Upstreams and private mirrors
A private mirror gives one approved PyPI, npm, or Maven source an authenticated Ravenstash destination. The source can be an official public registry or another public or authenticated package repository.
Use a mirror directly for read-only dependency installs, or connect it to a matching private repository so private and approved external packages resolve through one selected Ravenstash target.
A source connected to a repository is called an upstream. A repository can use private mirrors and other private Ravenstash repositories as upstreams.
Find it in the app
Section titled “Find it in the app”| In the Ravenstash app | What you do there |
|---|---|
| Repository → Upstreams tab | Connect sources to a package format, and set their order and package age. Guides: Configure an official mirror, Connect a custom source, and Minimum package age. |
| Repository → Rules tab | Choose which upstreams can supply specific packages, and turn on Version-level resolution. Guide: Package resolution rules. |
| Remote caches on the Repositories page | Create, browse, and manage private mirrors. Guide: Manage a private mirror. |
Choose what you need to do
Section titled “Choose what you need to do”Understand private mirrorsLearn how direct mirror access, repository connections, security scanning, and package-age controls fit together.
Understand package resolutionSee how source order, selected packages, shadowed packages, and version lookup work.
Set package resolution rulesReserve the names you own, limit a package to selected upstreams, or combine versions from several sources.
Configure an official mirrorConnect the protected PyPI, npmjs.org, or Maven Central source for a repository format.
Connect a custom sourceCreate a private mirror for another public or authenticated PyPI, npm, or Maven source.
Set minimum package ageDelay brand-new external releases before they become available to builds.
Manage mirrored contentBrowse cached packages, review usage and connections, or remove stored content.
Mirror boundaries
Section titled “Mirror boundaries”- A mirror is read-only; publish private packages to a repository instead.
- PyPI, npm, and Maven mirrors connect only to repositories of the same format.
- OCI repositories do not use Ravenstash private mirrors.
- Direct mirror access and repository connections keep independent access and package-age settings.
For the repository side of this relationship, see Repositories.

