GitLab Artifact Central
Organization-level artifact management from GitLab for hosting, proxying, and governing packages and container images.
About GitLab Artifact Central
GitLab Artifact Central is a beta artifact management service from GitLab. It gives platform teams one governed home for the packages and container images that teams and agents publish and pull. Access is by beta request, rolling out to GitLab.com customers first.
What It Is
Artifact Central is an artifact registry that works at the organization level. Retention, quota, and access are set once for the organization instead of once per project. The docs describe repositories that each serve one package format: Docker, Maven, npm, or OCI.
How Repositories Work
The documentation describes three repository types:
- Hosted repositories store artifacts you publish, such as packages produced by CI/CD pipelines.
- Remote repositories proxy and cache one external registry. Documented public upstreams are npmjs.com, Maven Central, and Docker Hub.
- Virtual repositories combine several repositories behind a single URL. The registry walks an ordered upstream list, which can hold up to 20 upstreams, until it finds the requested package.
Cache validity is configurable, and scheduled health checks mark unhealthy remotes. Upstream credentials are write-only. Repositories can be managed through the UI, a GraphQL API, and a management API.
Migration and Traceability
GitLab describes a gradual migration path. Existing registries are added as remotes behind a virtual repo, and artifacts move over only when a build requests one. The old registry remains the system of record until the remote is converted to hosted. GitLab also states that each artifact carries build provenance, including pipeline, branch, commit, and the user who triggered the job. Publishing and pulling use the same CI/CD identity that pipelines already use.
Current Status
Artifact Central is in beta. During beta, repositories are private by default, and organization members need an assigned artifact registry role to view the registry. The docs list the Premium and Ultimate tiers on GitLab.com. Virtual repositories are still in development, and you cannot publish to them. Deleting a repository permanently removes its artifacts. Self-Managed use requires GitLab 19.5 or later and Cloud Native GitLab. GitLab says it is working with a small group of Self-Managed design partners.
Community Discussions
Be the first to start a conversation about GitLab Artifact Central
Share your experience with GitLab Artifact Central, ask questions, or help others learn from your insights.
Pricing
Contact for pricing details
Capabilities
Key Features
- Organization-level retention, quota, and access policy
- Hosted repositories for publishing packages and images
- Remote repositories that proxy and cache npmjs.com, Maven Central, and Docker Hub
- Virtual repositories that front multiple upstreams behind one URL
- Build provenance on every artifact
- Configurable cache validity and upstream health checks
- GraphQL and management APIs
- Gradual migration from existing registries
- Support for Docker, Maven, npm, and OCI formats
