ArtiFerrisRegistries

Two registries, one console

ArtiFerris speaks the npm registry protocol and the Docker/OCI one: npm, pnpm, yarn, docker and podman use it as they would their usual registry. Each repository holds npm packages or Docker images, never both.

One group, two members

The .npmrc of a project points to a group. The group asks its members in the order you set, and the first one that holds the package answers. Turn the switch on to see what a second request changes.

The npm registry in the documentation

.npmrc
registry=https://acme.artiferris.pro/npm/npm-all/
//acme.artiferris.pro/npm/npm-all/:_authToken=<jeton>

# then, in the project
npm install left-pad

Package served by npmjs-proxy, from upstream

npm-all

npm-hostedhosted, does not have it
npmjs-proxyproxy, answered

upstream

registry.npmjs.organswered

npm-hosted does not contain left-pad, so the group moves to the next member. The proxy fetches the package from registry.npmjs.org, keeps it, then serves it.

The Docker registry

The password for docker login is an API token. Every push starts a Trivy scan of the image, whose results show on its page.

The Docker registry in the documentation

Log in, push and pull an image
echo <jeton> | docker login acme.artiferris.pro -u camille --password-stdin
docker tag api:1.4.0 acme.artiferris.pro/images/api:1.4.0
docker push acme.artiferris.pro/images/api:1.4.0
docker pull acme.artiferris.pro/images/api:1.4.0

The rules of a repository

What each repository keeps, refuses and checks.

Three types of repository
Hosted for your own packages, proxy for a cache in front of an upstream registry, group for several repositories of the same format behind one address. Reading through a group takes read on each of its members.
A quota per repository
The room the repository may take. A publish that would exceed it is refused.
Retention per repository
Keep only the last N versions or tags. The purge runs every 6 hours, and latest is never purged. Republishing an unpublished npm version is refused.
Dependencies audited
On every publish, ArtiFerris audits the package's dependencies. npm audit also works against ArtiFerris; the audited names and versions are then sent to registry.npmjs.org.
Images analyzed
Trivy, shipped in the ArtiFerris image, analyzes every image pushed. A scan can be run again by hand from the image page.
Public repositories
A public repository can be read without an account and shows in the public catalog. Anonymous reads have a budget per client and per minute, 1,200 by default.

Repositories in the documentation

Try ArtiFerris, then deploy your own instance.

The public instance lets you discover the product. Your instance keeps your packages.

Start the stack with Docker Compose
git clone https://github.com/Masmarino/ArtiFerris.git
cd ArtiFerris
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SECRETS_ENCRYPTION_KEY, PUBLIC_URL and the first admin in .env
docker compose up -d --build