People and access
Portal allow list and break glass
Hide the portal from networks you do not trust, with an emergency way back in.
Whitelist Admin Portal
- Under Allow a network, add your office and VPN ranges, or click Add the address I am on.
- Click Switch the filter on. It refuses unless your own address is on the list.
From any other address, /_admin and /_api answer a plain 404, so the portal does not even appear to exist.
Break glass keys
A break glass key lets someone in from an unlisted network in an emergency. Under Make a key, set how many times it can be used, how many minutes of access it grants and when the key expires. The person opens https://packages.example.com/_admin/?bgt=<key>. Keys are stored hashed, tries are throttled, and every use is audited. Revoke every active grant ends them all.
Whitelist Clients
- Only allow npm clients from the networks below limits the registry itself, not just the portal.
- Let a valid token through from any network lets remote developers in with a token.
- Allow GitHub SaaS keeps GitHub Actions runner ranges up to date automatically.
on the server
./whitelist.sh 10.20.0.0/16 --admin --label "office"
./whitelist.sh 203.0.113.7 --client --label "build server"
Note
The script adds networks but does not switch a filter on. The running server notices within 5 seconds.
Careful
Behind a reverse proxy, the proxy must set X-Forwarded-For to the real client address, and nothing but the proxy may reach the container port. Otherwise the allow list can be fooled.