ArtiFerrisProduct

What ArtiFerris does today

Everything on this page exists today. What is planned is in the roadmap.

The application's interface exists in five languages; its documentation is in French.

Repositories

npm and Docker repositories, filed by organization or under your own name.

  • Three types per format: hosted, proxy in front of an upstream registry, and group of several repositories behind one address
  • read, write and admin rights, granted user by user
  • A storage quota and a retention per repository; latest is never purged
  • Public repositories, readable without an account, or private ones
  • A personal repository under /@user, next to the organization's repositories

Packages and images

A page per npm package and per Docker image.

  • npm: publish, install, unpublish and dist-tags, with npm, pnpm or yarn
  • Docker/OCI: push, pull and manifest deletion, with docker or podman
  • The README of an npm package, converted and sanitized on the server, and its install command
  • The size of each tag of an image, and the downloads of the last seven days
  • Republishing an unpublished npm version is refused

Artifact analysis

What the packages and images you distribute contain.

  • Dependency audit of an npm package on every publish
  • A Trivy scan of every Docker image pushed, which can be run again by hand
  • The results on the package or image page, with their severity

Organizations

Several teams or several customers on the same instance.

  • One organization per subdomain, with its repositories and users
  • Its branding: logo and favicon
  • Its identity provider: local accounts, LDAP or Active Directory, or OIDC
  • Organization administrators who act on their own alone; a default public organization for a single-organization instance

Public catalog

Give people without an account access to packages.

  • A catalog per format, a search that forgives typos and suggestions as you type
  • The /@user and /o/organization profiles, and the page of each public package
  • Search engine indexing, off by default and adjustable per organization

Documentation

Built into the application, at /docs.

  • Open to everyone, signed in or not
  • Getting started, usage (repositories, npm, Docker, account and tokens, public catalog), administration and the public API
  • In French, with search

Accounts, administration, languages and deployment

Accounts and access

Two-factor authentication is mandatory.

  • Mandatory for every account: an authenticator app (TOTP) or a passkey, and backup codes
  • Local accounts, LDAP or Active Directory, and OIDC
  • Invitations by e-mail: the administrator only enters the address, the invitee chooses their username
  • Personal API tokens, which administrators can list and revoke

Administration

What an administrator sees.

  • A dashboard, usage metrics and a health page
  • An audit log and a security log
  • Users, resetting their password or their two-factor authentication, and SMTP with a test e-mail
  • Export and import of the configuration

Languages

The interface in five languages.

  • French, English, Spanish, Italian and German; the account's language comes before the browser's
  • E-mails and the titles of public pages follow the reader's language

Technical aspects

What you deploy and what it needs.

  • A single Rust binary (Axum) serves the API, both registries and the Angular web application
  • PostgreSQL 18 for the data; archives and blobs on a volume
  • Docker Compose or a Helm chart for Kubernetes; image masmarino/artiferris, Trivy included
  • A hexagonal architecture, split over six Cargo crates

Not yet available

All of this is on the roadmap. None of it exists today.

See the roadmap

  • More formats: Maven and Gradle, PyPI, NuGet, Cargo, Go, Helm and raw repositories
  • S3-compatible object storage, to run several replicas: today, one volume and one replica
  • High availability and geographic replication
  • SAML
  • Package signing and provenance (Sigstore, npm provenance)

Try ArtiFerris, then deploy your own instance.

The public instance lets you discover the product. Your instance keeps your packages.

Start the stack with Docker Compose
git clone https://github.com/Masmarino/ArtiFerris.git
cd ArtiFerris
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SECRETS_ENCRYPTION_KEY, PUBLIC_URL and the first admin in .env
docker compose up -d --build