Back to articles
Technology Insight

Scaling Internal Efficiency: Deploying Private NuGet and PyPI Repositories on ARM-Based VPS with BaGet and pypiserver

June 4, 2026

In the modern software development lifecycle, managing internal dependencies is a critical factor for maintaining security, consistency, and speed. As technology companies grow, the need to share proprietary libraries across multiple projects becomes unavoidable. Relying on public repositories for private code is a security risk, while manual distribution of binaries is an operational nightmare. This is where private package registries come into play.

Traditionally, hosting such services required significant overhead or expensive enterprise licenses. However, with the rise of high-performance ARM-based VPS instances (such as those offered by AWS Graviton or Oracle Cloud), companies can now host their own robust infrastructure at a fraction of the cost. This article provides a technical roadmap for deploying BaGet for NuGet packages and pypiserver for Python packages on a single ARM server using Docker.

Why ARM Architecture for Internal Tooling?

ARM-based servers are no longer just for mobile devices; they have become a staple in the data center. For a company hosting internal tools like NuGet or PyPI servers, ARM offers several distinct advantages:

  • Cost-Efficiency: ARM instances typically provide 20-40% better price-to-performance ratios compared to x86 equivalents.
  • Power Efficiency: Lower power consumption translates to lower operational costs, which is often reflected in the billing of cloud providers.
  • Scalability: Most modern containerized applications are built to be architecture-agnostic, making the transition to ARM seamless.

Part 1: Setting up the Private NuGet Server with BaGet

BaGet is a lightweight, open-source implementation of a NuGet server. It is particularly well-suited for ARM because it is built on .NET Core, which has first-class support for ARM64.

Prerequisites and Configuration

Before deployment, ensure your VPS has Docker and Docker Compose installed. We will use a SQLite database for simplicity, though BaGet supports SQL Server and PostgreSQL for larger scale operations.

Pro Tip: Always use an API Key to protect your package feed. Unprotected feeds are vulnerable to unauthorized package injections.

Docker Compose Deployment

Create a directory for BaGet and define your docker-compose.yml. You will need to map volumes for the data and configuration files to ensure persistence across container restarts.

    services:
      baget:
        image: loicsharma/baget
        container_name: nuget-server
        environment:
          - ApiKey=YOUR_SECURE_API_KEY
          - Storage__Type=FileSystem
          - Storage__Path=/var/baget/packages
          - Database__Type=Sqlite
          - Database__ConnectionString=Data Source=/var/baget/baget.db
        volumes:
          - ./baget-data:/var/baget
        ports:
          - "5000:80"
        restart: always
  

Part 2: Hosting Private Python Packages with pypiserver

For the Python ecosystem, pypiserver is a minimal, highly efficient solution that works perfectly on ARM. It allows your team to pip install internal tools just as they would from the public PyPI.

Security and Access Control

Unlike public repositories, your internal PyPI should require authentication. pypiserver uses htpasswd files for basic authentication, which is lightweight and easy to manage on a VPS.

Implementation Steps

  1. Create a packages directory: mkdir ~/pypi/packages.
  2. Generate an htpasswd file to store encrypted credentials.
  3. Configure the Docker container to point to these files.

By running pypiserver, you avoid the complexity of full-scale Artifactory or Nexus setups while maintaining complete control over your Python artifacts.

Part 3: Unified Management and Reverse Proxy

Running two separate services on one VPS requires a way to route traffic efficiently. We recommend using Nginx or Traefik as a reverse proxy. This setup allows you to use subdomains like nuget.yourcompany.com and pypi.yourcompany.com.

Implementing SSL via Let's Encrypt

Security is non-negotiable for internal code. Using Certbot, you can automate the acquisition of SSL certificates. Never transmit API keys or package data over unencrypted HTTP, especially when accessing the server over the public internet.

Sample Nginx Configuration

Your Nginx configuration should handle large file uploads (common in package management) by adjusting the client_max_body_size parameter. A standard value for internal repositories is 100MB.

Optimizing Performance on ARM

To ensure your repositories remain responsive as your library count grows, consider the following optimizations:

  • I/O Optimization: Use an SSD-backed block storage for your package volumes. ARM instances often have high throughput capabilities that can be bottlenecked by slow disks.
  • Resource Limits: Define CPU and Memory limits in Docker Compose to prevent one service from starving the other.
  • Regular Backups: Use rsync or cloud snapshots to back up your package volumes daily. Losing your internal source of truth can halt production deployments.

Conclusion

Deploying a private NuGet and PyPI server on an ARM VPS is a sophisticated yet cost-effective way to mature your organization's DevOps culture. By utilizing BaGet and pypiserver, you provide your developers with the tools they need to collaborate securely without the high overhead of enterprise-grade suites.

The transition to internal package management reduces build times through local caching, improves security by keeping proprietary code off public mirrors, and ensures that your deployment pipeline is resilient against external repository outages. Start small, secure your endpoints, and empower your engineering team with a professional-grade artifact infrastructure.

Scaling Internal Efficiency: Deploying Private NuGet and PyPI Repositories on ARM-Based VPS with BaGet and pypiserver | DPTCloud