The boring but important part
Service policy
What this mirror promises, what it refuses to promise, and who is behind it.
Who runs this
AssetFlux is a small independent mirror operated by a handful of build engineers who got tired of watching CI fleets pull the same tarball a thousand times a day from the other side of the planet. It is funded out of pocket and by a few companies who pay us to keep a shelf warm for their pipelines. There is no company behind it beyond that, no funding round, and no plan to become a platform.
We are not upstream. AssetFlux is not affiliated with, endorsed by, or speaking for any project whose artifacts appear here. We did not write this software, we do not maintain it, and we cannot answer questions about how to use it. We copy published files and hand them back faster. That is the whole service.
What we promise
- Byte fidelity
- Artifacts are copies. If a digest here does not match the one upstream published, we have a bug and you should not trust the file.
- Permanence
- Once mirrored, an artifact stays. Unpublishing upstream does not remove our copy. This is the point of the whole exercise.
- No accounts
- Read access is open and anonymous. There is nothing to sign up for and no token that unlocks anything.
- No tracking
- No analytics, no third-party resources, no cookies. These pages load one stylesheet and one icon, both from this host.
What we refuse to promise
- Uptime. There is no SLA. We publish real numbers on the edge map and they are good, but they are a record, not a commitment.
- Completeness. The fetcher can miss a release. If a version exists upstream and not here, that is a gap, not a statement about the version.
- Being your only source. Configure a fallback to the upstream registry. Any team whose builds cannot survive this host going away has taken on a risk we did not offer to carry.
- Forever. If this becomes unaffordable we will say so, keep it read-only for as long as the storage bill allows, and publish the shelf as a downloadable set before anything is switched off.
Logs and what we keep
Edge sites log request path, response code, byte count, coarse region and a truncated client address, for seven days, for capacity planning and abuse handling. They are not joined to anything, not sold, and not shared except where a court in the hosting jurisdiction compels it. Aggregate counters — the ones on these pages — are kept indefinitely because they are just numbers.
Fair use
No hard rate limit is published because the honest answer is that almost nobody hits one. A single address pulling the same immutable artifact thousands of times per hour is not using a mirror, it is missing a cache, and we will throttle it and try to work out who to tell. If you need to warm a large fleet, pull once into your own proxy and serve from there — that is strictly better for both of us.
Takedowns and corrections
Publishers who want their artifacts removed, and anyone reporting a digest mismatch, a missing release or a security problem, should write to ops@assetflux.org. Include the shelf name and the exact path. We answer within two working days and we do not argue with a publisher about their own artifacts.
Mirrors earn trust by being dull, predictable and honest about their limits. We would rather be the least exciting dependency in your pipeline.
Changes to this page
Last revised 2026-09-18. Material changes are noted here with a date rather than announced; there is no mailing list to join.