Development teams often face this challenge: Java project JARs, frontend npm dependencies, container images, and Helm Charts are scattered across different services, each requiring separate repository addresses, access credentials, and caching strategies. Internal components rely on file sharing, public dependencies are downloaded repeatedly, and artifact permissions and security information are difficult to manage uniformly.
AngusRepo provides a unified enterprise-grade artifact repository platform, managing 10+ formats including Maven, Docker, npm, PyPI, NuGet, Helm, Go, APT, YUM, and Raw in a single system. It provides clear storage locations for artifacts, stable access points for dependencies, and makes publishing and governance easier to integrate into team workflows.
What is AngusRepo?
AngusRepo is an enterprise-grade multi-format artifact repository management system within the AngusKit suite, designed to uniformly host, proxy, distribute, and manage software artifacts. It supports 10 mainstream artifact formats and seamlessly integrates with developers' familiar build and package management tools through standard protocols.
- 10+ — Supported Formats
- 3 Types — Repository Types: Hosted/Proxy/Group
- Unified — Platform Management & Security
For development teams, AngusRepo is more than just a place to upload files. It connects internal artifact publishing, public dependency retrieval, version distribution, access control, and security governance, helping developers, builders, deployers, and managers work around a unified artifact source.
AngusRepo vs Other Solutions
As part of the AngusKit ecosystem, AngusRepo deeply integrates with AngusGit (code repository), AngusGM (project management), AngusSecurity (security scanning), and other products to provide enterprises with a complete DevOps toolchain from source code to artifact delivery. Compared to independently deploying Nexus, Artifactory, or Harbor, AngusRepo's advantages include:
- Unified Identity and Permission System: Shares users, organizations, and permission management with other AngusKit products
- Native Integration: Works seamlessly with AngusGit CI/CD, AngusSecurity scanning, and other features without additional configuration
- Simplified Operations: Unified deployment, monitoring, and upgrade processes reduce multi-system maintenance costs
- Optional Cloud-Native Architecture: Supports containerized deployment, horizontal scaling, and high availability configuration
Functional Architecture Overview
The diagram below shows AngusRepo's complete capability system from a product functional perspective, covering the entire workflow from user roles, client access, artifact formats, repository management, security governance to CI/CD integration, as well as typical artifact flow scenarios.
Architecture Diagram Explanation
The architecture diagram is divided into four main functional areas, showcasing AngusRepo's complete capability system:
① Client & Artifact Formats (Left · Green Area)
- Displays 10 supported artifact formats, each with dedicated cards and descriptions
- Developers use familiar package managers (Maven, Docker CLI, npm, etc.) and build pipelines to access
- All formats communicate with AngusRepo through standard protocols without learning new tools
② AngusRepo Core Repository (Center · Orange Area)
- Repository Types: HOSTED (internal hosting), PROXY (proxy caching), GROUP (aggregated access)
- Artifact Management: Repository creation, version browsing, access control, analytics & audit, REST API/Webhook
- Security & Compliance: Vulnerability scanning, license analysis, SBOM export, scanning policy configuration
③ CI/CD & Ecosystem Collaboration (Right · Purple Area)
- Seamless integration with mainstream CI/CD tools like Jenkins, GitHub Actions, GitLab CI
- Deep collaboration with AngusKit ecosystem (AngusGit, AngusAI)
- Connect third-party tools and custom workflows through REST API and Webhook
④ Typical Artifact Flow (Bottom · Yellow Area)
- Public Dependency Retrieval: Upstream Repository → PROXY Cache → GROUP Aggregation → Development/Build Pull
- Internal Artifact Delivery: CI Build → HOSTED Hosting → Security Scanning → Downstream Consumption
💡 Tip: The architecture diagram supports dark mode and automatically adapts to your system theme preferences.
Core Capabilities: What Can AngusRepo Do?
1. Unified Multi-Format Management
Manage 10 artifact formats in a single platform. Teams can plan repositories by format and purpose without introducing separate management processes for each package or image type. All artifacts use unified permission systems, audit logs, and storage management.
2. Host Internal Artifacts
Through HOSTED (hosted) repositories, teams can store their own built and published packages, images, and other artifacts, and provide access to developers, CI/CD pipelines, or downstream environments based on permissions. Internal artifacts thus have unified, traceable publishing locations without relying on temporary files or personal machine transfers.
