I need to provide Debian packages across a work network containing roughly 2,500 servers. Every server runs the same software: an Incus container hosting Debian as the base system, with a player used for digital signage. I have never set up a package mirror before and would prefer to mirror only the packages and versions these machines actually use rather than cloning the entire Debian repository. Should I use aptly, debmirror, reprepro, or another tool?
2 Answers
For a curated internal repository, aptly or reprepro would be a better fit than apt-mirror. You can download only the required packages, publish a signed repository, and then point the containers at that internal endpoint. Keep the repository configuration and package list under version control so it can be rebuilt or updated consistently.
A standard mirror tool is mainly useful when you want a broad copy of an upstream archive. Since all 2,500 systems are identical, first create a list of the packages and versions installed in the base image, then use that list to populate a small internal repository. You can also cache packages on demand, but make sure the cache is backed up and that clients receive packages through a properly signed repository.

That sounds closer to what I need. I definitely want to avoid mirroring the entire Debian archive when all the machines use the same limited set of packages.