Sign inSign up

orbitalreg/orbitalreg-api

By orbitalreg

•Updated 1 day ago

Secure, self-hosted artifact registry — signed-pull verification, CVE scanning, 40+ formats

Image
0

4.9K

orbitalreg/orbitalreg-api repository overview

OrbitalReg — Your packages, in your orbit.

⁠OrbitalReg — API

Your hardware. Your data. Your terms.
The self-hosted artifact registry for teams who need to own what they ship.

Version Arch Base Trial


This is the API / control-plane image for OrbitalReg. It runs alongside orbitalreg/orbitalreg-frontend, Postgres, and an S3-compatible object store (MinIO works out of the box). The image is a single static Go binary on a distroless non-root base — no shell, no package manager, nothing to patch but the binary itself.

⁠Try it in 5 minutes

A full-featured 30-day trial — every commercial feature, no NDA, no signup. The trial overlay runs without an identity provider: a break-glass local admin is created and SAML is bypassed, so you can sign in immediately and wire up your IdP later.

helm repo add orbitalreg https://orbitalreg.com/charts
helm repo update

# pulls the trial overlay + a throwaway MinIO from orbitalreg.com/charts
helm install orbitalreg orbitalreg/orbitalreg \
  -n orbitalreg-trial --create-namespace -f values-trial.yaml

Prefer to pull the images directly?

docker pull orbitalreg/orbitalreg-api:0.1.0
docker pull orbitalreg/orbitalreg-frontend:0.1.0

→ Full quick-start, values files, and air-gapped tarball: https://orbitalreg.com/download⁠

⁠What you get

40+ package formatsDocker/OCI, Maven, npm, PyPI, NuGet, Go, Helm, Debian, RPM, Cargo, and more — one registry for everything.
Native CVE detectionVulnerability scanning built in, not bolted on. No external scanner to license or feed.
Verify-on-pull gatesCryptographic signature verification before any artifact leaves the registry — CMS, OpenPGP, RSA, Sigstore. Unverified pulls are blocked at the gate.
Air-gapped by defaultFirst-class offline mode. Helm chart ships an air-gapped tarball variant. No outbound calls required.
GitOps-nativeTerraform provider, Kubernetes operator, and the orbital CLI ship out of the box. Your registry, declarative.
Drop-in migrationImporters for every major registry — move in without a rewrite.

⁠Self-hosted, sovereign, predictable

We build software you install, not software you subscribe to. It runs on your hardware, your cluster, your air-gapped network — your traffic stays yours. Outbound is limited to an optional daily anonymous license-state heartbeat (install ID, version, license state — nothing about your users, repos, or artifacts), and it's disabled entirely in air-gap mode.

Two-tier license model: Free Forever (Security + Core Hosting — uploads, tokens, CVE detection, audit log, pull-gate) is always available. Commercial (premium integrations — webhooks, SSO, replication, migration importers) unlocks with a trial or commercial license.

⁠Supported tags

  • 0.1.0, latest — multi-arch manifest (linux/amd64, linux/arm64)

OrbitalReg — your packages, in your orbit.

Tag summary

Content type

Image

Digest

sha256:3ffa632ca…

Size

14.3 MB

Last updated

1 day ago

docker pull orbitalreg/orbitalreg-api