Authentication
Built-in sign-in, automatic first administrator, LDAP, Google, and generic OIDC flows.
Platform security
This page describes controls present in the source project and their boundaries. It makes no certification or independent-assurance claim.
Built-in sign-in, automatic first administrator, LDAP, Google, and generic OIDC flows.
Six fixed platform roles, local and LDAP groups, and LDAP membership mapping at sign-in.
User/group/anonymous subjects, organization/project/repository scope, name/key matching, exclusions, and label ALL/ANY rules.
Scoped permissions and a separate token lifecycle for automation.
Durable audit, package-usage, operation, outbound, and application-log records.
TLS validation, SSRF protection, redirect inspection, system proxy, and write-only upstream-secret handling.
Architecture
Restricted to read-only proxy repository flows and gated by the Anonymous account being enabled.
Basic, bearer, and selected format-specific header/token credentials are supported; secret values are never returned by read APIs.
Metadata and audit records live in PostgreSQL; artifact content lives in the selected filesystem or S3-compatible storage component.
System-proxy and repository-proxy settings provide controlled egress. No public, verified air-gapped operating profile is published.
No public certification, independent penetration-test summary, assurance report, or SLA document is currently published.
Technical evaluation
Let’s review your formats, deployment, and security policies together.