Infrastructure

Managed Artifactory

Assistance-operated Artifactory service for packages, build artifacts, Helm charts, and Docker/OCI repositories


Managed Artifactory is for teams that need a dependable repository layer for packages, build outputs, Helm charts, and Docker/OCI images without maintaining repository infrastructure themselves. Assistance operates the Artifactory platform while your engineering teams keep ownership of artifacts, image contents, tags, releases, and deployment decisions.

Best-fit use cases#

Use caseWhy managed Artifactory fits
Private packages and artifactsPublish internal libraries, SDKs, binaries, release bundles, and build outputs under controlled access
Dependency proxyingCache upstream package ecosystems to improve build reliability and reduce external dependency risk
Docker/OCI image publishingPublish container images and OCI artifacts through Artifactory Docker/OCI repositories
Environment promotionPromote tested artifacts and images from development to staging to production with clear rules
GovernanceApply access control, audit logging, vulnerability/license workflows, retention policies, and cleanup controls consistently

What Assistance operates#

AreaIncluded managed service responsibility
ProvisioningArtifactory setup, storage backend, endpoint naming, TLS, and secure baseline configuration
Repository designHosted, remote, and virtual repository layout based on package ecosystems, Docker/OCI image flows, teams, and environments
AvailabilityHealth monitoring, storage durability design, backup/snapshot approach where applicable, and runbooks
AccessUser/team permissions, service accounts, tokens, image pull secret guidance, and rotation support
GovernanceVulnerability/license scanning workflows where included, policy recommendations, audit logging options, and retention controls
IntegrationCI/CD credentials, package-manager configuration, Kubernetes pull secrets, webhooks, and promotion workflow support
SupportSeverity-based support for Artifactory platform incidents and escalation for covered production release paths

Ownership boundary#

ResponsibilityAssistance ownsCustomer owns
Artifactory platformRuntime, storage, TLS, monitoring, upgrades, retention controls, and platform incidentsBuild tools, source repositories, and deployment decisions
Packages, images, and tagsStorage, repository configuration, access controls, and retention implementationPackage contents, Dockerfiles, base images, tag strategy, release promotion, and rollback choices
Proxy repositoriesCache configuration, availability, and upstream health visibilityApproved upstream sources and dependency usage policy
Security findingsScanner operation and reporting workflow where includedRemediation, exception approval, and application or license risk acceptance
AccessRoles, tokens, service accounts, and rotation procedureUser approvals, internal access reviews, and pipeline secret consumption
Storage growthMonitoring and retention policy implementationArtifact lifecycle rules and legal/business retention requirements

Deployment options#

OptionWhen to use it
Assistance physical serversDevelopment teams, self-hosted runners, predictable internal artifact traffic, and flat-rate economics
Customer cloud accountProduction build or pull paths that must stay inside your cloud/network/compliance boundary
Hybrid repository topologyCentral Artifactory service with controlled mirrors, caches, or promotion into cloud production registries
Migration engagementMove from Nexus, Harbor, GitLab, GitHub Packages, Docker Hub private repositories, cloud-native registries, file shares, or unmanaged Artifactory

Reliability and support model#

TopicManaged Artifactory approach
AvailabilityTarget availability scoped by deployment model, storage backend, replication needs, and support tier
DurabilityBackup/snapshot strategy and retention expectations defined during onboarding
Build continuityProxy caching reduces external outage impact but does not guarantee third-party package availability beyond cached artifacts
PerformancePull/push latency, storage, errors, and request volume monitored for covered repositories
GovernanceScanning, license, audit, and retention workflows included when selected
ResponseP1 response targets scoped in support agreement; 24/7 critical response available for covered production release paths

Onboarding#

1. Repository assessment#

We review current repositories, package ecosystems, image volume, pull patterns, CI/CD systems, Kubernetes clusters, access model, scanning expectations, and retention needs.

2. Managed design#

Assistance proposes repository topology, endpoint naming, storage, access model, scanning workflow, retention policies, backup approach, integrations, and support tier.

3. Migration and integration#

We provision Artifactory, create initial repositories, configure CI/CD credentials, provide package-manager and Kubernetes pull secret guidance, and support artifact migration or promotion setup.

4. Operate and govern#

After go-live, we monitor platform health, storage growth, scanning status, upstream cache behavior, and access patterns. Retention and permissions are reviewed on the agreed cadence.

Supported capabilities#

  • Maven, npm, PyPI, NuGet, Helm, generic, and other repository formats supported by the selected Artifactory edition
  • Docker and OCI image publishing through Artifactory Docker/OCI repositories
  • Hosted, remote, and virtual repository patterns
  • Role-based access control and service accounts
  • Vulnerability/license scanning workflow and reporting where included
  • Webhooks or CI/CD integrations where scoped
  • Retention and cleanup policies
  • Migration from common artifact and registry platforms

Not included by default#

  • Updating every project's dependencies or build files
  • Rebuilding or hardening every container image
  • Owning vulnerability remediation, license approval, or exception approval
  • Managing application deployment rollouts
  • Unlimited storage, retention, replication, or bandwidth outside the plan
  • Guaranteeing public internet CDN performance unless scoped with that architecture

Getting started#

Frequently asked questions#

Can we use this with Kubernetes? Yes. We provide image pull secret guidance, service account patterns, and Artifactory Docker/OCI repository access models for Kubernetes clusters.

Do you scan images and packages for vulnerabilities? Scanning workflows are available and can be included. Assistance operates the agreed scanning workflow; your team owns remediation and risk acceptance.

Can you migrate from an existing repository platform? Yes. We support migration planning from Nexus, Harbor, GitLab, GitHub Container Registry, Docker Hub, cloud-native registries, file shares, and existing Artifactory installations.

Who owns tag naming and release promotion? Your engineering/release team owns tag strategy and promotion rules. We implement the repository controls and can advise on safer workflows.

What SLA applies? Availability and response targets are scoped by deployment model, storage design, replication, and support tier.