| 1 | --- |
| 2 | title: Packages |
| 3 | description: Publish and install packages beside your code, with the same people, roles and tokens. |
| 4 | --- |
| 5 | |
| 6 | A workspace can publish packages to g1t and install them from it, beside |
| 7 | the code they are built from: container images, npm packages, Composer |
| 8 | packages and Go modules, with Cargo to follow. Each registry speaks its |
| 9 | tool's own protocol, so `docker`, `npm`, `composer` and `go` work with |
| 10 | nothing but a login and an address. Composer packages and Go modules are |
| 11 | read from the workspace's repositories: there is nothing to upload. |
| 12 | |
| 13 | | Registry | Address | Guide | |
| 14 | | --- | --- | --- | |
| 15 | | Container images | `g1t.sh/<workspace>/<name>` | [Container images](/guides/containers/) | |
| 16 | | npm | `https://g1t.sh/-/npm/`, for the scope `@<workspace>` | [npm](/guides/npm/) | |
| 17 | | Composer | `https://g1t.sh/-/composer/<workspace>/`, from the workspace's repositories | [Composer](/guides/composer/) | |
| 18 | | Go | `g1t.sh/<workspace>/<repo>`, straight from git | [Go modules](/guides/go/) | |
| 19 | |
| 20 | ## Names |
| 21 | |
| 22 | Every package's name starts with its workspace: `g1t.sh/acme/web` is the |
| 23 | `web` image of the `acme` workspace. A name may have more parts after it, |
| 24 | such as `g1t.sh/acme/web/worker`. |
| 25 | |
| 26 | ## Who can see and publish a package |
| 27 | |
| 28 | A package is linked to a repository, or belongs to its workspace. |
| 29 | |
| 30 | - **Linked.** The first push of an image whose name starts with a |
| 31 | repository's name (`acme/web`, `acme/web/worker` for the repository |
| 32 | `acme/web`) links it to that repository; so does the first publish of |
| 33 | an npm package whose `package.json` `repository` is a g1t.sh repository |
| 34 | of the workspace, or which is named like one (`@acme/web`). It then has |
| 35 | the repository's visibility and [roles](/guides/access-and-roles/): |
| 36 | |
| 37 | | | Needs | |
| 38 | | --- | --- | |
| 39 | | Pull | Read: on a public repository, anyone, signed in or not | |
| 40 | | Push a new version or tag | Write | |
| 41 | | Delete versions and the package, change its settings | Admin | |
| 42 | |
| 43 | - **Unlinked.** A package whose name matches no repository is the |
| 44 | workspace's. It is private: members pull and push it by the workspace's |
| 45 | [base permission](/guides/access-and-roles/#the-base-permission) (Read pulls, |
| 46 | Write pushes), and only owners delete it or change its settings. An owner |
| 47 | can make it public, and then anyone can pull it. |
| 48 | |
| 49 | A linked package can be unlinked, and an unlinked one linked to a |
| 50 | repository of its workspace by someone with Admin on that repository. |
| 51 | |
| 52 | Private packages look exactly like ones that do not exist to anyone who may |
| 53 | not pull them. |
| 54 | |
| 55 | ## Tokens |
| 56 | |
| 57 | Sign in to a registry with your username and an |
| 58 | [access token](/guides/authentication/#access-tokens) as the password. |
| 59 | A token with scopes needs the package ones: |
| 60 | |
| 61 | | Scope | Lets a token | |
| 62 | | --- | --- | |
| 63 | | `packages:read` | Pull private packages. Public ones need no scope. | |
| 64 | | `packages:write` | Push and publish. Includes `packages:read`. | |
| 65 | | `packages:delete` | Delete versions and packages | |
| 66 | |
| 67 | Tokens with full access, and tokens made before scopes, have all three. A |
| 68 | token never does more than its owner could: `packages:delete` alone does not |
| 69 | let a member delete an owner's package. |
| 70 | |
| 71 | In [workflows](/guides/actions/#secrets-and-variables), `G1T_TOKEN` is the |
| 72 | workspace's own token for the run: it pushes and pulls the workspace's |
| 73 | packages with no setup. A g1t agent at work on a repository may push the |
| 74 | packages of that repository, as it may push its code, and never deletes |
| 75 | them. |
| 76 | |
| 77 | ## Storage |
| 78 | |
| 79 | Every file is kept once, by its content: two images that share a layer |
| 80 | store it once, and a layer pushed again is not stored again. A workspace's |
| 81 | storage counts each file once, as public when any public package uses it. |
| 82 | |
| 83 | Files no version uses any more are deleted a day after the last version |
| 84 | that used them goes. |
| 85 | |
| 86 | Without the [g1t plan](/guides/usage-and-billing/#the-g1t-plan), public |
| 87 | packages may hold 10 GB and private ones 500 MB per workspace; a push past |
| 88 | either is refused, with a message saying how much is used. On the plan, |
| 89 | storage past those amounts is charged instead. See |
| 90 | [storage and pull limits](/guides/containers/#storage-and-pull-limits). |
| 91 | |
| 92 | ## Events and the audit log |
| 93 | |
| 94 | Publishing a version, deleting a version and deleting a package are |
| 95 | [audit log](/guides/audit-log/) entries, and the events |
| 96 | `package.published`, `package.version_deleted`, `package.deleted` and |
| 97 | `package.visibility_changed`, which [webhooks](/guides/webhooks/) can be |
| 98 | sent: a linked package's go to its repository's webhooks and its |
| 99 | workspace's, an unlinked package's to its workspace's webhooks. |