ArtiFerrisRegistries
Two registries, one console
ArtiFerris speaks the npm registry protocol and the Docker/OCI one: npm, pnpm, yarn, docker and podman use it as they would their usual registry. Each repository holds npm packages or Docker images, never both.
One group, two members
The .npmrc of a project points to a group. The group asks its members in the order you set, and the first one that holds the package answers. Turn the switch on to see what a second request changes.
registry=https://acme.artiferris.pro/npm/npm-all/
//acme.artiferris.pro/npm/npm-all/:_authToken=<jeton>
# then, in the project
npm install left-pad
Package served by npmjs-proxy, from upstream
npm-all
upstream
npm-hosted does not contain left-pad, so the group moves to the next member. The proxy fetches the package from registry.npmjs.org, keeps it, then serves it.
The Docker registry
The password for docker login is an API token. Every push starts a Trivy scan of the image, whose results show on its page.
echo <jeton> | docker login acme.artiferris.pro -u camille --password-stdin
docker tag api:1.4.0 acme.artiferris.pro/images/api:1.4.0
docker push acme.artiferris.pro/images/api:1.4.0
docker pull acme.artiferris.pro/images/api:1.4.0
The rules of a repository
What each repository keeps, refuses and checks.
- Three types of repository
- Hosted for your own packages, proxy for a cache in front of an upstream registry, group for several repositories of the same format behind one address. Reading through a group takes
readon each of its members. - A quota per repository
- The room the repository may take. A publish that would exceed it is refused.
- Retention per repository
- Keep only the last N versions or tags. The purge runs every 6 hours, and
latestis never purged. Republishing an unpublished npm version is refused. - Dependencies audited
- On every publish, ArtiFerris audits the package's dependencies.
npm auditalso works against ArtiFerris; the audited names and versions are then sent toregistry.npmjs.org. - Images analyzed
- Trivy, shipped in the ArtiFerris image, analyzes every image pushed. A scan can be run again by hand from the image page.
- Public repositories
- A public repository can be read without an account and shows in the public catalog. Anonymous reads have a budget per client and per minute, 1,200 by default.
Try ArtiFerris, then deploy your own instance.
The public instance lets you discover the product. Your instance keeps your packages.
git clone https://github.com/Masmarino/ArtiFerris.git
cd ArtiFerris
cp .env.example .env
# set POSTGRES_PASSWORD, JWT_SECRET, SECRETS_ENCRYPTION_KEY, PUBLIC_URL and the first admin in .env
docker compose up -d --build