Back to articles
Technology Insight

Building a Self-Hosted Private Package Registry for Enterprises: NPM, PyPI, and Composer via Verdaccio and Nexus on VPS

June 3, 2026

Introduction: The Case for a Private Package Registry

In modern enterprise software development, proprietary source code is one of an organization's most valuable intellectual property assets. While open-source ecosystems like NPM (Node.js), PyPI (Python), and Composer (PHP/Packagist) offer an incredible wealth of shared libraries, relying solely on public repositories poses significant challenges for enterprise-grade projects. Sharing internal proprietary code across team boundaries often leads organizations into a dilemma: publish to public registries risking IP exposure, or manage cumbersome git submodules that break semantic versioning.

Furthermore, recent supply chain attacks, such as dependency confusion and malicious package injections, have forced engineering leaders to rethink security compliance. A self-hosted Private Package Registry solves these challenges by providing a secure, centralized, and controlled environment inside your organization's perimeter. In this comprehensive guide, we will explore how to architect and deploy a robust private registry infrastructure using two industry-standard open-source tools: Verdaccio and Sonatype Nexus Repository Manager, hosted on a cost-effective Virtual Private Server (VPS).

---

Why Move Away From Public Registries?

Before diving into the technical implementation, it is vital to understand the business and technical catalysts for self-hosting:

  • Intellectual Property Protection: Organizations frequently develop internal utility libraries, core business logic modules, and microservice clients that must never be exposed to the public internet.
  • Dependency Control and Caching: Public registry outages can halt your entire Continuous Integration and Continuous Deployment (CI/CD) pipeline. A local registry acts as a caching proxy, ensuring high availability and faster build times.
  • Security and Compliance: By routing all third-party package downloads through an internal proxy, security teams can audit, filter, and block vulnerable packages before they ever reach a developer's machine.
---

Architecting the Solution: Verdaccio vs. Sonatype Nexus

To support a multi-language tech stack (JavaScript, Python, PHP), we must choose tools that balance ease of deployment with enterprise-grade features. We will utilize a hybrid architectural approach:

1. Verdaccio: The Lightweight Champion for Node.js

Verdaccio is a lightweight, zero-configuration-required private NPM registry written in Node.js. It is highly efficient, consumes minimal system resources, and perfectly mirrors the NPM registry API. We will use Verdaccio specifically to handle the JavaScript/TypeScript ecosystem.

2. Sonatype Nexus Repository Manager: The Enterprise Backbone

Sonatype Nexus is an industrial-strength repository manager that supports a vast array of package formats. It will serve as our primary engine for hosting PyPI wheels and Composer packages, while also offering advanced user access control (RBAC) and storage management suitable for scaled operations.

---

Prerequisites and Server Preparation

To ensure optimal performance and security, your target VPS should meet the following minimum specifications:

  • OS: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS
  • CPU: 2 vCPUs (Minimum), 4 vCPUs (Recommended)
  • RAM: 4GB RAM minimum (Nexus requires at least 2.7GB of dedicated heap memory)
  • Storage: 40GB+ SSD/NVMe (Scalable based on package volume)
  • Network: Static IPv4 address with a domain name pointed to it (e.g., registry.yourcompany.com)
Security Note: Always ensure your firewall (UFW) blocks public access to internal ports. We will use Nginx as a reverse proxy to safely expose our services over HTTPS via Let's Encrypt certificates.
---

Step-by-Step Implementation Guide

Step 1: Setting Up the Base Environment

First, update your system packages and install Docker and Docker Compose, which will drastically simplify the orchestration of our registry services.

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose -y
sudo systemctl enable --now docker

Step 2: Deploying Verdaccio for NPM

Create a dedicated directory structure for Verdaccio to persist configurations and package binaries:

mkdir -p ~/registry/verdaccio/conf ~/registry/verdaccio/storage
cd ~/registry/verdaccio

Create a config.yaml file inside the conf directory. Define your storage paths, proxy uplink settings to the official NPM registry, and strict access controls:

storage: /verdaccio/storage/data
plugins: /verdaccio/storage/plugins

web:
  title: "Enterprise Private NPM"

auth:
  htpasswd:
    file: /verdaccio/storage/htpasswd

uplinks:
  npmjs:
    url: [https://registry.npmjs.org/](https://registry.npmjs.org/)

packages:
  '@company/*':
    access: $authenticated
    publish: $authenticated
    proxy: npmjs
  '**':
    access: $all
    publish: $authenticated
    proxy: npmjs

Launch Verdaccio using a lightweight Docker container by mapping ports and volumes correctly to ensure data persistence across server restarts.

Step 3: Deploying Sonatype Nexus for PyPI and Composer

Nexus requires specific system tuning for memory maps due to its Java architecture. Run the following command on your host VPS host:

sudo sysctl -w vm.max_map_count=262144

Create a directory for Nexus storage data and set the appropriate ownership permissions so the containerized application can read and write freely:

mkdir -p ~/registry/nexus-data
sudo chown -R 200:200 ~/registry/nexus-data

Deploy Nexus using Docker Compose. Ensure you allocate the recommended Java Virtual Machine (JVM) heap size settings within your environment variables to prevent out-of-memory errors during high-concurrency CI/CD builds.

---

Configuring Repositories for Multi-Ecosystem Support

Once your Nexus instance is running, navigate to its administrative dashboard to configure your private repositories.

PyPI Configuration (Python)

In the Nexus repository management panel, create two separate repositories for Python:

  1. pypi-hosted: Set deployment policy to 'Allow Redeploy' or 'Disable Redeploy' based on your versioning strategy. This stores internal wheels.
  2. pypi-proxy: Remote URL set to [https://pypi.org/](https://pypi.org/). This caches public packages.
  3. pypi-group: Combine both hosted and proxy into a single unified URL for seamless developer consumption.

Composer Configuration (PHP)

Similarly, create a composer-proxy pointing to [https://repo.packagist.org](https://repo.packagist.org) and a composer-hosted repository for your organization's internal generic zip distributions, allowing seamless integration with your composer.json workflow.

---

Securing Your Infrastructure with Nginx and SSL

Exposing database or registry ports directly to the internet is highly insecure. To protect authentication tokens and package traffic, set up Nginx as a reverse proxy configured with TLS encryption via Certbot.

An example Nginx block configuration ensures all traffic passing to your private registries goes through port 443 with strong modern cipher suites, effectively eliminating cleartext eavesdropping risks on your proprietary enterprise libraries.

---

Conclusion and Best Practices

Establishing a private package registry is a major milestone in securing an organization's software supply chain. By utilizing Verdaccio for rapid Node.js development and Sonatype Nexus for multifaceted PyPI and Composer management, you gain absolute governance over your dependencies.

As next steps, ensure you implement regular automated backups of your storage volumes, set up monitoring alerts for disk space usage, and integrate your registry authentication with your company's Single Sign-On (SSO) or LDAP system for seamless access control management.

Building a Self-Hosted Private Package Registry for Enterprises: NPM, PyPI, and Composer via Verdaccio and Nexus on VPS | DPTCloud