Digi Control documentation
Sources, signatures and package safety
Repository/local RPM trust, impact preview, locks and journal recovery.
What it covers
- Repository packages use configured metadata/keys and native backend policy.
- A local RPM/bundle is checked for source kind, RPM list, signature and trust: verified, unknown, unsigned, untrusted or blocked.
- Unknown/unsigned requires explicit extra confirmation only when policy permits.
- Impact preview reports install/upgrade/reinstall/remove/downgrade counts, core packages and reboot likelihood.
How to use it
- Check source-policy.
- Check lock-status/journal.
- For a stale journal use recover-journal reason::TOKEN.
- Then registry-status.
Important rules
- Do not manually delete lock/state.
- High risk belongs in a maintenance window.
- Copy the exact displayed token.
dctl source-policy
dctl lock-status
dctl journal
dctl recover-journal reason::DISPLAYED_TOKEN
dctl registry-status