Features
One catalogue. Four client worlds. A pipeline you control.
Operators see packages, artifacts, channels, and who may pull or publish. Clients speak native APT, pacman, MSI, and NuGet.
Formats
deb, Arch, MSI, and NuGet without a second product
deb
APT
Debian and Ubuntu
Signed indices and pool downloads. Suites follow the distribution, with channel suffixes such as trixie-testing.
pkg.tar.zst
Arch
pacman
Repository names match the channel. Clients install with the usual pacman drop-in and HTTP Basic pull token.
msi
Windows MSI
Windows installers
Latest JSON plus pool files per architecture. CI uploads the installer; clients fetch the current published build.
nupkg
NuGet
restore feeds
V3 restore per channel. One grant covers the software on that channel the same way it covers deb, Arch, and MSI.
Pipeline
Promote along a fixed lane
Upload always names a channel. Promote sets publication. Unpublish clears it. APT suite names follow the distribution plus an optional channel suffix.
- Alpha
- Beta
- Testing
- Canary
- Release
Capabilities
What ships with the operator UI
Four formats, one catalogue
Debian APT, Arch pacman, Windows MSI, and NuGet live as packages and versioned artifacts in the same catalogue. Grants and channels apply once — not once per format.
Release pipeline you can see
Upload requires a channel. Promote along alpha, beta, testing, canary, and release. Unpublish clears publication. Operators watch the lane instead of guessing which feed is current.
Visibility of what is in the repo
Packages and Artifacts list identity, format, distribution, architecture, channel, and status. Filter unpublished. Home shows uploads, downloads, published-by-channel, and recent publications.
Authorizations that match the job
Groups hold grants. Users inherit the union. Each grant names a package or Any, a channel or Any, and Allow pull, Allow publish, or Allow creating new packages.
Separate pull and publish credentials
Clients pull with HTTP Basic. CI publishes with a Bearer token shown once and rotatable. The admin token cannot upload. User detail copies APT, Arch, and NuGet snippets.
Retention and integrity
Named policies cap unpinned versions, age, and size. Pin keeps a build. Integrity scan marks missing blobs as error so the catalogue does not pretend the file is there.
Audit and field errors
Upload and download events with period filters. With the ArtifactD.ClientErrorReporting SDK in your apps, crash and curated error reports land on the artifact so operators see field failures next to the build that shipped.
Client error reporting SDK
Ship ArtifactD.ClientErrorReporting in apps that publish through the catalogue. The NuGet library queues crashes and curated errors, uploads them with the pull identity, and binds each report to the released artifact by package name and version.
Self-hosted Debian package
Install artifactd from APT, set the env file, and run the service. Dataplane serves clients; management serves the operator UI and API on a separate listen address.