Passer au contenu principal
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.artifact-hub-e44b75b5-5402-4e83-b6a4-ec35f3eac7eb/image2_logolarge.png

Artifact Hub on Ubuntu 24.04 LTS

par cloudimg

Need custom pricing or terms? Request a private offer directly from the seller - tailored for your organization.

Run your own catalogue of Helm charts, operators and policies on a single VM.

This is a repackaged open source product with additional charges for cloudimg support services.

Artifact Hub - the CNCF package catalogue, self hosted by cloudimg

Deploy your own Artifact Hub on Azure in minutes, with no manual installation and no shared credentials. This image delivers Artifact Hub at the pinned upstream release v1.23.0, compiled from source and hardened, so your catalogue is serving as soon as the machine boots.

What Artifact Hub Does

Artifact Hub indexes Helm charts, OLM operators, OPA and Kyverno policies, Falco rules, Tekton tasks, Krew kubectl plugins, container images and around thirty other artifact kinds, presenting each with its versions, changelog, values and values schema, declared security context and rendered documentation, all searchable from one page.

Run privately, it becomes an internal catalogue of your own charts and operators: your platform team publishes to it, your developers search it, and accounts and organisations decide who sees what, with no dependency on a public service. Artifact Hub is a Cloud Native Computing Foundation incubating project.

What Is Included

  • Artifact Hub 1.23.0 (Apache 2.0), built from upstream source pinned by git tag AND commit hash, so the image cannot drift onto a moving tag
  • The web interface and REST API on port 443 over HTTPS behind nginx, with port 80 redirecting to it
  • A scheduled indexer that re reads every registered repository every 30 minutes
  • The project's own documentation and OpenAPI reference served by YOUR machine, not fetched from the internet
  • The command line repository linter for validating package metadata before you publish
  • PostgreSQL 16 on the same machine, schema applied and verified, reachable only over loopback
  • A starter public repository under your own administrator account, so the catalogue is populated on day one and removable in one click
  • A default drop host firewall admitting only ports 22, 80 and 443
  • Fully patched base with unattended security upgrades enabled
  • 24/7 cloudimg engineers handling upgrades, tuning and configuration

Secure By Default: The Published Demo Account Never Exists

Upstream ships sample data that seeds a documented demo account. This image applies the schema with that sample data switched OFF, so the account is never created and the image ships with no accounts at all. On a freshly launched machine the published demo credential is proven actively refused by the running server, and its database row proven absent, before the image ships.

Secure By Default: Five Secrets, Generated On Your First Boot

The database password, the session cookie key, the cross site request forgery key, the administrator password and the TLS certificate are all generated uniquely on each machine's first boot, into a file only root can read. Upstream's defaults for those signing keys are literal placeholder strings; none survives into a running machine. The database role ships with no password at all.

The application and the indexer are gated on a marker first boot creates only after every secret exists and the administrator has been proven able to sign in, so nothing can start against an unconfigured database and nothing binds a port until provisioning finishes. The database and the unauthenticated metrics endpoint are bound to loopback only.

Getting Started

1. Launch the image on Standard_B2ms or larger 2. Read the per machine credentials from /root/artifact-hub-credentials.txt 3. Browse to the machine on port 443 and sign in 4. Add your own repository from the control panel

Licensing and Pricing

Artifact Hub is licensed under the Apache License 2.0 and is free; there is no per-seat fee. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support. The machine generates its own self signed TLS certificate on first boot; install a certificate for your own hostname, and restrict the ports to your team's source addresses in your network security group, before you publish internal package metadata to it.

Container image vulnerability scanning is an optional upstream component with its own scanning server and database, and is NOT included; repositories seeded by this image are registered with scanning switched off so nothing advertises a report that will not arrive. Everything else works exactly as upstream.

cloudimg Support

24/7 technical support by email covers deployment, upgrades, repository configuration and tuning. Critical issues receive a one-hour average response.

cloudimg is not affiliated with or endorsed by the Artifact Hub project or the CNCF. All product and company names are trademarks of their respective holders.

Vue d’ensemble

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.artifact-hub-e44b75b5-5402-4e83-b6a4-ec35f3eac7eb/image7_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.artifact-hub-e44b75b5-5402-4e83-b6a4-ec35f3eac7eb/image4_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.artifact-hub-e44b75b5-5402-4e83-b6a4-ec35f3eac7eb/image5_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.artifact-hub-e44b75b5-5402-4e83-b6a4-ec35f3eac7eb/image3_screenshot04.png
Français (Suisse)
Vos choix en matière de confidentialité – Icône Désactiver Vos choix de confidentialité
Confidentialité de l’intégrité des consommateurs Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies