Platform
Three services, one upload path. You can use any one of them on its own; most customers end up with all three.
Release channels
An artifact is immutable once uploaded. What moves is the channel pointer. Promoting
a build from beta to stable is a single API call and takes
effect at every edge within about 40 seconds; rolling back is the same call with the
previous version.
- Per-channel access rules — public, licence-key gated, or signed URLs with a TTL you set.
- Delta files generated on upload for clients that support them, full artifacts always kept.
- Download counters per channel, region and version, exported hourly.
Registry replication
Read-through replicas for the registry formats teams actually use: OCI images, npm, Maven, PyPI, NuGet, Debian and RPM repositories. A replica holds what your builds have asked for, not a full copy of the upstream world, so a new region warms up in hours rather than days.
| Format | Read-through | Private publish |
|---|---|---|
| OCI / Docker | yes | yes |
| npm | yes | yes |
| Maven | yes | yes |
| PyPI | yes | yes |
| NuGet | yes | — |
| Debian / RPM | yes | yes |
Artifact storage
Every object gets a SHA-256 on ingest and is verified again on each replication hop. Retention is policy-driven: keep all releases of a major version, keep the last n nightlies, keep anything referenced by a channel indefinitely. Nothing is deleted while a channel still points at it, whatever the policy says.
How it is built
Storage lives in three primary regions with cross-region replication; edges are cache-only and hold nothing that cannot be refetched. An edge losing its disk is a cache miss, never data loss. Origin is multi-homed and we run our own anycast for the control API.
Operations
- Change windows published a week ahead; emergency work notified within 15 minutes.
- Release-day capacity reservations for customers who tell us the date in advance.
- Quarterly restore drills from cold storage, results shared with customers on request.