Перейти к содержимому

Package Management: DNF & RPM Forensics, Repos, History Rollback | Zero to LLMOps (Day 9)

Zero to LLMOps

0:00 / 0:00

Package Management: DNF & RPM Forensics, Repos, History Rollback | Zero to LLMOps (Day 9)

61 просмотр · 2 недели назад
Zero to LLMOps
44 подписчика
61 просмотр · 2 недели назад
Day 9 of a free 180-day DevOps course. Yesterday we learned to see and control running processes. Today: where does software actually come from in the first place? Every command you type in Linux arrived inside a package. Today you learn how software is packaged, verified, and managed on Enterprise Linux (RHEL, CentOS Stream, Fedora) using RPM and DNF. More importantly, you master 3 operational superpowers: tracing unknown disk files back to their parent package, safely rolling back multi-package transactions, and auditing cryptographic repo signatures. What we cover today: • RPM vs DNF: RPM queries the offline local database; DNF handles repos, networks, and dependency resolution. • RPM Query Family: rpm -q (is it installed?), -qi (provenance & license), -ql (file list), and -qa (inventory). • Forensics Move (rpm -qf): Tracing any mystery binary or config file back to its package owner. • The Unowned File Trap: Why /etc/passwd has no package owner; shipped content vs runtime state. • Package Verification (rpm -V): Checking files against build-time checksums; letter codes (5, S, T, M). • DNF Operations: search, info (checking repo source), install, remove, and reinstall (repairing files). • check-update & Exit Code 100: Detecting pending updates in scripts without running full upgrades. • Package Groups: Installing complete toolchains via dnf group install. • Repos & Trust: /etc/yum.repos.d/ config format, baseurl, mirrorlist, and gpgcheck=1. • Security Auditing: Automating gpgcheck audits with grep to detect unsigned third-party repos. • Repo Trust Decision: Why adding third-party repos is granting root privileges to an external vendor. • DNF History Safety Net: Transaction logging, inspecting dependencies, and atomic rollbacks. • Rollback Demo: Reversing installs with dnf history undo; why undo appends instead of rewriting past state. • Modularity: AppStream streams (dnf module list) for parallel runtime versions. • 5-Step Forensics Workflow: Investigating unknown or corrupted files on production systems. ⏱ Chapters 00:00 Intro: Software Provenance & Package Management 01:12 Recall: SIGTERM vs SIGKILL, kill -0 & /proc/PID/fd 02:35 Hook: Where Did PID 1 (systemd) Come From? 02:57 Part A: RPM the Low-Level & Local Database 04:16 Demo: Querying Installed Packages (rpm -q, -qi, -ql, -qa) 05:14 The Forensics Move: rpm -qf (Who Owns This File?) 06:36 The Unowned File Trap: Why /etc/passwd Has No Package Owner 07:38 Package Verification: rpm -V (Silence Means Clean) 08:22 Demo: Catching Tampered Files with rpm -V (Timestamp & Checksum) 09:37 Part B: DNF the Daily Driver (dnf vs yum, search & info) 10:37 Demo: Checking Status Before Installing (rpm -q vs dnf info) 11:05 Installing Packages & Reading Transaction Summaries (dnf install tree) 12:20 Pending Updates & Exit Code 100: dnf check-update 13:37 Package Groups: Bundles & Development Tools (dnf group list) 14:20 Part C: Repositories & /etc/yum.repos.d/ Configuration 15:53 Cryptographic Trust: gpgcheck=1 & Package Signatures 16:44 Security Audit Demo: Finding Unsigned Repositories with grep 17:51 Adding Third-Party Repositories: Granting Root to a Stranger 18:32 Part D: DNF History & Transaction Safety Net 19:39 Rollback Demo: Rolling Back Transactions (dnf history undo) 20:25 Append-Only History: Why DNF Undos Never Rewrite Past State 20:52 Limits of Rollback: Packages vs Config Edits & User Data 21:16 Modularity & AppStream Streams (dnf module list) 22:37 The 5-Step "What Is This File?" Forensics Workflow 23:49 Demo: Broken File Forensics & Restoration (dnf reinstall) 24:50 Lab Walkthrough: Part 1 - RPM Forensics & Deliberate Tampering 26:20 Lab Walkthrough: Part 2 - DNF Daily Ops, tree & check-update 27:36 Lab Walkthrough: Part 3 - DNF History & Undo Rollback Cycle 28:35 Lab Walkthrough: Part 4 - Repo Config Files & gpgcheck Audit 29:13 Recap: RPM vs DNF Mental Model & Owned vs Unowned Files 30:44 Definition of Done & 6 Recall Questions 31:14 Day 10 Preview: Linux Storage, Disks & Filesystems (lsblk, fdisk, mount) Definition of Done: 1. Traced binaries to packages using rpm -qf and explained why /etc/passwd is unowned. 2. Verified package integrity with rpm -V and caught a modified system binary. 3. Inspected repo configurations in /etc/yum.repos.d/ and audited gpgcheck status. 4. Inspected transactions with dnf history info and rolled back cleanly using dnf history undo. 5. Restored corrupted files using dnf reinstall. 📚 FREE COURSE MATERIAL — every lesson, lab and answer key: https://github.com/mahadikabhijeet/ze... All 185 written lessons, labs, and study guides are on GitHub, free and open. ◀ Previous — Day 8: Linux Processes & Signals (ps, top, kill, SIGTERM vs SIGKILL, /proc) ▶ Next — Day 10: Linux Storage & Filesystems (lsblk, fdisk, parted, xfs vs ext4, mount, fstab) 🔔 Subscribe for the full path from zero to LLMOps. #DevOps #Linux #LinuxTutorial #ZeroToLLMOps #LearnLinux #BashScripting #SystemAdmin #DevOpsCourse