I am undertaking an overhaul of the OI IPS repository operation.  The following 
is as brief a statement of the absolutes of proper software repository 
management at enterprise scale as I can make.
I should be most interested in additional constraints anyone might wish to 
suggest or use cases that these would interfere with.  My base operating 
environment case is big oil operations where failures can be fatal and 
requirements very dynamic and on  time frames and in software environments that 
cannot allow a system update.
I am also getting concerned about so called "supply chain attacks" on 
repositories.  Once I have implemented the framework for the listed items, 
adding additional safeguards is fairly simple.  What I've outlined already 
blocks many such attacks.  ZFS should cover the rest.
Have Fun!Reg
------------------------------------------------------------------------------------------------------------------------------------
The OI repositories should meet the following criteria:
1) Any package published in the repository in the interval between releases 
should be available indefinitely.  Disk is cheap.  Forcing a "pkg upgrade" to 
add one new package not installed when the system was built  is not tolerable.  
Especially if you are on the end of a BW limited channel.
2) No package installed from the repository has missing files or dependencies.
3) No package installed from the repository modifies other packages.
4) No package modifies existing system configuration files without making a 
backup copy that does NOT overwrite a prior backup copy.
_______________________________________________
openindiana-discuss mailing list
[email protected]
https://openindiana.org/mailman/listinfo/openindiana-discuss

Reply via email to