Typical Use Cases:
- Publish internal Java component libraries to Maven hosted repositories
- Push enterprise application Docker images for test and production environments to pull
- Host team-developed npm private packages for frontend projects
3. Proxy and Cache Public Dependencies
Through PROXY (proxy) repositories, AngusRepo can proxy upstream repositories for supported formats and cache retrieved dependencies. Development and build processes thus gain unified dependency access points and reduce repeated downloads' direct dependency on external networks.
Key Advantages:
- Accelerate Builds: Local caching after first download, subsequent builds don't need to repeatedly fetch from public networks
- Improve Stability: Reduce dependency on external repository availability
- Save Bandwidth: Team-shared caching reduces duplicate traffic
- Offline Support: Cached dependencies can be used in network-restricted environments
4. Aggregate Multi-Source Access
GROUP (aggregated) repositories can query multiple member repositories in configured order, allowing clients to retrieve artifacts from different sources through a single read-only entry point. It's especially suitable for organizing internal artifact repositories and public dependency proxies into a unified pull entry point.
Example: A Maven group repository can sequentially query internal releases, internal snapshots, and Maven Central proxy, with developers only needing to configure one repository address.
5. Security and Compliance Governance
AngusRepo provides complete artifact security governance capabilities:
- Access Control: Fine-grained permission management based on users, organizations, and projects
- Access Tokens: Support for read-only, read-write, specific repository-scoped tokens for easy CI/CD integration
- Activity Audit: Records all artifact upload, download, delete operations to meet compliance requirements
- Security Scanning: Integrates with AngusSecurity for artifact vulnerability scanning and license analysis
- SBOM Generation: Automatically generates Software Bill of Materials
- Lifecycle Management: Automatically deletes expired or unused artifacts through cleanup policies to save storage space
6. Integration with DevOps Workflows
- Standard Protocol Support: Developers continue using familiar tools like Maven, Docker CLI, npm, pip without learning new commands
- REST API: Complete API support for automated operations like artifact queries, version management, repository configuration
- Webhook Notifications: Artifact publish, delete events can trigger external systems, such as notifying test environments for automatic deployment
- CI/CD Integration: Seamlessly works with Jenkins, GitLab CI, GitHub Actions, AngusGit CI, and more
Supported Artifact Formats and Repository Types
AngusRepo's 10 supported formats cover common development language ecosystems, container delivery, system packages, and generic files. The table below lists supported repository types for each format:
| Artifact Format | HOSTED | PROXY | GROUP | Typical Use |
|---|---|---|---|---|
| Maven | ✓ | ✓ | ✓ | Java/JVM project dependency management, internal component publishing |
| Docker / OCI | ✓ | ✓ | ✗ | Application image hosting, public image proxy and deployment delivery |
| npm | ✓ | ✓ | ✓ | Frontend dependency management, internal npm package publishing |
| PyPI | ✓ | ✓ | ✓ | Python project dependency retrieval and internal package distribution |
| NuGet | ✓ | ✓ | ✓ | .NET application dependency management and component publishing |
| Helm | ✓ | ✓ | ✗ | Kubernetes application Chart hosting and distribution |
| Go | ✗ | ✓ | ✗ | Retrieve and cache Go dependencies through module proxy |
| APT | ✓ | ✗ | ✗ | Debian/Ubuntu .deb package hosting and distribution |
| YUM | ✓ | ✓ | ✗ | RPM-based Linux environment package distribution |
| Raw | ✓ | ✓ | ✗ | Installers, binary files, archives, and other files |
Notes:
- ✓ indicates the format supports this repository type
- ✗ indicates the format does not support this repository type
- HOSTED: Store team's own artifacts
- PROXY: Cache upstream public repository dependencies
- GROUP: Provide unified multi-source query entry point (only some formats supported)
These 10 formats each retain their ecosystem's usage patterns. Developers can still use familiar command-line tools and build systems to access, with repository addresses, authentication methods, and format-specific configurations following respective format guidelines. See the complete format usage guide.
How Do the Three Repository Types Work Together?
AngusRepo organizes different artifact flow patterns using three repository types. Each has different responsibilities, and not all artifact formats support all three types simultaneously.
| Repository Type | Main Responsibility | Typical Use |
|---|---|---|
| HOSTED | Store team's own artifacts and provide authorized access | Publish internal packages, components, and images |
| PROXY | Connect to upstream repositories and cache retrieved dependencies | Centrally access public dependencies, reduce duplicate downloads |
| GROUP | Query multiple member repositories in configured order, providing unified read-only entry | When format supports, organize internal artifacts and public dependencies into a single pull address |
For example, in a typical Maven project, a team can place internal releases in maven-releases (HOSTED), configure Maven Central as maven-central (PROXY), and create maven-public (GROUP) for developers to resolve dependencies. Developers pull dependencies through the unified entry point, while CI/CD publishes new versions to the corresponding HOSTED repository.
