Preconfigure Debian packages with dpkg-preconfigure
You will run a Debian package's debconf configuration before installation, so answers are ready when the package is installed. The examples use dpkg-preconfigure from debconf 1.5.86ubuntu1, installed as /usr/sbin/dpkg-preconfigure on this machine. Allow about fifteen minutes, plus the time needed to obtain the package you actually intend to install.
The route
Jump straight to the step you need, or tick off Done means at the end.
You need a readable local .deb file for the direct workflow. Preconfiguration can ask questions or write debconf answers, but it does not install the package. Use an ordinary user for inspection and preparation. Use elevated privileges only when your system's debconf database or package workflow requires them.
1. Check the installed command
Start with the command path, package version and built-in help. These are read-only checks:
$ command -v dpkg-preconfigure
/usr/sbin/dpkg-preconfigure
$ dpkg-query -W -f='${Package} ${Version}\n' debconf
debconf 1.5.86ubuntu1
$ dpkg-preconfigure --help
Usage: dpkg-preconfigure [options] [debs]
--apt Apt mode.
-f, --frontend Specify debconf frontend to use.
-p, --priority Specify minimum priority question to show.
--terse Enable terse mode.
The help command also exits non-zero on this installed release, so treat its printed usage as information rather than using its exit status as a health check. The available switches are --apt, --frontend, --priority and --terse, alongside --help.
Checkpoint
Confirm that the package version and command path are the ones you mean to use before putting the command into an installation script.
2. Preconfigure one local package
Give the command one or more package filenames. Replace the placeholder with a file you have deliberately downloaded or built:
$ PACKAGE='/path/to/package.deb'
$ test -r "$PACKAGE" && echo 'package is readable'
package is readable
$ dpkg-preconfigure "$PACKAGE"
For each package that uses debconf, its configuration script gets a chance to inspect the system and ask questions. The command may open the selected debconf frontend, or it may use defaults when the question priority is below your threshold. A successful return to the shell means the preconfiguration command completed; it does not mean the package has been installed.
Do not use a package from an untrusted source. Its configuration script runs as part of this operation and can inspect the system within the permissions of the process. Check the file's origin and package metadata using your normal repository and signature controls before answering questions.
3. Choose which questions to show
The priority setting is a minimum priority. Questions below the selected priority are skipped and their default answers are used. For a deliberate interactive run, set the value explicitly:
$ dpkg-preconfigure --priority=low "$PACKAGE"
The exact questions depend on the package and the debconf database. A low threshold can expose more questions, while a higher threshold can leave more answers at their defaults. Do not assume that selecting a priority means every possible question will appear.
If you need a different interface, pass its debconf frontend name:
$ dpkg-preconfigure --frontend=readline --priority=low "$PACKAGE"
Only choose a frontend that suits the environment. A graphical frontend is a poor fit for an SSH session, while a terminal frontend can block an unattended job waiting for input. In automation, make the frontend and priority part of the reviewed job configuration rather than relying on whatever the session happens to provide.
4. Verify the operation without installing anything
Keep preconfiguration separate from installation while testing. The command below feeds apt mode an empty package list, which is a safe way to check that the input channel is accepted:
$ printf '' | dpkg-preconfigure --apt --priority=low
$ printf 'exit status: %s\n' "$?"
exit status: 0
On this host the command also prints a debconf warning about an inaccessible passwords database when run without the permissions needed to read it. The warning is not a package installation result. Investigate the database permissions and the account used by your real workflow; do not silence warnings blindly.
For a real package, verify the preconfiguration step immediately after it finishes:
$ dpkg-preconfigure --priority=low "$PACKAGE"
$ status=$?
$ printf 'dpkg-preconfigure status: %s\n' "$status"
dpkg-preconfigure status: 0
The status records whether the command completed. It does not prove that every answer is suitable for the later installation. Review the questions and package documentation before proceeding, especially for packages that alter networking, authentication, storage or services.
5. Connect it to apt only after the manual run works
In apt mode, dpkg-preconfigure reads package filenames from standard input rather than from command-line arguments. The manpage documents an apt hook in /etc/apt/apt.conf:
// Pre-configure all packages before
// they are installed.
DPkg::Pre-Install-Pkgs {
"dpkg-preconfigure --apt --priority=low";
};
This is a system-wide apt configuration change. Before editing it, save the existing file and arrange a rollback. The change normally requires elevated privileges because it writes under /etc/apt:
$ sudo cp --preserve=all /etc/apt/apt.conf /etc/apt/apt.conf.before-dpkg-preconfigure
$ sudoedit /etc/apt/apt.conf
If /etc/apt/apt.conf does not exist, do not create a new global hook just to follow this example. First check how your host organises apt configuration, then place the setting in the configuration location used by that deployment. Keep the hook's command short and review its quoting before saving.
To undo the example, restore the backup after confirming that no other administrator has changed the file:
$ sudo cp --preserve=all /etc/apt/apt.conf.before-dpkg-preconfigure /etc/apt/apt.conf
Run an apt operation only in a maintenance window if the selected frontend can ask questions. A hook that waits for input can make an unattended upgrade appear stuck.
6. Diagnose the common traps
- No questions appear: the package may not use debconf, answers may already exist, or the priority threshold may be too high. Lower the threshold deliberately and check the package's documentation.
- The command cannot open the package: check the exact path and read permission with
ls -landtest -r. Do not addsudountil you know the file access is the actual problem. - An unattended job waits: check the frontend. A prompt is expected behaviour for an interactive frontend, not proof that apt is broken.
- A warning mentions the debconf database: identify which account is running the command and whether it can read or write the database used by that installation context. Avoid changing database permissions broadly.
- You expected installation: this command only runs package configuration scripts before installation. A separate package installation command is still required.
Done means
- The installed debconf version and
dpkg-preconfigurepath are confirmed. - The intended
.debfile is readable and came from a trusted source. - The frontend and minimum question priority match the session or automation environment.
- A real preconfiguration run returned status 0, and its questions or warnings were reviewed.
- Any apt hook was treated as a privileged, system-wide change with a tested rollback.
- You understand that preconfiguration prepares answers; it does not install the package.