Install · pre-alpha

Install the preview on a host you can afford to break.

The latest immutable release is v0.17.2. It installs through a signed bootstrap script on Fedora 44, Ubuntu 26.04 LTS, and Arch Linux, x86_64 only. No release is assigned as external tester authority yet: you may inspect it on a disposable host, and the tester loop itself stays inactive until one is.

Where things stand

Released, not yet open for external testing.

v0.17.2 is a real, immutable, signed release whose packages installed through the signed bootstrap protocol on all three hosts, as recorded in the release matrix. No release is assigned as tester authority while the remaining launch gates are open. Inspecting it on a disposable host is fine; it is not a tester run and does not count toward the milestone.

Confirmation rule

When --yes is required, and when it is not.

--yes is required only for commands the risk policy classes as active-host, selected-root, destructive-database, or always-live mutations, and only outside --dry-run. Everything else runs without confirmation even when it changes state. The --yes-gated classes below are transcribed from apps/conary/src/command_risk.rs, the policy that enforces them, and are complete by construction. The two side-effect groups are known misclassifications, commands the policy calls read-only whose implementations write; they are examples found by audit, not a complete list, and are tracked in #918 until the classifier is fixed and this list is generated from it. The absence of a --yes flag never means a command is read-only.

Policy classes, plus known misclassifications
Require --yes outside --dry-run
  • conary install
  • conary install @collection
  • conary update
  • conary update @collection
  • conary remove
  • conary autoremove
  • conary ccs install
  • conary model apply
  • conary automation apply
  • conary system unadopt
  • conary system restore
  • conary system native-handoff
  • conary system takeover
  • conary system repository-takeover
  • conary system rebuild-db
  • conary system db-backup recover
  • conary system state revert
  • conary system state rollback
  • conary system generation build
  • conary system generation publish
  • conary system generation switch
  • conary system generation rollback
  • conary system generation gc
  • conary system generation recover
  • conary system generation recover-db
Active-host mutations with the apply intent built in (no flag exists)
  • conary self-update
  • conary try keep
  • conary try rollback
  • conary try --activate
Change Conary's database without confirmation
  • conary system adopt --system
  • conary system adopt --refresh
  • conary system adopt <pkg>
Change local state without confirmation
  • conary pin
  • conary unpin
  • conary new
  • conary cook
  • conary try
  • conary try --watch
  • conary publish
  • conary system init
  • conary system state prune
  • conary system state create
  • conary system trigger enable / disable / add / remove / run
  • conary system redirect add / remove
  • conary system update-channel set / reset
  • conary repo add / remove / reset-trust / enable / disable / sync
  • conary config backup / restore
  • conary registry update
  • conary query label add / remove / path / set / link / delegate
  • conary ccs enhance / init / build / test
  • conary derive create / patch / override / delete
  • conary model snapshot / update / publish
  • conary collection create / add / remove / delete
  • conary automation configure
  • conary bootstrap seed --from-adopted
  • conary provenance register
  • conary trust init / enable
  • conary federation add-peer / remove-peer / enable-peer / disable-peer / scan --add
Known misclassifications, examples only: classed read-only or non-host, but write artifacts
  • conary system generation export
  • conary model lock
  • conary sbom
  • conary system sbom
  • conary ccs sign
  • conary ccs keygen
  • conary ccs export
  • conary provenance export
  • conary trust keygen
  • conary profile generate
  • conary profile publish
  • conary derive build
  • conary derivation build
  • conary automation daemon
  • conary cache populate
  • conary bootstrap init
  • conary bootstrap dry-run (creates the work directory, validates only)
  • conary bootstrap cross-tools
  • conary bootstrap temp-tools
  • conary bootstrap system
  • conary bootstrap config
  • conary bootstrap tier2
  • conary bootstrap guest-profile
  • conary bootstrap image
  • conary bootstrap run
  • conary bootstrap resume
  • conary bootstrap seed
  • conary bootstrap clean (removes stage trees)
  • conary export
Known misclassifications, examples only: classed read-only, but write the database
  • conary automation check
  • conary automation daemon
  • conary federation test
Boot continuation authorized by the generation artifact, not a flag
  • conary system generation activate
01

Download, read, and preview the bootstrap script

The script downloads the release manifest and its detached signature, verifies the Ed25519 signature against the embedded release key before it reads any selection field, picks the one package for this host, downloads it, and checks its size and SHA-256 against the signed manifest. Without --apply it only prints the plan. --manifest-url binds the run to v0.17.2, the release this page authorizes; without it the script follows releases/latest, which can be a newer release than the one the release matrix and launch-status name.

