Project reference ↗

JavaScript teams may need to publish private packages and keep a local source for dependencies fetched from public registries. Verdaccio provides an npm-compatible registry that can store private publications and proxy upstream packages. It offers a focused service for package distribution without requiring a large repository platform. Private package files may be irreplaceable even when cached public dependencies are not, so storage, access rules and backups should distinguish those roles and preserve the URLs used by existing builds.

Current guidance

Current documentation recommends the project’s own Helm chart and distinguishes stable, next and experimental application tracks in its examples. Review the image tag explicitly rather than assuming a runnable example selects the stable release you intend to operate.

Verdaccio can proxy upstream packages and store private publications. Those are different durability requirements: a cache may be reproducible while an unpublished private tarball is not. Define persistent storage, backup, authentication plugins, package access rules and trusted uplinks. Prevent private package names from being resolved unexpectedly through public registries by reviewing scope and proxy configuration.

For migration, back up package data, configuration and required authentication/signing material, then test publishing and installing representative scoped packages with clean client caches. Check lock-file registry URLs, token behavior, metadata and tarball checksums. Multiple pods sharing storage are not automatically a safe high-availability design; verify the chosen storage plugin and release’s concurrency model. Keep the previous registry readable until builds can resolve their pinned dependencies without relying on developer caches.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2018-09-20T10:23:02+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Verdaccio is a simple, zero-config-required local private npm registry. No need for an entire database just to get started! Verdaccio comes out of the box with its own tiny database, and the ability to proxy other registries (eg. npmjs.org), caching the downloaded modules along the way. For those looking to extend their storage capabilities, Verdaccio supports various community-made plugins to hook into services such as Amazon’s s3 and Google Cloud Storage.

Prerequisites

  • Kubernetes 1.7+ with Beta APIs enabled
  • PV provisioner support in the underlying infrastructure

Use private packages

If you want to use all benefits of npm package system in your company without sending all code to the public, and use your private packages just as easy as public ones.

Cache npmjs.org registry

If you have more than one server you want to install packages on, you might want to use this to decrease latency (presumably “slow” npmjs.org will be connected to only once per package/version) and provide limited failover (if npmjs.org is down, we might still find something useful in the cache) or avoid issues like How one developer just broke Node, Babel and thousands of projects in 11 lines of JavaScript, Many packages suddenly disappeared or Registry returns 404 for a package I have installed before.

Link multiple registries

If you use multiples registries in your organization and need to fetch packages from multiple sources in one single project you might take advance of the uplinks to feature with Verdaccio, chaining multiple registries and fetching from one single endpoint.

Override public packages

If you want to use a modified version of some 3rd-party package (for example, you found a bug, but maintainer didn’t accept pull request yet), you can publish your version locally under the same name.

See in detail each of these use cases.

Compatibility

Verdaccio aims to support all features of a standard npm client that make sense to support in private repository. Unfortunately, it isn’t always possible.

Basic features

  • Installing packages (npm install, npm upgrade, etc.) – supported
  • Publishing packages (npm publish) – supported

Advanced package control

  • Unpublishing packages (npm unpublish) – supported
  • Tagging (npm tag) – supported
  • Deprecation (npm deprecate) – not supported – PR-welcome

User management

  • Registering new users (npm adduser {newuser}) – supported
  • Transferring ownership (npm owner add {user} {pkg}) – not supported, PR-welcome

Misc stuff

  • Searching (npm search) – supported (cli / browser)
  • Ping (npm ping) – supported
  • Starring (npm star, npm unstar) – not supported, PR-welcome

Security

  • npm audit – supported

Verdaccio has evolved since the fork in 2016. Thanks of the community the project is still running and improving in several ways, a new UI, the product more stable and reliable, but still, there is a lot to do and I encourage you to contribute and make this amazing project stronger and popular.

There are other options outside for npm proxy servers, but, verdaccio wants to be a fast and portable npm private registry free solution for the community.

The post Verdaccio appeared first on kubedex.com.

Sources & further reading

  1. Verdaccio official chart and release-track guidance
  2. Recovered historical source

Spotted something that needs another look?

Help improve this page →