Home / Alt manpages / apt-config(8)

  • apt-config(8)
  • Admin command
  • linux

Query APT Configuration Safely with apt-config

You will finish with a repeatable way to read APT settings, pass a temporary value to an APT command, and expose selected configuration values to a shell script. The examples use apt-config from APT 2.8.3, installed here as package version 2.8.3 for amd64.

Allow about fifteen minutes. You need a shell and the apt package. The normal examples are read-only and do not need elevated privileges. This guide does not edit /etc/apt, install packages or change repository settings.

1. Check the installed command

Start by checking the version and the available command shape. These are ordinary, read-only commands:

$ apt-config --version
apt 2.8.3 (amd64)
$ apt-config --help
apt-config [options] command

The installed manual describes two useful commands: shell emits shell assignments for selected values, while dump prints the configuration space. It also accepts global options such as --config-file, --option, --format and --empty.

Checkpoint: confirm which binary your script will run:

$ command -v apt-config
/usr/bin/apt-config

2. Query one value with shell

Give shell pairs of a shell variable name and an APT configuration key. A simple architecture query looks like this:

$ apt-config shell APT_ARCH APT::Architecture
APT_ARCH='amd64'

The output is an assignment, not just the bare value. The quoting is intended to make the result usable by a shell. The key is hierarchical, so use the exact spelling and punctuation used by APT.

To use the assignment in a script, keep the variable name under your control and evaluate only output produced by the trusted local command:

result=$(apt-config shell APT_ARCH APT::Architecture) || exit $?
eval "$result"
printf 'APT architecture: %s\n' "$APT_ARCH"

Do not feed arbitrary user input into either the variable-name position or the configuration-key position before using eval. Configuration can contain shell-sensitive characters, and the whole point of this interface is that it returns shell syntax. If you only need to display a value, inspect the assignment instead of evaluating it.

3. Ask for a normalised type

Append a suffix to the configuration key when the script needs a particular type. The manual documents /f for file names, /d for directories, /b for booleans and /i for integers. A temporary configuration file gives us safe, reproducible values to query:

$ cfg=$(mktemp /tmp/apt-config-guide.XXXXXX)
$ chmod 600 "$cfg"
$ printf '%s\n' 'Guide::Path "/var/tmp/example";' 'Guide::Enabled "true";' 'Guide::Retries "3";' > "$cfg"
$ apt-config --config-file "$cfg" shell PATH_VALUE Guide::Path/f ENABLED Guide::Enabled/b RETRIES Guide::Retries/i
PATH_VALUE='/var/tmp/example'
ENABLED='true'
RETRIES='3'

The file is an example of APT configuration syntax, not a replacement for the system configuration. Keep it private if it contains credentials or repository details. The --config-file option reads the default configuration first and then the specified file, so a key in the later file can override an earlier value.

Checkpoint: confirm that your script received the values it expects:

case "$ENABLED" in
    true|false) ;;
    *) printf 'unexpected boolean: %s\n' "$ENABLED" >&2; exit 1 ;;
esac
case "$RETRIES" in
    ''|*[!0-9]*) printf 'unexpected integer: %s\n' "$RETRIES" >&2; exit 1 ;;
esac

4. Inspect configuration with dump

Use dump when you need a wider view, such as checking which setting is winning after several configuration files have been read:

$ apt-config --no-empty --format '%f=%v%n' --config-file "$cfg" dump
Guide::Path=/var/tmp/example
Guide::Enabled=true
Guide::Retries=3

The format string uses %f for the full hierarchical name, %v for the value and %n for a newline. The manual also defines %t for an individual name, %N for a tab and %% for a literal percent sign. Values are encoded when the format requires a quoted-string representation.

--empty includes options with empty values and is the default. Add --no-empty when empty entries would obscure the setting you are looking for. Avoid dumping configuration into a public log: APT settings may reveal proxy names, credentials, local paths or repository choices. Filter the output at the point of use.

5. Override one option for a single command

Use --option, or its short form -o, to set an arbitrary option for this invocation. It can be repeated. This example supplies a value for the query without editing any file:

$ apt-config -o MyApp::options='-f' shell OPTS MyApp::options
OPTS='-f'

The syntax is -o Foo::Bar=bar. This changes the configuration seen by apt-config for that process only. It does not write the option to /etc/apt/apt.conf and it does not persist after the command exits.

When passing an option to another APT command, put it before that command's operation and quote the complete assignment when values contain spaces or shell metacharacters. Read that command's own manual before changing settings that can alter downloads, authentication, package selection or removal.

6. Separate ordering from persistence

--config-file adds a file after the default configuration has been read. The APT_CONFIG environment variable is different: the manual says it selects a file to read before the default configuration files. That ordering matters when an early value affects how later files are interpreted.

$ APT_CONFIG="$cfg" apt-config shell PATH_VALUE Guide::Path/f
PATH_VALUE='/var/tmp/example'

Use an explicit environment assignment for one command when testing. Do not export it from a login profile just to make a temporary experiment work. If a real deployment needs it, document the owning service or wrapper and keep a copy of the previous environment so you can undo the change.

7. Diagnose failures without guessing

APT uses exit status 0 for normal operation and decimal 100 for an error. Capture the status when a script must distinguish a missing value from a command failure:

$ apt-config nonsense
E: Invalid operation nonsense
$ printf 'exit status: %s\n' "$?"
exit status: 100

A blank shell assignment does not automatically mean that the setting is false, absent or safe to ignore. Check the key spelling, the files being read and the type suffix. Run apt-config dump with a narrow format and filter only after considering whether the output may contain sensitive data.

There is no undo command for the read-only examples. A -o override, --config-file selection or APT_CONFIG assignment disappears when that process ends. If you create a temporary file, remove that specific file when you have finished testing, or retain it only if its contents are harmless and its permissions are appropriate.

Done means

  • You confirmed the installed APT version and binary path.
  • You can query one setting with shell and understand that its output is shell syntax.
  • You used /f, /d, /b or /i only when the value's type matters.
  • You can inspect effective configuration with a controlled dump format.
  • You know that -o is temporary and that configuration-file ordering changes what wins.
  • Your scripts check exit status, avoid unsafe evaluation of untrusted output and keep sensitive dumps out of logs.