Install

A package for your distribution.

Every release is built on the openSUSE Build Service for five distributions, on x86_64 and — for most of them — ARM. Add the repository once, and new versions arrive with the rest of your system updates. No Rust toolchain and no Bun on the machine that runs it.

What is built

DistributionOBS repositoryArchitectures
TumbleweedopenSUSE_Tumbleweedx86_64
Tumbleweed on ARMopenSUSE_Factory_ARMaarch64
Leap 16.016.0x86_64, aarch64
Fedora 44Fedora_44x86_64, aarch64
Fedora 43Fedora_43x86_64, aarch64
RawhideFedora_Rawhidex86_64
Debian 13 “trixie”Debian_13amd64, arm64
Ubuntu 26.04xUbuntu_26.04amd64
ArchArchx86_64

The build log and the files for each one are on the OBS package page. openSUSE's download page writes the same commands for your distribution, if you would rather take them from there.

openSUSE

Tumbleweed · x86_64
$ sudo zypper addrepo https://download.opensuse.org/repositories/home:/abksh:/tapedeck/openSUSE_Tumbleweed/home:abksh:tapedeck.repo
$ sudo zypper refresh
$ sudo zypper install tapedeck

zypper asks whether to trust the repository key on the refresh. Check the fingerprint against the one at the foot of this page, then answer a to trust it always. openSUSE's rctapedeck shortcut is installed too.

Fedora

Fedora 44 · x86_64, aarch64
$ sudo dnf config-manager addrepo --from-repofile=https://download.opensuse.org/repositories/home:/abksh:/tapedeck/Fedora_44/home:abksh:tapedeck.repo
$ sudo dnf install tapedeck

This is the dnf5 syntax Fedora has shipped since 41. dnf asks to import the repository key on the first install; the fingerprint is at the foot of this page.

Debian

Debian 13 “trixie” · amd64, arm64
$ sudo curl -fsSL https://download.opensuse.org/repositories/home:/abksh:/tapedeck/Debian_13/Release.key -o /etc/apt/keyrings/tapedeck.asc
$ echo "deb [signed-by=/etc/apt/keyrings/tapedeck.asc] https://download.opensuse.org/repositories/home:/abksh:/tapedeck/Debian_13/ /" | sudo tee /etc/apt/sources.list.d/tapedeck.list
$ sudo apt update
$ sudo apt install tapedeck

Raspberry Pi OS on trixie is Debian 13, so a Pi running the 64-bit image takes the arm64 package as it is — nothing to compile on the Pi. The key is trusted for this one repository only, rather than dropped into trusted.gpg.d where apt would accept it for all of them. Debian 12 is not built: its Rust is older than the 1.88 Tapedeck needs.

Ubuntu

Ubuntu 26.04 · amd64
$ sudo curl -fsSL https://download.opensuse.org/repositories/home:/abksh:/tapedeck/xUbuntu_26.04/Release.key -o /etc/apt/keyrings/tapedeck.asc
$ echo "deb [signed-by=/etc/apt/keyrings/tapedeck.asc] https://download.opensuse.org/repositories/home:/abksh:/tapedeck/xUbuntu_26.04/ /" | sudo tee /etc/apt/sources.list.d/tapedeck.list
$ sudo apt update
$ sudo apt install tapedeck

22.04 and 24.04 are not built — their Rust is older than the 1.88 Tapedeck needs. On those, build from source.

Arch Linux

Arch · x86_64
$ curl -fsSL https://download.opensuse.org/repositories/home:/abksh:/tapedeck/Arch/x86_64/home_abksh_tapedeck_Arch.key | sudo pacman-key --add -
$ sudo pacman-key --lsign-key A61C52E4D6143F8B39BFC36A3DDBB9C7336FE66A
$ printf '\n[home_abksh_tapedeck_Arch]\nServer = https://download.opensuse.org/repositories/home:/abksh:/tapedeck/Arch/$arch\n' | sudo tee -a /etc/pacman.conf
$ sudo pacman -Syu tapedeck

The section name has to be home_abksh_tapedeck_Arch exactly — pacman looks for a database file of that name. The fingerprint in the second line is the key OBS signs with; the first line only fetches it, and nothing trusts it until the second.

After installing

The service is installed but not started, on every distribution. Until someone creates the first admin account, the setup page answers anyone who can reach port 8080. So it starts when you start it, not as a side effect of a package install.

$ sudoedit /etc/tapedeck/tapedeck.env
# set MUSICBRAINZ_CONTACT to an email address or URL, at least
$ sudo systemctl enable --now tapedeck
📋 Visit the web UI to complete setup.
→ http://your-server:8080

MUSICBRAINZ_CONTACT is the one setting to fill in. MusicBrainz blocks clients that don't identify themselves. Leave it empty and the MusicBrainz and Cover Art Archive lookups stay off, and the log says so. Behind a reverse proxy, set TRUST_PROXY=true and PUBLIC_URL in the same file. Everything else is set in the web UI.

Where it keeps things

/usr/bin/tapedeck The binary, with the web UI embedded
/etc/tapedeck/tapedeck.env Infrastructure settings, read by the service. Kept across upgrades
/var/lib/tapedeck Databases, the credential key tapedeck.key, uploaded scans
/var/log/tapedeck Log files, alongside the journal
/usr/share/doc/tapedeck/env.example Every setting there is, and what it is for

It runs as a systemd dynamic user. There is no tapedeck account to create, and nothing else on the host can write to its directories. Logs are also in journalctl -u tapedeck.

Backups and upgrades

Back up /var/lib/tapedeck, but keep tapedeck.key out of the database backups. A backup stored with its key is the same as no encryption. Fedora and openSUSE restart the service when an upgrade lands. On Debian, Ubuntu and Arch the old version keeps running until you sudo systemctl restart tapedeck.

Anything else

Tapedeck is packaged for Linux only. On Debian 12, Ubuntu 22.04 or 24.04, another distribution, or another system, build it from source. You need Rust 1.88+ and Bun, and cargo build --release gives you one binary with the UI inside. A Docker image is in development.

Or try the demo first. It is the real binary on a Raspberry Pi Zero 2 W.

The signing key

Every repository is signed by the same key: home:abksh OBS Project. Check its fingerprint before you trust it.

A61C 52E4 D614 3F8B 39BF C36A 3DDB B9C7 336F E66A