Artifact Keeper
Open-Source Artifactory/Nexus Alternative in Rust
Details
- External ID
- 46909037
- Source
- HN
- Company
- —
- Product
- Keeper
- Website domain
- github.com
- Launched
- Feb. 6, 2026
- Cohort
- —
- Upvotes
- 166
- Upvotes percentile
- 0.9326145552560647
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
I'm a software engineer who keeps getting pulled into DevOps no matter how hard I try to escape it. I recently moved into a Lead DevOps Engineer role writing tooling to automate a lot of the pain away. On my own time outside of work, I built Artifact Keeper — a self-hosted artifact registry that supports 45+ package formats. Security scanning, SSO, replication, WASM plugins — it's all in the MIT-licensed release. No enterprise tier. No feature gates. No surprise invoices.Your package managers — pip, npm, docker, cargo, helm, go, all of them — talk directly to it using their native protocols. Security scanning with Trivy, Grype, and OpenSCAP is built in, with a policy engine that can quarantine bad artifacts before they hit your builds. And if you need a format it doesn't support yet, there's a WASM plugin system so you can add your own without forking the backend.Why I built it:Part of what pulled me into computers in the first place was open source. I grew up poor in New Orleans, and the only hardware I had access to in the early 2000s were some Compaq Pentium IIs my dad brought home after his work was tossing them out. I put Linux on them, and it ran circles around Windows 2000 and Millennium on that low-end hardware. That experience taught me that the best software is software that's open for everyone to see, use, and that actually runs well on whatever you've got.Fast forward to today, and I see the same pattern everywhere: GitLab, JFrog, Harbor, and others ship a limited "community" edition and then hide the features teams actually need behind some paywall. I get it — paychecks have to come from somewhere. But I wanted to prove that a fully-featured artifact registry could exist as genuinely open-source software. Every feature. No exceptions.The specific features came from real pain points. Artifactory's search is painfully slow — that's why I integrated Meilisearch. Security scanning that doesn't require a separate enterprise license was another big one. And I wanted replication that didn't need a central coordinator — so I built a peer mesh where any node can replicate to any other node. I haven't deployed this at work yet — right now I'm running it at home for my personal projects — but I'd love to see it tested at scale, and that's a big part of why I'm sharing it here.The AI story (I'm going to be honest about this):I built this in about three weeks using Claude Code. I know a lot of you will say this is probably vibe coding garbage — but if that's the case, it's an impressive pile of vibe coding garbage. Go look at the codebase. The backend is ~80% Rust with 429 unit tests, 33 PostgreSQL migrations, a layered architecture, and a full CI/CD pipeline with E2E tests, stress testing, and failure injection.AI didn't make the design decisions for me. I still had to design the WASM plugin system, figure out how the scanning engines complement each other, and architect the mesh replication. Years of domain knowledge drove the design — AI just let me build it way faster. I'm floored at what these tools make possible for a tinkerer and security nerd like me.Tech stack: Rust on Axum, PostgreSQL 16, Meilisearch, Trivy + Grype + OpenSCAP, Wasmtime WASM plugins (hot-reloadable), mesh replication with chunked transfers. Frontend is Next.js 15 plus native Swift (iOS/macOS) and Kotlin (Android) apps. OpenAPI 3.1 spec with auto-generated TypeScript and Rust SDKs.Try it: git clone https://github.com/artifact-keeper/artifact-keeper.git cd artifact-keeper docker compose up -d Then visit http://localhost:30080Live demo: https://demo.artifactkeeper.com Docs: https://artifactkeeper.com/docs/I'd love any feedback — what you think of the approach, what you'd want to see, what you hate about Artifactory or Nexus that you wish someone would just fix. It doesn't have to be a PR. Open an issue, start a discussion, or just tell me here.https://github.com/artifact-keeper
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Data infrastructure
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- rust artifactory alternative
- Manually corrected
- False
Could you build this?
Partial A basic self-hosted artifact storage UI can be vibe-coded, but implementing fully compliant wire protocols for multiple package managers (OCI, Maven, npm, PyPI, Cargo) is intensely intricate.
What it would actually take: The stack would typically use Rust (Axum/Actix-web) with object storage (S3/local disk) and SQLite/PostgreSQL for metadata. The difficult part is accurately reverse-engineering and reverse-implementing individual package registry API specifications (authentication flows, manifest schema validation, chunked uploads, checksum handling) for each ecosystem to ensure existing CLI package managers don't break.
Discussion
20 comments analyzed.
Competitors mentioned: Artifactory, Sonatype Nexus OSS, JFrog, AWS ECR, Artipie
Concerns raised: Lacks encryption for stored artifacts, Security aspects scalability with large artifact counts (17M+ artifacts), Inaccurate project description (40+ formats claim vs actual 35), Uncertainty about true open-source commitment, Lack of community adoption
Feature requests: S3 bucket storage with encryption and authentication, Hybrid migration mode to run alongside Artifactory during evaluation, Autoscaling support via EC2/ECS/EKS, CLI/TUI interface, Malware scan integration (Packj or similar)
Competitors
Other products that read as similar to this one — 219 launches clear the similarity bar, closest 8 shown.
Attention rank: #25 of 220 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 99 days after the earliest competitor.
- Sighthound · hn · 2026-07-09 · 19 upvotes · similarity 0.50
- Open-source Markdown research tool written in Rust · hn · 2025-12-16 · 34 upvotes · similarity 0.47
- KeyEnv · hn · 2026-01-18 · 5 upvotes · similarity 0.45
- Nucleus · hn · 2026-06-09 · 40 upvotes · similarity 0.44
- VM-curator · hn · 2026-01-25 · 42 upvotes · similarity 0.43
- Shrouded, secure memory management in Rust · hn · 2026-03-23 · 5 upvotes · similarity 0.43
- OpenKnowledge · hn · 2026-06-25 · 381 upvotes · similarity 0.43
- Gitdot · hn · 2026-06-08 · 334 upvotes · similarity 0.43
Other launches for this product
Same idea, different domain
Nobody's really built a data infrastructure tool for Media & entertainment yet.