When something goes wrong
Lockdown and degraded registry modes
A worm spreading through npm, a registry compromise, a week nobody trusts the upstream. Registry mode at the top of the dashboard changes what the box fetches, with one click and a reason.
- normal: fetches anything the rules allow.
- degraded: nothing new is fetched by name. Packages the registry already holds keep refreshing and installing, new versions included, but a package it has never fetched gets a
503naming the mode. - lockdown: nothing is fetched from upstream at all. Metadata only offers versions and files already cached, so ranges settle on something that can be served. Quarantine acts strict.
Approvers and admins can raise the mode the moment an incident lands. Only admins bring it back down. Every change needs a reason, is in the audit trail, emails the admins, and shows as a badge in the top bar until it is back to normal.
Lockdown only helps if the cache holds what you need, so ForgeRepo™ makes that easy to check. An allow rule for any version caches the current version as soon as it is written. Cache the ticked rules downloads pinned versions now. Check for drift finds files the database thinks it has but the disk does not.
There is also a plain Upstream registry enabled switch. Off, and the box never calls out again, serving what is on disk at any age. That was the right answer on the day of the keyv compromise.
In short
- Three modes, one click, a reason required
- Degraded keeps what you hold fresh, lockdown freezes everything
- Ranges resolve among cached versions only, so builds keep working
- Admins emailed, badge on every page, audit trail entry
- Saving settings or importing a config never changes the mode
In the documentation
- Registry modes: degraded and lockdown Administrator Guide
- Scenarios: what happens, and what you do Administrator Guide
Goes well with
- Kill switch Take a package, a version range, one file hash or a whole advisory away from everyone, at once.
- Who has it Search a package, a hash or a CVE and see the applications, environments and pipelines that pulled it.
- S3 and Azure storage Keep the cache in a bucket. Every upload checked by hash, and a local copy cap on the disk.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.