---
tags:
- linux
- l1
- flashcard-deck
- package-management
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Package Management](../../../../library/portal/topics.md) | **Domain:** Linux
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
package-management/a3b7c1d9e4f2	package-management	easy	package-management, apt, dpkg, debian	What is the difference between dpkg and apt on Debian/Ubuntu systems?	dpkg is the low-level tool that operates on individual .deb files without resolving dependencies. apt is the high-level tool that resolves dependencies, fetches packages from repositories, and handles upgrades. Use apt for routine work; use dpkg for inspection and emergencies.\n\nExample: apt update refreshes the package index; apt upgrade installs newer versions. Always update before upgrade.\n\nGotcha: apt update does NOT install packages — it only downloads the latest package lists.	training/library/topics/package-management/primer.md
package-management/b5e8f2a1c7d3	package-management	easy	package-management, file-ownership, troubleshooting	How do you find which installed package owns a specific file on a Debian system?	Run dpkg -S /path/to/file. For example, dpkg -S /usr/sbin/nginx returns nginx-core: /usr/sbin/nginx. On Red Hat systems, use rpm -qf /path/to/file.\n\nRemember: "apt search FINDS, apt show DESCRIBES, dpkg -l LISTS installed." Example: apt search nginx | head -20	training/library/topics/package-management/primer.md
package-management/c9d4e6f3a2b8	package-management	easy	package-management, apt, versions, policy	How do you check which version of a package is installed and what versions are available on Debian/Ubuntu?	Run apt-cache policy <package>. It shows the installed version, the candidate version for upgrade, and all available versions with their repository sources and priorities.\n\nExample: dpkg -L nginx lists every file installed by the nginx package. Reverse lookup: dpkg -S /usr/sbin/nginx shows which package owns that file.\n\nGotcha: apt list --installed only shows apt-managed packages, not manually compiled ones.	training/library/topics/package-management/primer.md
package-management/d1f7a3b5c8e2	package-management	easy	package-management, cache, docker, disk	Why should you clean the package cache in a Dockerfile, and how?	Package caches bloat image layers. In Debian-based images, add apt-get clean && rm -rf /var/lib/apt/lists/* in the same RUN layer as the install. In Red Hat-based images, use dnf clean all. Placing cleanup in a separate RUN layer does not reduce image size because Docker layers are additive.\n\nRemember: "Pin to prevent pain" — version pinning stops surprise upgrades. Example: apt-mark hold nginx freezes nginx at current version.	training/library/topics/package-management/primer.md
package-management/e4a2b8c6d1f5	package-management	medium	package-management, pinning, hold, upgrade-safety	How do you prevent a specific package from being upgraded on Debian/Ubuntu, and what is the risk of doing so?	Use apt-mark hold <package> to hold it. The risk is that a held package can block apt upgrade entirely if other packages depend on a newer version of the held package. Unattended-upgrades may silently skip entire security transactions as a result. Monitor /var/log/unattended-upgrades/ for failures.	training/library/topics/package-management/primer.md
package-management/f6c3d9e7a4b1	package-management	medium	package-management, gpg, security, repositories	Why is using --nogpgcheck or --allow-unauthenticated dangerous in production, and what is the correct way to add a third-party repository?	Disabling signature verification means a compromised mirror can push arbitrary binaries to your fleet. The correct approach is to download the GPG key, store it (e.g., /usr/share/keyrings/ on Debian), and reference it with signed-by in the sources list. On Red Hat, import the key with rpm --import before adding the repo.	training/library/topics/package-management/primer.md
package-management/a8b1c5d3e7f9	package-management	medium	package-management, troubleshooting, broken-packages, dpkg	Walk through the triage sequence for a broken dpkg state on a Debian/Ubuntu system.	1. dpkg --audit to identify broken packages. \n2. apt --fix-broken install to let apt resolve dependencies. \n3. dpkg --configure -a to finish pending post-install configurations. \n4. If still broken, dpkg --remove --force-remove-reinstreq <package> then reinstall. \n5. Review /var/log/dpkg.log and /var/log/apt/history.log for the timeline of what went wrong.	training/library/topics/package-management/primer.md
package-management/b2d6e9f4a1c7	package-management	medium	package-management, security-updates, patching, production	What is the recommended production pattern for applying security updates across a fleet?	Stage security updates through dev -> staging -> prod with a 24-48 hour bake time between stages. Automate the promotion pipeline. On Debian, use unattended-upgrades configured to apply only security origins. On Red Hat, use dnf upgrade --security. Never skip staging even for security-only patches because they can still break application behavior.	training/library/topics/package-management/primer.md
package-management/c7e3f1a5b9d2	package-management	hard	package-management, rollback, dnf, history, disaster-recovery	How does dnf history undo work, and why is the lack of an equivalent on Debian systems a significant operational gap?	dnf history undo <transaction-id> reverses a specific transaction by removing packages that were installed and reinstalling packages that were removed. This provides native rollback for bad upgrades. Debian has no built-in transaction rollback. You must track changes externally using tools like Ansible, etckeeper, or log parsing of /var/log/apt/history.log. This makes Debian fleet recovery slower and more error-prone after a bad upgrade.	training/library/topics/package-management/primer.md
package-management/d5f8a2c4b7e1	package-management	hard	package-management, pinning, apt-preferences, priority	Explain Debian APT pinning priorities: what do priority values 1001, 500, 100, and -1 mean, and when would you use a priority above 1000?	Priority 500 is the default for packages from non-target repositories. 100 is the default for already-installed packages. -1 means never install. 1001 or higher forces installation even if it requires a downgrade. You would use priority >1000 to force-pin a specific version when you need to downgrade a package and prevent apt from upgrading it back. This is a blunt instrument — it overrides normal dependency resolution and should be paired with monitoring.	training/library/topics/package-management/primer.md
package-management/e1a9b3c6d8f4	package-management	hard	package-management, lock-files, race-condition, cloud-init	What causes apt lock file contention in cloud environments, and how do you handle it safely?	Lock contention typically occurs when cloud-init runs apt operations on boot at the same time as your provisioning automation (Ansible, user-data scripts). The locks are /var/lib/dpkg/lock-frontend and /var/lib/apt/lists/lock. The safe approach is to run cloud-init status --wait before any apt operations in your automation. Never delete lock files directly — use lsof to identify the holding process and wait for it to finish or kill it if it is genuinely stale.	training/library/topics/package-management/primer.md
package-management/f3b7d2e5a9c1	package-management	hard	package-management, fleet-drift, audit, comparison	How would you audit and compare installed package versions across a fleet of servers to detect drift?	Export the package list from each host: dpkg-query -W -f='${Package}\t${Version}\n' (Debian) or rpm -qa --queryformat '%{NAME}\t%{VERSION}-%{RELEASE}\n' (Red Hat). Collect these to a central location and diff them. For real-time drift detection, use configuration management tools (Ansible, Puppet) to enforce a declared package state, or tools like osquery to query installed packages across the fleet as a database.	training/library/topics/package-management/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Debian & Ubuntu Ecosystem](../../../../library/topics/debian-ubuntu/index.md) (Topic Pack, L1) — Package Management
- [Linux Ops](../../../../library/topics/linux-ops/index.md) (Topic Pack, L0) — Package Management
- [Package Management](../../../../library/topics/package-management/index.md) (Topic Pack, L1) — Package Management
- [Skillcheck: Linux Fundamentals](../../../../library/skillchecks/linux.fundamentals.md) (Assessment, L0) — Package Management

<!-- wiki:related:end -->
