First setup
Require tokens
Make every npm, pip and docker client prove who it is.
Out of the box anyone who can reach packages.example.com can pull what the rules allow. Turning on tokens means every download is tied to a person or a pipeline, and rules can be scoped by application and environment.
- Give every pipeline a token first, placed in its application and environment.
- Open Tokens. Under Who can pull packages, tick Require tokens and confirm.
- Watch Traffic for 401 answers from clients you missed.
Careful
Any client without a token stops working right away, including CI jobs.
Settings, Registries, Only answer package managers sends a 404 to browsers and scanners that are not npm clients.