Skip to main content

Universal Artifact Registry (Artifact Keeper)

Artifact Keeper is Okustera's sovereign, unified package and container registry.

It supports OCI container images, Helm charts, Python wheels (PyPI), npm packages, and Maven binaries within private, access-controlled tenant namespaces.


Supported Package Formats​

FormatProtocol / ToolExample Usage
OCI ContainersDocker, Podman, Skopeodocker push artifacts.okustera.com/tenant-prod/api:v1.0.0
Helm ChartsHelm 3 OCIhelm push my-chart-1.0.0.tgz oci://artifacts.okustera.com/tenant-prod/charts
Python (PyPI)Twine, pippip install --index-url https://artifacts.okustera.com/repository/pypi/ my-pkg
JavaScript (npm)npm, yarn, pnpmnpm publish --registry=https://artifacts.okustera.com/repository/npm/
OCI Model Packages & LoRAsORAS, ModelKit, Hugging Faceoras push artifacts.okustera.com/tenant-prod/models/llama-lora:v1 ./adapter

Pushing Container Images​

# 1. Authenticate with Okustera registry
docker login artifacts.okustera.com -u $OKUSTERA_USERNAME -p $OKUSTERA_API_TOKEN

# 2. Tag local image
docker tag my-app:latest artifacts.okustera.com/my-project/my-app:1.0.0

# 3. Push to registry
docker push artifacts.okustera.com/my-project/my-app:1.0.0

Automated Vulnerability Scanning​

Every image pushed to Artifact Keeper is automatically scanned using Trivy for known CVEs, outdated packages, and misconfigured secrets. Deployment admission controllers can be configured to block containers containing critical CVEs from starting in production clusters.


AI Model & LoRA Artifacts (Phase 8 Model Foundry Integration)​

Fine-tuned models, tokenizer configurations, and domain-specific LoRA adapters can be packaged as OCI Artifacts and hosted in private tenant namespaces:

# Package and push LoRA adapter using ORAS
oras push artifacts.okustera.com/tenant-prod/models/llama-legal-lora:v1.2 \
./adapter_config.json:application/vnd.okustera.ai.config.v1+json \
./adapter_model.safetensors:application/vnd.okustera.ai.weights.v1+safetensors

The Okustera Model Foundry automatically synchronizes these OCI artifacts into runtime vLLM instances for dynamic, on-the-fly adapter hot-swapping.