Run PaGetto on Azure
On Azure, store package metadata in Azure SQL Database (or Azure Database for PostgreSQL or MySQL) and packages in Azure Blob Storage. Run PaGetto itself on Azure App Service, Azure Container Apps, or AKS with the Helm chart.
Configure PaGetto​
Set these values in appsettings.json or as environment variables (Storage__Type, Database__ConnectionString, …). For the full list of settings, see Configuration.
Database​
Use any SQL database that PaGetto supports: Azure SQL Database (SqlServer), Azure Database for PostgreSQL (PostgreSql) or Azure Database for MySQL (MySql). PaGetto creates and updates its tables on startup. Set the database type and a connection string:
{
...
"Database": {
"Type": "SqlServer",
"ConnectionString": "..."
},
...
}
To connect to Azure SQL Database with a managed identity instead of a username and password, add Authentication=Active Directory Default to the connection string:
{
...
"Database": {
"Type": "SqlServer",
"ConnectionString": "Server=tcp:<server>.database.windows.net,1433;Initial Catalog=<database>;Authentication=Active Directory Default;Encrypt=True;Connection Timeout=30;"
},
...
}
The managed identity must be added as a user in the database before PaGetto can connect. db_ddladmin lets PaGetto run its migrations on startup:
CREATE USER [<identity-name>] FROM EXTERNAL PROVIDER;
ALTER ROLE db_datareader ADD MEMBER [<identity-name>];
ALTER ROLE db_datawriter ADD MEMBER [<identity-name>];
ALTER ROLE db_ddladmin ADD MEMBER [<identity-name>];
PaGetto doesn't support Azure Table Storage as a database (Database:Type = AzureTable), because it can't store feeds, user accounts or permissions. PaGetto refuses to start with it. Use one of the SQL databases above.
Azure Blob Storage​
Create a storage account and a container. Set the storage type to AzureBlobStorage, the container name and credentials:
- Managed identity (recommended)
- Connection string
- Access key
Set ConnectionString to the blob service endpoint and enable UseAzureDefaultCredential. PaGetto then authenticates with DefaultAzureCredential, which uses the managed identity of the App Service, Container App or AKS workload.
{
...
"Storage": {
"Type": "AzureBlobStorage",
"Container": "my-container",
"ConnectionString": "https://<account>.blob.core.windows.net",
"UseAzureDefaultCredential": true
},
...
}
The managed identity must be granted the Storage Blob Data Contributor role on the storage account (or the container) before PaGetto can read or write packages.
{
...
"Storage": {
"Type": "AzureBlobStorage",
"Container": "my-container",
"ConnectionString": "AccountName=my-account;AccountKey=abcd1234;..."
},
...
}
{
...
"Storage": {
"Type": "AzureBlobStorage",
"Container": "my-container",
"AccountName": "my-account",
"AccessKey": "abcd1234"
},
...
}
Keep connection strings and keys out of appsettings.json: use App Service settings, Key Vault references, environment variables or a secret file.
Search​
PaGetto searches the packages in its database (Search:Type = Database, the default). Azure AI Search (AzureSearch) isn't available yet.
Sign-in with Microsoft Entra ID​
To let users sign in with their Entra ID accounts and manage permissions with app roles, see Azure Entra ID setup. To send PAT expiry emails through Microsoft 365, see Microsoft Graph email.
Azure App Service​
Run the letreset/pagetto image on a Linux App Service:
-
Create a Web App with Publish: Container and Operating system: Linux, and choose the
letreset/pagettoimage from Docker Hub. Pin a version tag, see image tags. -
The container listens on port 8080. Add the app setting
WEBSITES_PORT=8080. -
Turn on the app's system-assigned managed identity and grant it access to the database and the storage account as described above.
-
Add the PaGetto settings as App settings, using
__for nested keys:Name Value Database__TypeSqlServerDatabase__ConnectionStringServer=tcp:<server>.database.windows.net,1433;Initial Catalog=<database>;Authentication=Active Directory Default;Encrypt=True;Storage__TypeAzureBlobStorageStorage__Containermy-containerStorage__ConnectionStringhttps://<account>.blob.core.windows.netStorage__UseAzureDefaultCredentialtrueAuthentication__ModeLocal(user accounts, see Authentication), orLegacywith an API keyAuthentication__ApiKeys__0__KeyLegacymode only: a long random value -
Set Health check to
/health, see Health endpoint.
App Service terminates TLS in front of the container and passes the original scheme and client address in X-Forwarded-* headers, which PaGetto reads.
Run several instances​
With the database and packages in Azure, you can scale out to more than one instance. Data Protection keys are stored in the blob container as well, so sign-in cookies work on every instance and you don't need session affinity.
Publish packages​
Replace your-server with the address of your PaGetto server, for example pagetto.azurewebsites.net.
dotnet nuget push -s https://your-server/v3/index.json -k <api-key> package.1.0.0.nupkg
Publish a symbol package the same way:
dotnet nuget push -s https://your-server/v3/index.json -k <api-key> symbol.package.1.0.0.snupkg
Secure your server by requiring an API key to publish packages. See Require an API key, or set up user accounts.
Restore packages​
Use the following package source:
https://your-server/v3/index.json
Other feeds are at https://your-server/feeds/{slug}/v3/index.json. Some helpful guides:
Symbol server​
Use the following symbol location:
https://your-server/api/download/symbols
For Visual Studio, see Configure symbol locations.