Run PaGetto on AWS
On Amazon Web Services, store package metadata in Amazon RDS and packages in Amazon S3 (or any other S3-compatible service). Run PaGetto itself wherever containers run: Amazon ECS, Amazon EKS with the Helm chart, or an EC2 instance with Docker or the release zip.
Configure PaGetto​
Set these values in appsettings.json or as environment variables (Storage__Type, Database__ConnectionString, …). For the full list of settings, see Configuration.
Amazon S3​
Create a bucket and give PaGetto access to it. Set Region to the bucket's region:
{
...
"Storage": {
"Type": "AwsS3",
"Region": "eu-west-1",
"Bucket": "my-nuget-packages",
"Prefix": "pagetto" // optional
},
...
}
Prefix is optional. When set, every object is stored under that key prefix, so several applications can share a bucket.
Credentials​
PaGetto needs read, write and delete access to the objects in the bucket (s3:GetObject, s3:PutObject, s3:DeleteObject and s3:ListBucket). Pick one way to provide credentials:
- IAM role (recommended)
- Assume a role
- Access key
Leave out all credential settings. The AWS SDK then uses its default credential chain: environment variables, the shared credentials file, an ECS task role, an EKS service account (IRSA or Pod Identity) or an EC2 instance profile.
To use that chain explicitly, set UseInstanceProfile:
{
"Storage": {
"Type": "AwsS3",
"Region": "eu-west-1",
"Bucket": "my-nuget-packages",
"UseInstanceProfile": true
}
}
To access a bucket through another role, for example in another account, set AssumeRoleArn. PaGetto uses the default credential chain to assume that role:
{
"Storage": {
"Type": "AwsS3",
"Region": "eu-west-1",
"Bucket": "my-nuget-packages",
"AssumeRoleArn": "arn:aws:iam::123456789012:role/pagetto-storage"
}
}
Create an IAM user with access to the bucket and an access key for it. AccessKey and SecretKey must be set together:
{
"Storage": {
"Type": "AwsS3",
"Region": "eu-west-1",
"Bucket": "my-nuget-packages",
"AccessKey": "",
"SecretKey": ""
}
}
Keep the secret key out of appsettings.json: use an environment variable or a secret file.
S3-compatible object storage​
You can use any storage service that is compatible with Amazon S3. Set Endpoint to the service URL instead of Region:
{
...
"Storage": {
"Type": "AwsS3",
"Endpoint": "https://eu-central-1.linodeobjects.com",
"Bucket": "nuget-packages",
"AccessKey": "",
"SecretKey": ""
},
...
}
Set only one of Region and Endpoint. PaGetto fails at startup if both are set.
Path-style addressing​
By default the AWS SDK uses virtual-hosted-style URLs, where the bucket is part of the host name (https://nuget-packages.example.com/...). Some S3-compatible services, such as a local MinIO server, only support path-style URLs, where the bucket is part of the path (http://localhost:9000/nuget-packages/...). Set ForcePathStyle to true to use path-style addressing. It defaults to false and only applies when Endpoint is set.
For example, for a local MinIO server:
{
...
"Storage": {
"Type": "AwsS3",
"Endpoint": "http://localhost:9000",
"ForcePathStyle": true,
"Bucket": "nuget-packages",
"AccessKey": "minioadmin",
"SecretKey": "minioadmin"
},
...
}
Or with environment variables:
Storage__Type=AwsS3
Storage__Endpoint=http://localhost:9000
Storage__ForcePathStyle=true
Storage__Bucket=nuget-packages
Storage__AccessKey=minioadmin
Storage__SecretKey=minioadmin
Known compatible services​
So far, PaGetto has been tested with Linode's Object Storage, and MinIO has been reported to work with ForcePathStyle. If you use PaGetto with another service, let us know so we can list it here.
Amazon RDS​
Create a database for PaGetto. PaGetto creates and updates its tables on startup, so the database user needs permission to change the schema. For more on connection strings, see Database configuration.
- Amazon RDS for PostgreSQL
- Amazon RDS for MySQL
- Amazon RDS for SQL Server
To use PostgreSQL, set:
{
...
"Database": {
"Type": "PostgreSql",
"ConnectionString": "Host=my-db.xxxxxxxx.eu-west-1.rds.amazonaws.com;Database=pagetto;Username=pagetto;Password=..."
},
...
}
To use MySQL, create the database with the utf8mb4 character set and set:
{
...
"Database": {
"Type": "MySql",
"ConnectionString": "Server=my-db.xxxxxxxx.eu-west-1.rds.amazonaws.com;Database=pagetto;User Id=pagetto;Password=..."
},
...
}
To use SQL Server, set:
{
...
"Database": {
"Type": "SqlServer",
"ConnectionString": "Server=my-db.xxxxxxxx.eu-west-1.rds.amazonaws.com;Database=pagetto;User Id=pagetto;Password=...;Encrypt=True"
},
...
}
Run several instances​
With the database on RDS and packages on S3, you can run more than one PaGetto instance behind a load balancer. Data Protection keys are stored in the bucket as well, so sign-in cookies work on every instance. Configure the load balancer's health check to use /health, see Health endpoint.
Publish packages​
Replace your-server with the address of your PaGetto server.
dotnet nuget push -s https://your-server/v3/index.json -k <api-key> package.1.0.0.nupkg
Publish a symbol package the same way:
dotnet nuget push -s https://your-server/v3/index.json -k <api-key> symbol.package.1.0.0.snupkg
Secure your server by requiring an API key to publish packages. See Require an API key, or set up user accounts.
Restore packages​
Use the following package source:
https://your-server/v3/index.json
Other feeds are at https://your-server/feeds/{slug}/v3/index.json. Some helpful guides:
Symbol server​
Use the following symbol location:
https://your-server/api/download/symbols
For Visual Studio, see Configure symbol locations.