How to Manage Repositories and Upstream Mirrors

Beginner 15 minutes DevOps / Platform Engineers Getting Started

Enable and disable repositories, configure anonymous access, browse cached packages, view per-repository traffic, and set up client connection guides.

Overview

Repositories in Chainsaw represent upstream package registries that the proxy mirrors. Each repository is a pull-through cache for a specific ecosystem — when a package is requested, Chainsaw fetches it from upstream, caches it locally, and serves it to the client. This tutorial covers managing these repositories.

Prerequisites

  • Admin or Owner role in Chainsaw
  • Understanding of which package ecosystems your organization uses

Step 1: View All Repositories

Navigate to Repositories in the sidebar. You’ll see a list of all configured repositories.

Repository listing page
All configured repositories with their format, status, and traffic summary

Each repository card shows:

FieldDescription
NameRepository identifier (e.g., npmjs, pypi)
FormatPackage ecosystem (npm, pip, maven, etc.)
UpstreamThe source registry URL
StatusEnabled or disabled
PackagesNumber of cached packages
TrafficRequest count in the selected time range

Step 2: Enable or Disable Repositories

Toggle repositories on or off based on which ecosystems your organization needs:

  1. Click on a repository
  2. Toggle the Enabled switch
  3. Disabled repositories reject all requests
Enabling/disabling a repository
Toggle repositories on or off — disabled repos reject all requests
Disable repositories your organization doesn’t use to reduce attack surface. If nobody uses Cargo, there’s no reason to leave the crates-io mirror active.

Step 3: Configure Anonymous Access

By default, repositories require client credentials. You can enable anonymous access for specific repositories if needed (e.g., for open development environments):

  1. Click on the repository
  2. Toggle Anonymous Access
  3. When enabled, requests without credentials are accepted
Anonymous access toggle
Enable anonymous access for repositories that don't require authentication
Anonymous access bypasses client identification. You lose the ability to trace requests to specific teams or apply client-scoped policies. Use sparingly.

Step 4: Browse Cached Packages

Click into a repository to see the packages that have been cached:

Package browser within a repository
Browse all packages cached in a repository

The package browser shows:

  • Package name and versions
  • Last access time
  • Download count
  • Vulnerability status (if scanned)

Step 5: View Per-Repository Traffic

Each repository has a Traffic tab showing request metrics:

  • Total requests over time
  • Cache hit ratio
  • Top requested packages
  • Blocked requests
Per-repository traffic metrics
Traffic metrics for a specific repository showing cache hits and request patterns

This helps you understand:

  • Which ecosystems generate the most traffic
  • How effective the cache is per registry
  • Which packages are most frequently requested

Step 6: View Client Setup Guides

Each repository page includes a Setup Guide section with copy-paste instructions for configuring package managers to use that specific repository.

Client setup guide for a repository
Per-repository setup instructions for package managers

Share these guides with your development teams to simplify onboarding.

Step 7: Understand Negative Caching

Chainsaw uses negative caching to prevent repeated 404 requests to upstream registries. When an upstream returns a 404:

  1. Chainsaw caches the negative result
  2. Subsequent requests for the same package return 404 immediately
  3. The cache expires after a configurable time

This reduces load on upstream registries and improves response times for packages that don’t exist.

Negative caching concept
Negative caching prevents repeated upstream requests for non-existent packages

Step 8: Format-Aware URL Rewriting

For some ecosystems (PyPI, Composer), upstream responses contain absolute URLs that point back to the original registry. Chainsaw automatically rewrites these URLs to point through the proxy, ensuring all subsequent requests stay on the Chainsaw path.

This rewriting is transparent to the client. Package managers work normally without any special configuration beyond pointing at the Chainsaw repository URL.

Supported Repository Formats

FormatUpstream DefaultRepository Path
npmregistry.npmjs.org/repository/@default/npmjs/
PyPIpypi.org/repository/@default/pypi/simple/
Mavenrepo1.maven.org/repository/@default/maven-central/
NuGetapi.nuget.org/repository/@default/nuget-official/v3/index.json
Cargocrates.io/repository/@default/crates-io/
Composerpackagist.org/repository/@default/packagist/
Goproxy.golang.org/repository/@default/gomod/
Dockerregistry-1.docker.io/repository/@default/docker-hub/
RubyGemsrubygems.org/repository/@default/rubygems-official/
APTvaries/repository/@default/apt-main/
Yum/DNFvaries/repository/@default/yum-baseos/
Hugging Facehuggingface.co/repository/@default/huggingface/

Next Steps