Your npm packages and Docker images, on a registry you host.

Hosted repositories, proxies and groups, quotas, retention, dependency audits and image scans: one Rust binary and one PostgreSQL. In production, the server and its database take about fifty MiB of memory together.

Open ArtiFerris
$docker compose up -d --build

No third-party account, no telemetry sent. See the architecture.

$ kubectl top pod -n artiferris --containers
POD                                    NAME             CPU(cores)   MEMORY(bytes)
artiferris-7f497fb86-pcft9             artiferris-api   2m           5Mi
artiferris-postgres-7f7784f89f-rcd4s   postgres         9m           48Mi
The production instance, version 0.6.1, on a Kubernetes cluster (amd64), measured on 6 October 2026, a few minutes after the server restarted.

Use cases

Four typical situations, and how ArtiFerris answers them.

Your builds download their dependencies from a public registry, every time.
A proxy repository sits in front of registry.npmjs.org or Docker Hub: the first request fetches the package upstream, the next ones serve it from ArtiFerris. A group puts that proxy and your packages behind a single address.
You host the packages of several teams or several customers on the same instance.
Each organization has its subdomain, its repositories, its users, its branding and its identity provider. Its administrators act on it alone; a super-administrator sees them all.
You want to know what the images and packages you distribute contain.
Trivy analyzes every image pushed, and the scan can be run again by hand. The dependencies of an npm package are audited on every publish. The results show on the image or package page.
You want two-factor authentication not to depend on everyone's diligence.
It is mandatory for every account, whether local or coming from LDAP or OIDC. Command-line tools authenticate with an API token, which administration can list and revoke.

Product overview

Excerpts of the real interface, not mock-ups. The interface exists in French, English, Spanish, Italian and German.

The full list of features

Architecture

One process, six crates, a hexagonal architecture: the domain knows nothing of the database, and each registry protocol has its own crate.

The source code on GitHub

Architecture of an ArtiFerris instanceIsometric drawing. An npm or Docker client and a browser talk to a single Rust binary, artiferris-api, made of the crates api, npm, docker, application, domain and infrastructure. The binary keeps its data in PostgreSQL and its archives and blobs on disk, queries LDAP and OIDC directories and the SMTP server, and its proxies pull from upstream registries. An orange line follows an install to the upstream registry. Seven numbered circles lead to the tiles of the page.api npm docker application domain infrastructure artiferris-api: one binary npm or Docker client HTTPS, API token npm, pnpm, yarn, docker, podman Browser signed-in console or public catalog api, npm, docker REST API, registry protocols, web interface domain entities and ports, no I/O application use cases infrastructure adapters: PostgreSQL, files, SMTP, LDAP, OIDC, Trivy, proxies PostgreSQL accounts, repositories, rights, audit; migrations on start-up Storage npm archives and Docker blobs, on disk Upstream registries registry.npmjs.org, Docker Hub…: a proxy pulls and keeps Directories and mail LDAP, OIDC, SMTP npm install group, then proxy upstream

Fig. 1 One instance. The orange line follows an install, from the client to the upstream registry a proxy asks.

  • request or storage
  • an install, to upstream
  • directory asked at sign-in
  • a numbered tile of this page
  1. artiferris-domainEntities, value objects and the ports the rest depends on. No input or output.
  2. artiferris-applicationThe use cases. Depends on the domain only.
  3. artiferris-infrastructureAdapters: PostgreSQL (SQLx), files, SMTP, LDAP, OIDC, Trivy, Argon2, JWT.
  4. artiferris-apiThe Axum server: routes, wiring, and the Angular front end. It is the binary.
  5. artiferris-npmThe npm registry protocol.
  6. artiferris-dockerThe Docker/OCI registry protocol.

What is missing today

Worth knowing before you deploy.

Two formats only
npm and Docker/OCI. Maven, PyPI, NuGet, Cargo, Go, Helm and raw repositories are on the roadmap.
A single replica
Storage is a local file system: one volume, one replica. S3-compatible storage is planned.
No SAML
Accounts come from ArtiFerris, from LDAP or Active Directory, or from an OIDC provider.
No package signing
Signing and provenance (Sigstore, npm provenance) are on the roadmap.

Outlook

What is planned, with no version yet. An item is only ticked once it ships.

  1. FormatsMaven, PyPI, NuGet, Cargo, Go, Helm and raw repositoriesPlanned
  2. StorageS3-compatible object storage, for several replicasPlanned
  3. OperationsHigh availability and geographic replicationPlanned
  4. ProvenancePackage signing and provenancePlanned
  5. IdentitySAMLPlanned

Try ArtiFerris, then deploy your own instance.

The public instance lets you discover the product. Your instance keeps your packages.

Start the stack with Docker Compose
git clone https://github.com/Masmarino/ArtiFerris.git
cd ArtiFerris
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SECRETS_ENCRYPTION_KEY, PUBLIC_URL and the first admin in .env
docker compose up -d --build