This division makes "where to get dependencies" and "where to publish artifacts" clear, and facilitates separate team management of publishing permissions, dependency sources, and version strategies. See the Repository Management Manual for more repository planning approaches.
Typical Use Cases: What Problems Does AngusRepo Solve?
1. Unified Artifact Management for Multi-Language Teams
Scenario: An internet company uses Java (backend), React (frontend), Python (data analysis), and Go (microservices), each language with its own dependency management approach.
Problems:
- Developers need to separately configure Maven, npm, PyPI, Go proxy repository addresses and credentials
- Different repositories have independent permission management, difficult to unify accounts and tokens
- Lack of unified audit and monitoring, unable to comprehensively understand artifact usage
Solution: Use AngusRepo to create repositories for corresponding formats, managing all artifacts uniformly. Team members use the same identity system to access different format repositories, and administrators manage permissions, audit logs, and storage quotas through one platform.
2. Accelerate Builds and Improve Stability
Scenario: An enterprise team is in a network-restricted environment, with slow and unstable access to Maven Central, npm Registry, and other public repositories.
Problems:
- Builds repeatedly download dependencies from public networks, time-consuming and prone to failure
- Multiple developers and CI/CD nodes repeatedly download the same dependencies, wasting bandwidth
- External repositories occasionally unavailable causing build interruptions
Solution: Configure AngusRepo's PROXY repositories to proxy upstream public repositories. After the first download, dependencies are cached locally, subsequent builds pull directly from cache, build speed improves by 60%, and no longer affected by external networks.
3. Standardized Publishing of Internal Component Libraries
Scenario: A development team maintains multiple internal common component libraries for use by various business lines.
Problems:
- Component publishing relies on manual JAR file copying to shared directories, chaotic version management
- No formal version numbers and change records, downstream projects don't know which version to use
- Lack of access control, anyone can modify or delete components
Solution: Use AngusRepo's HOSTED repositories to host internal components. Component libraries publish official versions through mvn deploy, downstream projects reference through standard dependency declarations. Combined with access tokens, only authorized CI/CD pipelines can publish new versions, all operations have audit records.
4. Centralized Container Image Management
Scenario: A team uses Kubernetes to deploy microservices, needing to manage numerous application images and base images.
Problems:
- Application images pushed to Docker Hub public repositories pose security risks
- Pulling base images from Docker Hub is slow and affected by access restrictions
- Lack of image vulnerability scanning and version management
Solution: Use AngusRepo to create Docker HOSTED repositories to host application images, create Docker PROXY repositories to proxy Docker Hub. Combined with AngusSecurity, automatically scan pushed images for vulnerabilities, blocking images with critical vulnerabilities from deploying to production environments.
5. Artifact Governance Meeting Compliance Requirements
Scenario: A financial enterprise needs to meet regulatory requirements for comprehensive software supply chain audit and management.
Requirements:
- Record source, publisher, and usage of all artifacts
- Regularly scan dependencies for security vulnerabilities and license compliance
- Generate SBOM (Software Bill of Materials) for compliance reporting
Solution: AngusRepo records all artifact upload, download, delete operations, and integrates with AngusSecurity for vulnerability scanning and license analysis. Automatically generates SBOM documents to meet compliance audit needs. Configure cleanup policies to automatically delete expired versions, reducing storage costs.
Team Type Applicability
| Team Type | Key Benefits |
|---|---|
| Small to Medium Development Teams (10-50 people) | Quickly build private repositories, simplify dependency management, reduce operational burden |
| Multi-Language Stack Teams | Unified management of multiple formats, reduce learning and configuration costs |
| Microservice & Container Teams | Centrally manage container images and Helm Charts, accelerate deployment processes |
| Enterprise Development Teams (50+ people) | Fine-grained permission control, audit, security scanning, meet compliance requirements |
| Network-Restricted or Offline Environments | Cache public dependencies, ensure build stability and speed |
Quick Start: Configuration Examples
Maven: Publishing and Pulling Java Artifacts
Below shows how to configure a Maven project to use AngusRepo: developers retrieve dependencies from a unified repository entry, CI/CD publishes build artifacts to hosted repositories.
1. Create Repositories in AngusRepo
| Repository Name | Type | Purpose |
|---|---|---|
maven-releases |
HOSTED |
Store internal release versions |
maven-central |
PROXY |
Proxy Maven Central |
maven-public |
GROUP |
Provide unified dependency pull entry for clients |
Add maven-releases and maven-central to maven-public.
