Security
Who may pull. Who may publish. What the index signs.
Authorizations sit on groups and grants, not on a shared password for the whole pool. Clients import a repository public key. The admin token cannot upload packages.
Controls
Product behaviour operators can show
Least privilege on packages
A grant is software plus channel plus action. Any-package publish that can create names is an explicit tick, not a default.
Pull is not publish
HTTP Basic pull tokens never upload. Bearer publish tokens never belong on workstation apt auth.conf files.
Signed catalogue indices
APT and Arch indices are signed with the repository key. Clients import the published public key. Unsigned Release files are not served.
Compiled-form license
The shipped artifactd package is licensed under ABUL-1.0. It is not an open-source redistribution of the product source.
Tokens
Two credentials, two jobs
- Pull
- HTTP Basic on the dataplane. High-entropy token. Copy into apt auth.conf, pacman, or NuGet config from the user detail panel.
- Publish
- Bearer token for CI upload. Shown once. Rotatable. Not the management admin token.
- Grant knobs
- Package or Any. Channel or Any. Allow pull. Allow publish. Allow creating new packages (Any plus publish only).
- Report a vulnerability
- Email hello@auroratech.ai with a description and reproduction. Do not file public issues with exploit detail.