- Artifact Procurement: Pull artifacts from diverse sources including OCI registries, Helm repositories, S3-compatible storage, and HTTP endpoints
- Security Validation: Perform malware scanning, CVE analysis, license verification, and signature validation before artifact transfer
- Policy Enforcement: Ensure only artifacts meeting defined security and compliance policies cross security boundaries
- Declarative Management: Leverage Kubernetes-native declarative configuration for artifact lifecycle management
- Auditability: Provide attestation and traceability of all artifact processing operations
Out of Scope: ARC does not replace existing registry solutions or artifact repositories. It functions as an orchestration layer that coordinates artifact transfer and validation between existing infrastructure components.
For detailed information have a look at /docs or the live documentation on ARC Docs.
⚠️ Before contributing, make sure you read the contribution guidelines
Please see our documentation in the /docs folder for more details.
The hosted version of the documentation can be found at https://arc.opendefense.cloud/.
We'd love to get feedback from you. Please report bugs, suggestions or post questions by opening an issue.