2. Configure Maven Credentials
Configure publishing credentials in ~/.m2/settings.xml. It's recommended to inject tokens via environment variables, don't commit actual tokens to code repositories:
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0">
<servers>
<server>
<id>angusrepo-releases</id>
<username>${env.ANGUS_REPO_USERNAME}</username>
<password>${env.ANGUS_REPO_TOKEN}</password>
</server>
</servers>
</settings>
3. Configure Project Dependencies and Publishing Target
Configure in the project's pom.xml:
<repositories>
<repository>
<id>angusrepo-public</id>
<url>https://repo.anguskit.com/maven/maven-public</url>
</repository>
</repositories>
<distributionManagement>
<repository>
<id>angusrepo-releases</id>
<url>https://repo.anguskit.com/maven/maven-releases</url>
</repository>
</distributionManagement>
4. Publish Artifacts
mvn deploy
For more configuration methods, see the Maven Format Manual.
Docker: Hosting and Pulling Container Images
Configure Docker to use AngusRepo for hosting and pulling container images.
1. Create Repositories in AngusRepo
| Repository Name | Type | Purpose |
|---|---|---|
docker-hosted |
HOSTED |
Store internal application images |
docker-hub |
PROXY |
Proxy Docker Hub |
2. Login to AngusRepo Docker Repository
docker login repo.anguskit.com
Enter username and access token (generated in AngusRepo user settings).
3. Push Images to Hosted Repository
# Build image
docker build -t repo.anguskit.com/docker-hosted/myapp:1.0.0 .
# Push image
docker push repo.anguskit.com/docker-hosted/myapp:1.0.0
4. Pull Public Images from Proxy Repository
# Pull Docker Hub image (through AngusRepo proxy)
docker pull repo.anguskit.com/docker-hub/nginx:latest
5. Use in CI/CD
# GitLab CI example
stages:
- build
- push
build-image:
stage: build
script:
- docker build -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .
- echo $ANGUS_REPO_TOKEN | docker login -u $ANGUS_REPO_USERNAME --password-stdin repo.anguskit.com
- docker push repo.anguskit.com/docker-hosted/myapp:$CI_COMMIT_SHA
For more configuration methods, see the Docker Format Manual.
npm: Managing Frontend Dependencies
1. Configure npm to Use AngusRepo
# Set npm registry
npm config set registry https://repo.anguskit.com/npm/npm-public/
# Configure authentication token
npm config set //repo.anguskit.com/npm/:_authToken YOUR_ACCESS_TOKEN
2. Install Dependencies
npm install
3. Publish Internal Packages
npm publish --registry https://repo.anguskit.com/npm/npm-releases/
For more format configuration examples, see the complete format usage guide.
Frequently Asked Questions
Q: How to generate access tokens?
Login to AngusRepo → User Settings → Access Tokens → Generate New Token. You can specify token permission scope (read-only/read-write) and validity period.
Q: How do PROXY repositories handle authentication?
If the upstream repository requires authentication (such as private Docker Registry), configure upstream credentials when creating the PROXY repository. AngusRepo will automatically use these credentials when requesting upstream.
Q: How to clean up old artifact versions?
Configure cleanup policies in repository settings to automatically delete artifacts according to these rules:
- Keep the most recent N versions
- Delete artifacts unused for more than X days
- Delete old versions of specific version patterns (such as SNAPSHOT)
Q: Does it support anonymous access?
Yes. You can enable anonymous reading in repository settings, allowing unauthenticated users to pull artifacts. However, publishing artifacts always requires authentication and authorization.
Integration with Development Workflows
AngusRepo can serve as the artifact entry point in build and delivery processes:
- Development Phase: Developers resolve dependencies locally, retrieve public dependencies from PROXY repositories, and internal components from HOSTED repositories
- Build Phase: CI/CD publishes artifacts to HOSTED repositories after build completion, triggering Webhook notifications to test environments
- Testing Phase: Test environments pull corresponding artifact versions from controlled repository addresses for deployment
- Release Phase: Production environments pull deployments from approved artifact versions, all operations have complete audit records
Combined with permission management, cleanup policies, audit, and security governance, teams can more easily unify artifact flow patterns and continuously maintain understandable, reusable delivery processes.
Implementation Recommendation: For teams already using automated pipelines, start with the most commonly used formats like Maven, npm, or Docker, verify basic processes, then gradually expand to other formats based on project and team needs.
Originally published at anguskit.com.

Top comments (0)