About Cloudsmith
What is Cloudsmith?
Cloudsmith is a fully managed, cloud-native artifact management platform that provides a single source of truth for all software artifacts. It serves as both the control plane and data plane for your software supply chain, helping teams control, secure, and distribute artifacts at global scale.
Cloudsmith supports all major package formats - such as Docker, Python, Maven, npm, Helm, ML models, and more - and integrates with CI/CD systems, developer workflows, and security tools. Artifacts are delivered through a global Package Delivery Network (PDN) for fast, reliable access anywhere in the world.
Differentiators
Cloudsmith is designed for organizations that want to:
- Move to the cloud: Replace on-premises registries with a fully managed, globally available service.
- Secure their software supply chain: Enforce policies, scan for vulnerabilities, and verify artifact provenance.
- Adopt AI: Support AI-enabled development workflows, where models, datasets, and other artifacts become part of the software supply chain. Cloudsmith provides a single platform to manage these alongside traditional software artifacts, with consistent security and governance.
- Improve developer experience: Provide developers with fast artifact access, CI/CD integrations, and reliable global delivery.
- Distribute software globally: Deliver artifacts to customers, partners, or internal teams with low latency worldwide.
Cloudsmith organizes artifacts into a simple hierarchy:
- Workspace: The top-level scope for managing users, billing, and policies.
- Repository: A logical grouping of packages. Repositories are multi-format and can host any supported package type.
- Package: An immutable software artifact, such as a container image, library, or dataset.
For more details about these concepts, see Key Concepts, or explore some practical examples in the Common Use Cases section.
Not sure where to start?
Artifact Management for the SDLC
Centralized storage, management, and control of all software artifacts in one location.
Software Distribution
A platform to securely and reliably distributing software to customers at scale.
Software Supply Chain Security
Identify and mitigate security vulnerabilities and license compliance risks.
Software Supply Chain Observability
Get insights about your artifact management and distribution workflows.
Developer tools
Cloudsmith is built by developers, for developers. We understand the workflows and processes that developers use and need, and we try to ensure that what we build brings value to our customers, and generally makes their lives easier.
We maintain a set of tools to programmatically manage your workspaces, repositories, and artifacts. Along with other elements within Cloudsmith that helps you manage your organization: like teams, user accounts, service accounts, or tokens to conveniently automate configuration through scripts or any of the existing tooling you already use.
Cloudsmith CLI
Integrate smoothly with Cloudsmith without requiring explicit plugins or tools
REST API
Retrieve information, upload packages, or take actions programmatically through our API.
Visual Studio Code Extension
View and manage your Cloudsmith packages directly within VS Code.
Webhooks
Reveive notifications when particular actions take place within Cloudsmith.
Terraform Provider
Automate administrative actions with our Terraform provider.
We believe in what we have built. We love to talk to other developers about what we have created, how it can fit into their development processes, and how we can help. If you have questions or would like to chat, please just contact us.