Proxy Repositories
CloudRepo provides Proxy Repositories for Maven Repositories in order to prevent your builds from failing if a dependency disappears from a publicly available repository (like Maven Central).
It is rare for an artifact to be removed from Central, but when it does it can be very difficult to recover the exact artifact that you were previously depending on.
CloudRepo proxy repositories will retrieve your dependencies from a downstream maven repository and store a copy in a CloudRepo repository which is fully in your control.
Creating a Proxy Repository
Creating a Proxy Repository is identical to creating a local repository with the addition of selecting which downstream repository you wish to proxy.
Supported Remote Servers
Proxy Repositories require a downstream server to be specified. We have configured a list of the most common public repositories that are users have requested.
Don’t see a remote server that you need? We can add it! Please see the section on Adding Additional Remote Repositories for more information.
Select one of the following repositories to complete the creation of your proxy repository:
Maven Central
URL:
https://repo.maven.apache.org/maven2/
Apache Snapshots
URL:
https://repository.apache.org/snapshots/
Atlassian
URL:
https://maven.atlassian.com/content/repositories/atlassian-public/
Cloudera Repositories
URL:
https://repository.cloudera.com/content/groups/cloudera-repos/
Gradle Plugins
URL:
https://plugins.gradle.org/m2/
Grails Core
URL:
https://repo.grails.org/grails/core/
Hortonworks
URL:
https://repo.hortonworks.com/content/repositories/releases/
Jahia
URL:
https://maven.jahia.org/maven2/
JasperSoft
URL:
https://jaspersoft.artifactoryonline.com/jaspersoft/jaspersoft-repo/
JBoss Public
URL:
https://repository.jboss.org/nexus/content/groups/public/
JBoss Releases
URL:
https://repository.jboss.org/nexus/content/repositories/releases/
JCenter
URL:
https://jcenter.bintray.com/
LifeRay Public
URL:
https://repository.liferay.com/nexus/content/repositories/public/
Mulesoft Public
URL:
https://repository.mulesoft.org/nexus/content/repositories/public/
Sonatype Releases
URL:
https://oss.sonatype.org/content/repositories/releases/
Sonatype Public
URL:
https://oss.sonatype.org/content/groups/public/
Spring Lib M
URL:
https://repo.spring.io/libs-milestone/
Spring Plugins
URL:
https://repo.spring.io/plugins-release/
Adding Additional Remote Repositories
If you don’t see the repository that you need, please let us know and we’ll review and add it within an hour or two of receipt.
Upstream Credentials
Docker proxy repositories can authenticate to the upstream registry rather than pulling anonymously. Upstream registries rate-limit anonymous pulls, and that allowance is shared across every CloudRepo customer pulling anonymously from the same address, so it can run out. Supplying your own credential moves the limit onto your own account at that registry, and lets the proxy pull images that are private to it.
Upstream credentials apply to Docker proxy repositories. The proxy fetch path for Maven, npm and PyPI does not present a credential, so no credential fields are offered for those formats.
Where a credential can live
A credential can be attached in two places:
On one repository. Open the repository, then Settings → Upstream Credential.
On your organization, as a default for one upstream registry. Open Repositories → Upstream Credentials in the left-hand navigation. A default authenticates every proxy repository that pulls from that registry and has no credential of its own, so a rotation is one change instead of one per repository.
Which credential a pull uses
Resolution runs in this order, and the repository’s own Settings page names the winner for that repository:
The repository’s own upstream credential, if one is set.
Your organization’s default for that repository’s upstream registry, if one is set.
Anonymous.
A credential set on an individual repository therefore overrides the organization default for that repository, and leaves every other repository on that registry using the default. Removing the default returns every repository it covers to anonymous pulls.
Setting, rotating and removing
Setting and rotating are the same action, and both replace the credential completely: supply the username and the access token in full. There is no half to keep: CloudRepo encrypts the access token and never reads it back, so it cannot be shown, copied, or partially updated. The portal shows only that a credential is stored, and the username it was stored with.
Use a personal access token where the registry issues them, rather than your account password.
Removing a credential leaves the repository proxying. It simply stops authenticating and falls back to the next entry in the order above.
Every set, rotate and remove asks you to confirm your identity first, on a repository and on an organization default alike.
Public repositories always pull anonymously
A public proxy repository never presents an upstream credential, and neither a repository credential nor an organization default changes that. Anyone can pull through a public repository without signing in, and those pulls must not reach the upstream registry under your account or spend your allowance there.
CloudRepo enforces this in both directions: a repository that stores an upstream credential cannot be made public, and a public repository cannot store one. To authenticate a repository’s pulls, turn off Public Access first.
Supported upstream registries
An organization default can be set for the Docker registries CloudRepo proxies:
Docker Hub:
https://registry-1.docker.ioGitHub Container Registry:
https://ghcr.ioAWS ECR Public:
https://public.ecr.aws
Don’t see the registry you need? Please see Adding Additional Remote Repositories.
Connecting to Proxy Repositories
Uploading to Proxy Repositories
Uploading to proxy repositories via maven clients is not permitted - if you attempt to upload with Maven, the request will be rejected.
However, you can upload files directly through the Admin Portal.
Connecting Maven Clients to Proxy Repositories
Proxy repositories are used and configured just like any other Maven Repository. Please see the Maven Repositories documentation for complete instructions.
Removing Cached Dependencies
Dependencies can be removed from your proxy repositories by deleting them like you would for any other artifact. See deleting files and folders for more information.