First Boot

Debian Development Machine Setup

Chapter 2 ยท First Boot: Updates, sudo & the Essentials

devserver has just booted into Debian 13 for the first time. Before you install any development tools, there is a short list of jobs worth doing once, in order: understand where your packages come from, bring the system up to date, check that sudo works, install a small set of tools every development machine needs, make the shell prompt tell you which machine you are on, and confirm you can log in remotely. None of it is glamorous, but everything in the rest of the course sits on top of it.

Where Your Packages Come From

On Debian 13, apt reads its package sources from the newer deb822 format: files ending in .sources in /etc/apt/sources.list.d/, where each source is a stanza of Key: value lines. The old one-line-per-repository /etc/apt/sources.list format still works, but it is no longer what a fresh Trixie install uses. Have a look at yours:

ls /etc/apt/sources.list.d/ cat /etc/apt/sources.list.d/debian.sources

You should see something like this (yours will show the mirror you chose in the installer, and the exact lines can differ slightly):

Types: deb URIs: https://deb.debian.org/debian Suites: trixie trixie-updates Components: main non-free-firmware Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg Types: deb URIs: https://security.debian.org/debian-security Suites: trixie-security Components: main non-free-firmware Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
FieldWhat it means
Typesdeb is binary packages. deb-src would add source packages, which you only need if you plan to build Debian packages from source.
URIsThe mirror to download from. The second stanza is Debian's separate security archive.
Suitestrixie is the release itself. trixie-updates carries fixes that are not security-related but should not wait for the next point release. trixie-security carries security fixes.
Componentsmain is Debian's free software. non-free-firmware holds firmware for hardware such as network cards. contrib and non-free exist too but are not enabled here.
Signed-ByThe keyring apt uses to check the packages really came from Debian.
Old-format files
If you ever meet an old .list file, from a tutorial or a third-party installer, apt can convert it: sudo apt modernize-sources rewrites .list files to the .sources format and asks before it changes anything. Linux Package Managers 3 (Managing Repositories on Debian-Based Systems) covers repositories in more depth, though it predates the move to the newer format.
Don't enable non-free yet
Chapter 4 needs the non-free component for the NVIDIA driver. Leave it off for now, and add it at that point, when there is a reason to.

Updating the System

Two apt commands do the work, and they do different jobs. apt update downloads the current list of available packages, and installs nothing. apt full-upgrade then actually installs newer versions. Always run them in that order.

sudo apt update sudo apt full-upgrade

Why full-upgrade and not upgrade? upgrade only installs upgrades that do not need any existing package removed. full-upgrade does the same, and will also remove installed packages if that is needed to upgrade the system as a whole. On a stable release those removals are rare and apt shows you exactly what it will do before asking you to confirm, so full-upgrade is the safer habit: it never leaves you half-updated. Read the summary before you type y.

If a new kernel was installed, restart the machine so it is the one running. You can compare what is running with what is installed:

# The kernel you are running now uname -r # The kernel packages that are installed dpkg -l 'linux-image*' | grep ^ii

sudo: Your Administrator Account

In Chapter 1 you left the root password empty in the installer. Debian responded by disabling the root account and adding your first user to the sudo group. Check that this happened:

groups sudo whoami

groups should list sudo, and sudo whoami (after your password) should print root. That single line is the whole idea: you are an ordinary user who borrows administrator rights for one command at a time, instead of staying logged in as an all-powerful account.

Edit sudo rules only with visudo
If you ever need to change who can use sudo, use sudo visudo (or a file under /etc/sudoers.d/ edited with sudo visudo -f). It checks the syntax before saving. A typo in a plain-text edit of the sudoers file can lock you out of administrator access completely. Do not add NOPASSWD rules to save typing; a password prompt is a very cheap safety net.

A Starter Set of Tools

A fresh desktop install is deliberately small. These tools are worth installing right away because you will reach for them constantly, and later chapters assume they are present:

sudo apt install build-essential curl wget git vim htop tree unzip zip jq ripgrep \ ca-certificates gnupg pciutils
PackageWhy you want it
build-essentialA C/C++ compiler and make. Many language packages compile small pieces of C when they install.
curl, wgetDownload files and talk to web services from the command line.
gitVersion control. Chapter 9 builds a Git server; you need the client before then.
vimA proper editor for the terminal. The default vi is a cut-down cousin.
htopA readable view of what the machine is doing.
tree, unzip, zipShow directory structure; open and create archives.
jq, ripgrepjq reads and filters JSON. rg is a very fast search through files.
ca-certificates, gnupgTrusted certificates for HTTPS, and GPG for verifying keys. Later chapters add third-party repositories, which need both.
pciutilsProvides lspci, which Chapter 1 used to find the graphics card.

