// unattended-upgrades drop-in so the gitea apt source (agent/internal/repo) actually gets
// pulled in automatically, not just reconciled into sources.list. Path B of issue #109: apt
// covers Debian today while the signed-manifest updater (bitua-updater.timer) stays dormant
// until a manifest is published.
//
// Gitea's generated Release file (dists/bookworm/Release) sets Origin/Label to its own
// generic "Gitea: Git with a cup of tea" string, not per-repo, so they can't be used to match
// only the bitua source — every package on gitea.bitua.io would match. Origins-Pattern
// supports a URI-based "site=" selector instead, which is specific to this host.
Unattended-Upgrade::Origins-Pattern {
	"site=gitea.bitua.io";
};

// The daemon's own loop (repo reconcile) and postinst (try-restart on upgrade) already handle
// bringing bitua-agentd back up on the new binary; an unattended reboot is never needed for
// this package and would be a surprise on a server.
Unattended-Upgrade::Automatic-Reboot "false";

// Without these, Origins-Pattern is inert: unattended-upgrades never runs unless invoked
// manually.
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
