Skip to content

Proxy Repositories

View as Markdown

A proxy repository gives your builds one CloudRepo address for a public repository such as Maven Central. CloudRepo provides proxy repositories for Maven, npm, Python and Docker.

The first request for a dependency fetches it from the upstream repository, and CloudRepo stores a copy in your repository. You can delete the copy, and the next request fetches it from the upstream again.

Creating a Proxy Repository is identical to creating a local repository: choose Proxy as the Repository Mode, then pick the upstream under Select Remote Server.

Gradle Plugins (https://plugins.gradle.org/m2/) is picked in the list.

A proxy repository pulls from one upstream, chosen from this list.

Maven: Maven Central (https://repo.maven.apache.org/maven2/), Apache Snapshots, Atlassian, Clojars, Cloudera Repositories, Confluent, Google Maven, Gradle Plugins, Grails Core, Jahia, JBoss Public, JBoss Releases, LifeRay Public, Mulesoft Public, Spring Milestones and Spring Snapshots.

npm: npmjs.com (https://registry.npmjs.com, the default), npmjs.org, GitHub Packages and jsDelivr.

Python: pypi.org (https://pypi.org).

Docker: Docker Hub (https://registry-1.docker.io), GitHub Container Registry (https://ghcr.io) and AWS ECR Public (https://public.ecr.aws).

Don’t see a remote server that you need? See Adding Additional Remote Repositories.

If you don’t see the repository that you need, please let us know and we’ll review it.

Docker proxy repositories can authenticate to the upstream registry rather than pulling anonymously. Supplying your own credential lets the proxy pull as your account at that registry, including images that are private to it.

Upstream credentials apply to Docker proxy repositories. The proxy fetch path for Maven, npm and PyPI does not present a credential, so no credential fields are offered for those formats.

A credential can be attached in three places:

When you create the proxy repository. For a Docker proxy, the Create a Repository form has an Upstream Credentials section (optional).

On one repository. Open the repository, then Settings → Upstream Credential.

On your organization, as a default for one upstream registry. Open Repositories → Upstream Credentials in the left-hand navigation. A default authenticates every proxy repository that pulls from that registry and has no credential of its own, so a rotation is one change instead of one per repository.

Resolution runs in this order, and the repository’s own Settings page names the winner for that repository:

  1. The repository’s own upstream credential, if one is set.
  2. Your organization’s default for that repository’s upstream registry, if one is set.
  3. Anonymous.

A credential set on an individual repository therefore overrides the organization default for that repository, and leaves every other repository on that registry using the default. Removing the default returns every repository it covers to anonymous pulls.

Setting and rotating are the same action, and both replace the credential completely: supply the username and the access token in full. There is no half to keep: CloudRepo stores the access token encrypted and does not return it, so it cannot be shown, copied, or partially updated. The portal shows only that a credential is stored, and the username it was stored with.

Use a personal access token where the registry issues them, rather than your account password.

Removing a credential leaves the repository proxying. It simply stops authenticating and falls back to the next entry in the order above.

Public repositories always pull anonymously

Section titled “Public repositories always pull anonymously”

A public proxy repository never presents an upstream credential, and neither a repository credential nor an organization default changes that, so a public repository’s pulls never reach the upstream registry under your account.

CloudRepo enforces this in both directions: a repository that stores an upstream credential cannot be made public, and a public repository cannot store one. To authenticate a repository’s pulls, turn off Public Access first.

An organization default can be set for the Docker registries CloudRepo proxies:

  • Docker Hub: https://registry-1.docker.io
  • GitHub Container Registry: https://ghcr.io
  • AWS ECR Public: https://public.ecr.aws

Don’t see the registry you need? Please see Adding Additional Remote Repositories.

Uploading to a proxy repository is not permitted, from a build tool or from the Admin Portal: a proxy holds only what it fetched from its upstream.

Connecting Maven Clients to Proxy Repositories

Section titled “Connecting Maven Clients to Proxy Repositories”

A proxy repository is read like any other repository of its format. See Maven Repositories, npm Repositories, Python Repositories and Docker Repositories.

Dependencies can be removed from your proxy repositories by deleting them like you would for any other artifact. The next request for one fetches it from the upstream again. See deleting files and folders for more information. A deleted proxy file cannot be restored from the Trash.