Skip to content
Artifact Repository Manager

Security

Who may pull. Who may publish. What the index signs.

Authorizations sit on groups and grants, not on a shared password for the whole pool. Clients import a repository public key. The admin token cannot upload packages.

Controls

Product behaviour operators can show

  • Least privilege on packages

    A grant is software plus channel plus action. Any-package publish that can create names is an explicit tick, not a default.

  • Pull is not publish

    HTTP Basic pull tokens never upload. Bearer publish tokens never belong on workstation apt auth.conf files.

  • Signed catalogue indices

    APT and Arch indices are signed with the repository key. Clients import the published public key. Unsigned Release files are not served.

  • Compiled-form license

    The shipped artifactd package is licensed under ABUL-1.0. It is not an open-source redistribution of the product source.

Tokens

Two credentials, two jobs

Pull
HTTP Basic on the dataplane. High-entropy token. Copy into apt auth.conf, pacman, or NuGet config from the user detail panel.
Publish
Bearer token for CI upload. Shown once. Rotatable. Not the management admin token.
Grant knobs
Package or Any. Channel or Any. Allow pull. Allow publish. Allow creating new packages (Any plus publish only).
Report a vulnerability
Email hello@auroratech.ai with a description and reproduction. Do not file public issues with exploit detail.

Operator docsContact Aurora