I need to provide Debian packages across a work network containing roughly 2,500 identical servers. Each machine runs a containerized advertising player, with Incus containers using Debian as their base image. I have never maintained a package mirror before and want to avoid synchronizing the entire Debian archive if possible. I'm considering aptly or another modern tool for mirroring only the packages and repositories these systems actually require. apt-mirror seems less appealing because it has not been updated in several years. What approach would you recommend?
2 Answers
You could also run a repository manager such as Nexus. It can act as a proxy and cache, so packages are downloaded from the upstream Debian repositories only when requested and then served locally. That avoids mirroring the whole archive, although you should still plan how to retain packages and promote a tested version set if reproducible deployments matter.
aptly is a strong fit for this. You can mirror only the Debian distributions, components, and architectures you need, then publish a controlled repository for the containers to use. Its snapshots are also useful because you can pin a known package set and promote updates deliberately instead of having 2,500 machines change underneath you at once.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures