g1t/apps/docs/src/content/docs/guides/packages.md

99 lines4,491 bytesCodeBlame
1---
2title: Packages
3description: Publish and install packages beside your code, with the same people, roles and tokens.
4---
5
6A workspace can publish packages to g1t and install them from it, beside
7the code they are built from: container images, npm packages, Composer
8packages and Go modules, with Cargo to follow. Each registry speaks its
9tool's own protocol, so `docker`, `npm`, `composer` and `go` work with
10nothing but a login and an address. Composer packages and Go modules are
11read from the workspace's repositories: there is nothing to upload.
12
13| Registry | Address | Guide |
14| --- | --- | --- |
15| Container images | `g1t.sh/<workspace>/<name>` | [Container images](/guides/containers/) |
16| npm | `https://g1t.sh/-/npm/`, for the scope `@<workspace>` | [npm](/guides/npm/) |
17| Composer | `https://g1t.sh/-/composer/<workspace>/`, from the workspace's repositories | [Composer](/guides/composer/) |
18| Go | `g1t.sh/<workspace>/<repo>`, straight from git | [Go modules](/guides/go/) |
19
20## Names
21
22Every package's name starts with its workspace: `g1t.sh/acme/web` is the
23`web` image of the `acme` workspace. A name may have more parts after it,
24such as `g1t.sh/acme/web/worker`.
25
26## Who can see and publish a package
27
28A package is linked to a repository, or belongs to its workspace.
29
30- **Linked.** The first push of an image whose name starts with a
31 repository's name (`acme/web`, `acme/web/worker` for the repository
32 `acme/web`) links it to that repository; so does the first publish of
33 an npm package whose `package.json` `repository` is a g1t.sh repository
34 of the workspace, or which is named like one (`@acme/web`). It then has
35 the repository's visibility and [roles](/guides/access-and-roles/):
36
37 | | Needs |
38 | --- | --- |
39 | Pull | Read: on a public repository, anyone, signed in or not |
40 | Push a new version or tag | Write |
41 | Delete versions and the package, change its settings | Admin |
42
43- **Unlinked.** A package whose name matches no repository is the
44 workspace's. It is private: members pull and push it by the workspace's
45 [base permission](/guides/access-and-roles/#the-base-permission) (Read pulls,
46 Write pushes), and only owners delete it or change its settings. An owner
47 can make it public, and then anyone can pull it.
48
49A linked package can be unlinked, and an unlinked one linked to a
50repository of its workspace by someone with Admin on that repository.
51
52Private packages look exactly like ones that do not exist to anyone who may
53not pull them.
54
55## Tokens
56
57Sign in to a registry with your username and an
58[access token](/guides/authentication/#access-tokens) as the password.
59A token with scopes needs the package ones:
60
61| Scope | Lets a token |
62| --- | --- |
63| `packages:read` | Pull private packages. Public ones need no scope. |
64| `packages:write` | Push and publish. Includes `packages:read`. |
65| `packages:delete` | Delete versions and packages |
66
67Tokens with full access, and tokens made before scopes, have all three. A
68token never does more than its owner could: `packages:delete` alone does not
69let a member delete an owner's package.
70
71In [workflows](/guides/actions/#secrets-and-variables), `G1T_TOKEN` is the
72workspace's own token for the run: it pushes and pulls the workspace's
73packages with no setup. A g1t agent at work on a repository may push the
74packages of that repository, as it may push its code, and never deletes
75them.
76
77## Storage
78
79Every file is kept once, by its content: two images that share a layer
80store it once, and a layer pushed again is not stored again. A workspace's
81storage counts each file once, as public when any public package uses it.
82
83Files no version uses any more are deleted a day after the last version
84that used them goes.
85
86Without the [g1t plan](/guides/usage-and-billing/#the-g1t-plan), public
87packages may hold 10 GB and private ones 500 MB per workspace; a push past
88either is refused, with a message saying how much is used. On the plan,
89storage past those amounts is charged instead. See
90[storage and pull limits](/guides/containers/#storage-and-pull-limits).
91
92## Events and the audit log
93
94Publishing a version, deleting a version and deleting a package are
95[audit log](/guides/audit-log/) entries, and the events
96`package.published`, `package.version_deleted`, `package.deleted` and
97`package.visibility_changed`, which [webhooks](/guides/webhooks/) can be
98sent: a linked package's go to its repository's webhooks and its
99workspace's, an unlinked package's to its workspace's webhooks.