Private-mirror access
Private mirrors belong to the organization. One organization setting decides who can install directly from them, and it applies to every current and future private mirror. Organization administrators can always use private mirrors directly.
Choose who can use private mirrors
Section titled “Choose who can use private mirrors”Open organization settings, select Access, then Policies, and choose an option under Private mirrors:
| Option | Who can install directly from private mirrors |
|---|---|
| Organization administrators only | Only organization administrators |
| All organization members | Every active member |
| Controlled by each namespace | Members of at least one namespace that allows it |
Ravenstash asks you to confirm before the change takes effect.
Let a namespace decide
Section titled “Let a namespace decide”With Controlled by each namespace, each namespace workspace shows a Private mirrors section. An organization or namespace administrator turns on Namespace members can use private mirrors there. Everyone who belongs to at least one such namespace can install directly from every private mirror.
The namespace switch does not let namespace administrators create, configure, or remove mirrors.
What this setting does not control
Section titled “What this setting does not control”Mirror access covers direct installs from a private mirror. It is separate from using a mirror through a repository:
| Decision | Who decides |
|---|---|
| Create, configure, or remove a private mirror | Organization administrators |
| Connect a mirror to a repository | Repository Maintainers and Admins, where the organization makes the mirror available to that namespace |
| Set package resolution rules for a repository | Repository Maintainers and Admins |
| Install packages a connected mirror provides through a repository | Anyone who can read the repository |
| Install directly from the mirror | The private-mirror setting above |
For example, a repository Maintainer can connect the PyPI mirror to a repository and every Reader of that repository can install through it, even if the organization allows only administrators to use the mirror directly.
There are no per-mirror or per-person mirror permissions. A member’s personal token can include direct mirror access only while the member’s own mirror access allows it; see automation tokens.
For cache configuration, minimum package age, and cleanup, see Manage a private mirror.