$curl --proto '=https' --tlsv1.2 -fLO https://conary.io/install-conary-preview.sh $less install-conary-preview.sh manifest="https://github.com/FieldmouseWorks/Conary/releases/download/v0.17.2/conary-bootstrap-v1.manifest" $bash ./install-conary-preview.sh --manifest-url "$manifest"
Do not pipe the URL into a shell. Read the script. It is short, fails closed on anything it does not recognise, and refuses to run on a host or architecture outside the supported set. It is the only supported install path: a plain SHA256SUMS check against the same origin as the packages is not a substitute for the signed manifest. The release matrix records every asset digest if you want to cross-check by hand.
02

Apply

Installation needs both flags. The script hands the verified package to the host's own package manager (dnf, apt-get, or pacman) to install Conary itself; the package's post-install hook initialises the system database and the built-in Fedora, Ubuntu, and Arch source feeds. That is the only job the host package manager gets: Conary never delegates its own package transactions to it afterwards.

manifest="https://github.com/FieldmouseWorks/Conary/releases/download/v0.17.2/conary-bootstrap-v1.manifest" $bash ./install-conary-preview.sh --manifest-url "$manifest" --apply --yes $conary --version $sudo conary repo list
03

The bounded cross-distro loop

This is the loop the external tester milestone measures. The tester guide that owns it is paused and says not to run it until launch-status.json assigns an exact tester release. The commands are kept here so the shape is visible, folded away so the site does not become a second execution authority.

Retained tester loop — inactive until the tester guide is active; do not run as a tester run
inspect first live mutation read-only check
live$sudo conary repo sync remi choosesource=ubuntu-26.04  # on Fedora or Arch; use fedora-44 on Ubuntu inspect$sudo conary install htop --from "$source" --dry-run live$sudo conary install htop --from "$source" --yes read$sudo conary list htop --info read$sudo conary query depends htop inspect$sudo conary update htop --dry-run live$sudo conary remove htop --yes
Capability preflight is automatic and has no bypass. Conary validates a package's exact declared requirements against the host before mutation and rejects anything the host cannot satisfy. A local .rpm, .deb, or .pkg.tar.zst file can be inspected the same way on an installed host: sudo conary install ./package.deb --dry-run.
04

Optionally, let Conary see what the host already has

Adoption records packages that stay owned by dnf, apt, or pacman. It transfers nothing, and the risk policy lets it change Conary's database without a --yes, so run the dry-run first. Unadoption removes the tracking and deletes no files.

inspect$sudo conary system adopt --system --dry-run live$sudo conary system adopt --system read$sudo conary system adopt --status inspect$sudo conary system unadopt --all --dry-run live$sudo conary system unadopt --all --yes
05

Report what happened, including the boring parts

An exact capability error, a lifecycle defect, or a slow first conversion is useful evidence. An install that simply worked is evidence too. Keep the public report concise.

Record

  • Exact commands and exit statuses.
  • Distribution, kernel, architecture, and Conary version.
  • Source package format and the host's native package format.
  • Release tag, exact package filename, and checksum result.
  • Where a partial run stopped.
  • Anything confusing, slow, scary, or unexpectedly good.

Keep private

  • Complete transcripts and full package inventories.
  • Broad environment dumps, raw logs, and live databases.
  • Credentials, private keys, SSH keys, and shell history.
  • /etc/conary/trust and unreviewed support bundles.

Contributor path

Build from source

For development, not as a substitute for the packaged path. Requires Rust 1.98.0 or newer, Git, and Linux; Conary does not build on macOS or Windows.

$git clone https://github.com/FieldmouseWorks/Conary.git $cd Conary $cargo build -p conary $sudo ./target/debug/conary system init

For an isolated, non-root development database, pass a writable --db-path and keep using the same path for every later command.