First Boot
Debian Development Machine Setup
Chapter 2 ยท First Boot: Updates, sudo & the Essentials
devserver has just booted into Debian 13 for the first time. Before you install any
development tools, there is a short list of jobs worth doing once, in order: understand where your packages
come from, bring the system up to date, check that sudo works, install a small set of tools
every development machine needs, make the shell prompt tell you which machine you are on, and confirm you
can log in remotely. None of it is glamorous, but everything in the rest of the course sits on top of it.
Where Your Packages Come From
On Debian 13, apt reads its package sources from the newer deb822 format: files ending in
.sources in /etc/apt/sources.list.d/, where each source is a stanza of
Key: value lines. The old one-line-per-repository /etc/apt/sources.list format still
works, but it is no longer what a fresh Trixie install uses. Have a look at yours:
You should see something like this (yours will show the mirror you chose in the installer, and the exact lines can differ slightly):
| Field | What it means |
|---|---|
| Types | deb is binary packages. deb-src would add source packages, which you only need if you plan to build Debian packages from source. |
| URIs | The mirror to download from. The second stanza is Debian's separate security archive. |
| Suites | trixie is the release itself. trixie-updates carries fixes that are not security-related but should not wait for the next point release. trixie-security carries security fixes. |
| Components | main is Debian's free software. non-free-firmware holds firmware for hardware such as network cards. contrib and non-free exist too but are not enabled here. |
| Signed-By | The keyring apt uses to check the packages really came from Debian. |
.list file, from a tutorial or a third-party installer, apt can convert
it: sudo apt modernize-sources rewrites .list files to the .sources
format and asks before it changes anything. Linux Package Managers 3 (Managing Repositories on Debian-Based
Systems) covers repositories in more depth, though it predates the move to the newer format.
non-free component for the NVIDIA driver. Leave it off for now, and add it
at that point, when there is a reason to.
Updating the System
Two apt commands do the work, and they do different jobs. apt update downloads the current list
of available packages, and installs nothing. apt full-upgrade then actually installs newer
versions. Always run them in that order.
Why full-upgrade and not upgrade? upgrade only installs upgrades that
do not need any existing package removed. full-upgrade does the same, and will also remove
installed packages if that is needed to upgrade the system as a whole. On a stable release those removals
are rare and apt shows you exactly what it will do before asking you to confirm, so full-upgrade
is the safer habit: it never leaves you half-updated. Read the summary before you type y.
If a new kernel was installed, restart the machine so it is the one running. You can compare what is running with what is installed:
sudo: Your Administrator Account
In Chapter 1 you left the root password empty in the installer. Debian responded by disabling the root
account and adding your first user to the sudo group. Check that this happened:
groups should list sudo, and sudo whoami (after your password) should
print root. That single line is the whole idea: you are an ordinary user who borrows
administrator rights for one command at a time, instead of staying logged in as an all-powerful account.
sudo visudo (or a file under
/etc/sudoers.d/ edited with sudo visudo -f). It checks the syntax before saving. A
typo in a plain-text edit of the sudoers file can lock you out of administrator access completely. Do not
add NOPASSWD rules to save typing; a password prompt is a very cheap safety net.
A Starter Set of Tools
A fresh desktop install is deliberately small. These tools are worth installing right away because you will reach for them constantly, and later chapters assume they are present:
| Package | Why you want it |
|---|---|
| build-essential | A C/C++ compiler and make. Many language packages compile small pieces of C when they install. |
| curl, wget | Download files and talk to web services from the command line. |
| git | Version control. Chapter 9 builds a Git server; you need the client before then. |
| vim | A proper editor for the terminal. The default vi is a cut-down cousin. |
| htop | A readable view of what the machine is doing. |
| tree, unzip, zip | Show directory structure; open and create archives. |
| jq, ripgrep | jq reads and filters JSON. rg is a very fast search through files. |
| ca-certificates, gnupg | Trusted certificates for HTTPS, and GPG for verifying keys. Later chapters add third-party repositories, which need both. |
| pciutils | Provides lspci, which Chapter 1 used to find the graphics card. |
Some of these may already be installed. If so, apt tells you so and installs nothing extra. Chapter 3 shows how to check what is already on the system before you install, so you are not guessing.
A Prompt That Names the Machine
Debian's default bash prompt already shows user@hostname, but on two machines that look alike a
plain prompt is easy to skim past. The fix is to give each machine its own colour, so a glance at the
terminal tells you where you are. Confirm the hostname first:
If it does not say devserver, set it with
sudo hostnamectl set-hostname devserver and log out and in again. Then add this to the end of
~/.bashrc on devserver:
On the web server, use a colour that means be careful. Red (1;31) does the job:
Open a new terminal (or run source ~/.bashrc) to see the change. The \[ ... \]
pairs tell bash the colour codes take no screen space, which stops long commands from wrapping strangely.
Logging In Remotely with SSH
You ticked “SSH server” in the installer, so devserver is already running the
OpenSSH server. Trixie ships OpenSSH 10.0. On Debian the service is called ssh:
From another computer on your network, connect with ssh yourname@THE-ADDRESS. Typing an
address each time gets old fast, but the address is a reliable thing to fall back on, because a machine name
only works if your network can resolve it.
Log in with a key, not a password
A password can be guessed. A key pair cannot in any practical sense. Generate one on the computer you will
connect from, and copy the public half to devserver:
Once key login works, you can switch password logins off on devserver. Debian's SSH server
reads extra settings from files in /etc/ssh/sshd_config.d/, so you do not need to edit the main
file. Create /etc/ssh/sshd_config.d/10-no-passwords.conf containing:
Hands-On Exercises
Read your own /etc/apt/sources.list.d/debian.sources. For each stanza, explain what every field does. Then run apt policy and identify which of the archive lines correspond to the release, the updates suite and the security suite.
Before installing the starter tools, record which of them are already installed. Install the full list, then report which ones apt actually had to install and how you can tell. Finish by printing the version of each command-line tool.
๐ View solutionSet up the coloured prompt on devserver, generate an ed25519 key on another computer, install it, and log in with it. Then write out the exact order of steps you would follow to disable password logins safely, including how you would undo the change if it went wrong.
Chapter 2 Quick Reference
- Debian 13 keeps apt sources in
/etc/apt/sources.list.d/*.sources(deb822 format);apt modernize-sourcesconverts old.listfiles - Stanza fields: Types, URIs, Suites (trixie, trixie-updates, trixie-security), Components (main, non-free-firmware), Signed-By
sudo apt updaterefreshes the package list;sudo apt full-upgradeinstalls upgrades and may remove packages if needed- Check
groupsforsudo; edit sudo rules only withvisudo; avoidNOPASSWD - Starter tools:
build-essential curl wget git vim htop tree unzip zip jq ripgrep ca-certificates gnupg pciutils hostnamectlshows the hostname; a differentPS1colour per machine prevents running commands on the wrong one- The SSH service is
sshon Debian:systemctl status ssh - Use
ssh-keygen -t ed25519andssh-copy-id; put server settings in/etc/ssh/sshd_config.d/ - Always
sudo sshd -tbefore reloading, and keep a second session open while changing SSH settings