Skip to content

Private-mirror access

Private mirrors belong to the organization. One organization setting decides who can install directly from them, and it applies to every current and future private mirror. Organization administrators can always use private mirrors directly.

Open organization settings, select Access, then Policies, and choose an option under Private mirrors:

Option Who can install directly from private mirrors
Organization administrators only Only organization administrators
All organization members Every active member
Controlled by each namespace Members of at least one namespace that allows it

Ravenstash asks you to confirm before the change takes effect.

With Controlled by each namespace, each namespace workspace shows a Private mirrors section. An organization or namespace administrator turns on Namespace members can use private mirrors there. Everyone who belongs to at least one such namespace can install directly from every private mirror.

The namespace switch does not let namespace administrators create, configure, or remove mirrors.

Mirror access covers direct installs from a private mirror. It is separate from using a mirror through a repository:

Decision Who decides
Create, configure, or remove a private mirror Organization administrators
Connect a mirror to a repository Repository Maintainers and Admins, where the organization makes the mirror available to that namespace
Set package resolution rules for a repository Repository Maintainers and Admins
Install packages a connected mirror provides through a repository Anyone who can read the repository
Install directly from the mirror The private-mirror setting above

For example, a repository Maintainer can connect the PyPI mirror to a repository and every Reader of that repository can install through it, even if the organization allows only administrators to use the mirror directly.

There are no per-mirror or per-person mirror permissions. A member’s personal token can include direct mirror access only while the member’s own mirror access allows it; see automation tokens.

For cache configuration, minimum package age, and cleanup, see Manage a private mirror.