstream Mirrors