Some of these may already be installed. If so, apt tells you so and installs nothing extra. Chapter 3 shows how to check what is already on the system before you install, so you are not guessing.

A Prompt That Names the Machine

Debian's default bash prompt already shows user@hostname, but on two machines that look alike a plain prompt is easy to skim past. The fix is to give each machine its own colour, so a glance at the terminal tells you where you are. Confirm the hostname first:

hostnamectl

If it does not say devserver, set it with sudo hostnamectl set-hostname devserver and log out and in again. Then add this to the end of ~/.bashrc on devserver:

# Prompt: user@host in bold cyan on devserver, working directory in blue PS1='\[\e[1;36m\]\u@\h\[\e[0m\]:\[\e[1;34m\]\w\[\e[0m\]\$ '

On the web server, use a colour that means be careful. Red (1;31) does the job:

# On debserver: user@host in bold red PS1='\[\e[1;31m\]\u@\h\[\e[0m\]:\[\e[1;34m\]\w\[\e[0m\]\$ '

Open a new terminal (or run source ~/.bashrc) to see the change. The \[ ... \] pairs tell bash the colour codes take no screen space, which stops long commands from wrapping strangely.

Logging In Remotely with SSH

You ticked “SSH server” in the installer, so devserver is already running the OpenSSH server. Trixie ships OpenSSH 10.0. On Debian the service is called ssh:

systemctl status ssh # The machine's addresses; use one of these from another computer ip -br address

From another computer on your network, connect with ssh yourname@THE-ADDRESS. Typing an address each time gets old fast, but the address is a reliable thing to fall back on, because a machine name only works if your network can resolve it.

Log in with a key, not a password

A password can be guessed. A key pair cannot in any practical sense. Generate one on the computer you will connect from, and copy the public half to devserver:

# On the computer you connect FROM ssh-keygen -t ed25519 ssh-copy-id yourname@devserver-address # Check that the key login works before changing anything else ssh yourname@devserver-address

Once key login works, you can switch password logins off on devserver. Debian's SSH server reads extra settings from files in /etc/ssh/sshd_config.d/, so you do not need to edit the main file. Create /etc/ssh/sshd_config.d/10-no-passwords.conf containing:

PasswordAuthentication no
# Test the configuration for mistakes BEFORE applying it sudo sshd -t # Apply it without dropping existing connections sudo systemctl reload ssh
Keep a second door open
Never switch off password logins until you have proved key login works from a second terminal, and keep the first session logged in while you test. If the change goes wrong you can still fix it from the open session. If you close everything and are locked out, you need physical access to the machine, which is manageable on your desk but not on a remote server. This course only covers the basics; the Remote Access With SSH course goes much further.

Hands-On Exercises

Exercise 1

Read your own /etc/apt/sources.list.d/debian.sources. For each stanza, explain what every field does. Then run apt policy and identify which of the archive lines correspond to the release, the updates suite and the security suite.

๐Ÿ“„ View solution
Exercise 2

Before installing the starter tools, record which of them are already installed. Install the full list, then report which ones apt actually had to install and how you can tell. Finish by printing the version of each command-line tool.

๐Ÿ“„ View solution
Exercise 3

Set up the coloured prompt on devserver, generate an ed25519 key on another computer, install it, and log in with it. Then write out the exact order of steps you would follow to disable password logins safely, including how you would undo the change if it went wrong.

๐Ÿ“„ View solution

Chapter 2 Quick Reference

  • Debian 13 keeps apt sources in /etc/apt/sources.list.d/*.sources (deb822 format); apt modernize-sources converts old .list files
  • Stanza fields: Types, URIs, Suites (trixie, trixie-updates, trixie-security), Components (main, non-free-firmware), Signed-By
  • sudo apt update refreshes the package list; sudo apt full-upgrade installs upgrades and may remove packages if needed
  • Check groups for sudo; edit sudo rules only with visudo; avoid NOPASSWD
  • Starter tools: build-essential curl wget git vim htop tree unzip zip jq ripgrep ca-certificates gnupg pciutils
  • hostnamectl shows the hostname; a different PS1 colour per machine prevents running commands on the wrong one
  • The SSH service is ssh on Debian: systemctl status ssh
  • Use ssh-keygen -t ed25519 and ssh-copy-id; put server settings in /etc/ssh/sshd_config.d/
  • Always sudo sshd -t before reloading, and keep a second session open while changing SSH settings