Skip to content

Install from APT or YUM

The OpenSight artifact repository is a signed APT and YUM/DNF repo. Add it once; apt upgrade / dnf upgrade then pick up LinkMesh releases with the rest of the host’s updates, and the package manager verifies every package against the signing key before it installs.

This is the path to use when you want auto-updates. For a one-shot .deb / .rpm / Docker install, see the Quickstart. For Kubernetes, see Install on Kubernetes.

The repository publishes only the architectures below. apt and dnf/yum select the package that matches the host; do not paste a per-architecture file URL and assume the filename is what you get.

Package APT YUM / DNF
linkmesh-server amd64, arm64 x86_64, aarch64
linkmesh-agent amd64, arm64 x86_64, aarch64

After install, confirm the package you got:

# Debian / Ubuntu
dpkg-query -f '${Package} ${Architecture}\n' -W linkmesh-server

# RHEL / Rocky / AlmaLinux / Fedora
rpm -q --qf '%{NAME} %{ARCH}\n' linkmesh-server

Windows is not served by this repository. The optional agent on Windows is a binary; see Install the agent.

curl -fsSL https://artifacts.saas.opensight.ch/gpg-key | sudo gpg --dearmor -o /usr/share/keyrings/opensight.gpg
echo "deb [signed-by=/usr/share/keyrings/opensight.gpg] https://artifacts.saas.opensight.ch/apt stable main" | sudo tee /etc/apt/sources.list.d/opensight.list
sudo apt update
sudo apt install linkmesh-server

The same repository also has the optional agent: sudo apt install linkmesh-agent.

Future apt upgrade calls pick up new releases. You do not re-run the key or sources.list steps.

YUM / DNF (RHEL / Rocky / AlmaLinux / Fedora)

Section titled “YUM / DNF (RHEL / Rocky / AlmaLinux / Fedora)”

Works with dnf, yum, and microdnf.

sudo rpm --import https://artifacts.saas.opensight.ch/gpg-key
cat <<EOF | sudo tee /etc/yum.repos.d/opensight.repo
[opensight]
name=OpenSight Artifacts
baseurl=https://artifacts.saas.opensight.ch/yum
gpgcheck=1
gpgkey=https://artifacts.saas.opensight.ch/gpg-key
EOF
sudo dnf install linkmesh-server

Use sudo yum install linkmesh-server on hosts that do not have dnf. The optional agent is sudo dnf install linkmesh-agent.

Future dnf upgrade / yum update calls pick up new releases. You do not re-import the key or rewrite the repo file.

One canonical URL:

https://artifacts.saas.opensight.ch/gpg-key

Verify the key out of band before you dearmor it onto a host. Fetch it and print the fingerprint:

curl -fsSL https://artifacts.saas.opensight.ch/gpg-key | gpg --show-keys --fingerprint

The output must match:

pub   rsa4096 2026-04-07 [SCEAR]
      FDA3 156E D81C 9226 A7DC  D3CF 61D8 E6EA 3694 FE19
uid                      OpenSight Artifacts <[email protected]>

If the fingerprint differs, stop. Do not add the repository, and do not install from it.

The signed-by (APT) and gpgcheck=1 (YUM/DNF) entries in the commands above then tell the package manager to reject any package that is not signed by this key.

  • Server. The package starts the systemd service and seeds an admin account whose password is never logged. Set your own, then sign in — see Quickstart from the password-reset step onward.
  • Agent. Configure the enrollment token, then start the service — see Install the agent.
  • Upgrades. Once the repository is configured, upgrading is apt upgrade linkmesh-server / dnf upgrade linkmesh-server. The full order, backups, and rollback live on Upgrade LinkMesh; that page points here rather than restating these commands.
  • What changed. Read the changelog before you take a new version. LinkMesh version numbers do not carry a semver major warning; the changelog is what marks a breaking release.