Secure, self-hosted artifact registry — signed-pull verification, CVE scanning, 40+ formats
4.9K
Your hardware. Your data. Your terms.
The self-hosted artifact registry for teams who need to own what they ship.
This is the API / control-plane image for OrbitalReg. It runs alongside
orbitalreg/orbitalreg-frontend, Postgres, and an S3-compatible object store
(MinIO works out of the box). The image is a single static Go binary on a
distroless non-root base — no shell, no package manager, nothing to patch
but the binary itself.
A full-featured 30-day trial — every commercial feature, no NDA, no signup. The trial overlay runs without an identity provider: a break-glass local admin is created and SAML is bypassed, so you can sign in immediately and wire up your IdP later.
helm repo add orbitalreg https://orbitalreg.com/charts
helm repo update
# pulls the trial overlay + a throwaway MinIO from orbitalreg.com/charts
helm install orbitalreg orbitalreg/orbitalreg \
-n orbitalreg-trial --create-namespace -f values-trial.yaml
Prefer to pull the images directly?
docker pull orbitalreg/orbitalreg-api:0.1.0
docker pull orbitalreg/orbitalreg-frontend:0.1.0
→ Full quick-start, values files, and air-gapped tarball: https://orbitalreg.com/download
| 40+ package formats | Docker/OCI, Maven, npm, PyPI, NuGet, Go, Helm, Debian, RPM, Cargo, and more — one registry for everything. |
| Native CVE detection | Vulnerability scanning built in, not bolted on. No external scanner to license or feed. |
| Verify-on-pull gates | Cryptographic signature verification before any artifact leaves the registry — CMS, OpenPGP, RSA, Sigstore. Unverified pulls are blocked at the gate. |
| Air-gapped by default | First-class offline mode. Helm chart ships an air-gapped tarball variant. No outbound calls required. |
| GitOps-native | Terraform provider, Kubernetes operator, and the orbital CLI ship out of the box. Your registry, declarative. |
| Drop-in migration | Importers for every major registry — move in without a rewrite. |
We build software you install, not software you subscribe to. It runs on your hardware, your cluster, your air-gapped network — your traffic stays yours. Outbound is limited to an optional daily anonymous license-state heartbeat (install ID, version, license state — nothing about your users, repos, or artifacts), and it's disabled entirely in air-gap mode.
Two-tier license model: Free Forever (Security + Core Hosting — uploads, tokens, CVE detection, audit log, pull-gate) is always available. Commercial (premium integrations — webhooks, SSO, replication, migration importers) unlocks with a trial or commercial license.
0.1.0, latest — multi-arch manifest (linux/amd64, linux/arm64)orbitalreg/orbitalreg-frontendOrbitalReg — your packages, in your orbit.
Content type
Image
Digest
sha256:3ffa632ca…
Size
14.3 MB
Last updated
1 day ago
docker pull orbitalreg/orbitalreg-api