Artifact Keeper on Ubuntu 24.04 LTS
by cloudimg
One registry for every package format, with a per instance login and nothing open.
Artifact Keeper is an open source universal artifact registry. Instead of running a separate server for every language your teams build in, it speaks the native protocols of many package ecosystems from one endpoint, so Maven, npm, PyPI, container, Cargo, Go, Helm and operating system packages can all be published to and pulled from the same place, with one set of credentials and one audit trail.
What you get. Artifact Keeper 1.10.0 on Ubuntu 24.04 LTS, the official upstream container images pinned by digest and run by systemd, with nginx and PostgreSQL installed natively from the Ubuntu archive so the components that terminate TLS and hold your data are patched by the same updates as the rest of the instance. Repository metadata lives in PostgreSQL on the instance and artifact content lives on the instance's own disk, so both survive restarts and reboots. A working registry is available within minutes of launch with no manual configuration.
No shared credential, and no default left behind. The administrator password is generated uniquely on each instance's first boot, and the registry keeps its own setup lock armed so that password must be changed before the API will serve. No two deployments share a credential, and nothing usable exists in the image at any moment. The signing secret behind tokens and sessions is generated per instance at the same time, so a token minted on one deployment means nothing on another. Scoped API tokens let a pipeline that only pulls hold a credential that cannot push.
Only SSH and HTTPS are reachable. The registry's own services never leave the loopback interface, there is no plaintext port at all, and the database has no network listener whatsoever. Anonymous access is switched off explicitly, so an unauthenticated caller is refused rather than shown a readable registry. The address the registry writes into the links it hands back is resolved per instance, so package managers and CI jobs work against it immediately over TLS.
Hardened beyond the defaults. The optional scanning and search services are deliberately switched off, because they do not fit comfortably on the recommended instance size and their vulnerability databases would be stale the day the image was captured; the deployment guide explains what each adds and how to turn it on. An on-instance self test pushes an artifact through the real front door, fetches it back and compares the bytes, confirms a read-only token cannot write, removes everything it created, and confirms every refusal the registry is supposed to make; each of its checks is itself tested against a known-bad input first.
Licensing and trademarks. Artifact Keeper is free software under the MIT License, with no subscription or licence key. Artifact Keeper and Ubuntu are trademarks of their respective owners. All product and company names are trademarks or registered trademarks of their respective holders; cloudimg is not affiliated with, endorsed by or sponsored by them, and packages the unmodified open source software. The cloudimg charge of $0.04 per vCPU/hour covers packaging, hardening and 24/7 support.