Connect a custom package source
A custom package source connects an external HTTPS repository to a private Ravenstash mirror. The source can be public or require authentication.
Create the mirror
Section titled “Create the mirror”- Open Remote caches on the Repositories page of the Ravenstash app.
- Select Add cache, then Custom registry.
- Choose PyPI, npm, or Maven.
- Enter the external repository URL.
- Add source authentication when required.
- Choose whether the cache can be used directly.
- Select Create cache.
The mirror has its own private Ravenstash target. Use it directly through rvs
or connect it to a private repository.
Connect it to a private repository
Section titled “Connect it to a private repository”- Open the private repository.
- Open the Upstreams tab and select the matching ecosystem.
- Add the custom cache.
- Choose its order and package-age settings.
- Save the change.
A PyPI cache can connect only to PyPI, an npm cache only to npm, and a Maven cache only to Maven.
The order decides which source supplies a package that exists in more than one place; see How upstream package resolution works. To choose which upstreams can supply specific packages, add package resolution rules on the repository’s Rules tab.
Private external sources
Section titled “Private external sources”Source authentication is stored separately from developer and automation credentials. Developers continue authenticating to Ravenstash; they do not receive the external repository credentials.
Update the authentication details from the cache settings when the source credentials change.
Custom mirrors give your team one protected path to an approved source, without operating a separate proxy or distributing the source credentials to developers.

