Cargo configuration
A Cargo repository requires the cargo config. project and page are optional and shared with
Maven and npm.
{ "type": "Hosted" }Hosted is the only mode. There is no Proxy variant, so a Cargo repository cannot mirror
crates.io — configure both registries side by side and name yours explicitly on the dependencies
that come from it:
[dependencies]serde = "1" # crates.ionitro-example = { version = "1", registry = "nitro" } # yoursconfig.json
Section titled “config.json”Not a stored config — the registry generates it per request, because the right answer depends on how the client reached it:
{ "dl": "https://repo.example.com/repositories/local/crates/api/v1/crates", "api": "https://repo.example.com/repositories/local/crates", "auth-required": false}A request that arrived on a custom domain is answered with that domain’s
root instead. Telling a client to go back through /repositories/{storage}/{name} would work only
where both hosts resolve.
auth-required follows the repository’s visibility: true for anything not Public. It is what
makes Cargo send a token on index requests as well as on publish.
project
Section titled “project”Shared with Maven and npm. Badge appearance and version validation.
| Field | Type | Default |
|---|---|---|
badge_settings.style |
flat | plastic | flatsquare |
flat |
badge_settings.label_color |
colour | #555 |
badge_settings.color |
colour | #33B5E5 |
require_semver |
boolean | false |
Cargo versions are semver by definition, so require_semver is close to a no-op here.
A repository without a project config cannot serve badges — that is where their settings live.
See Badges.
Shared with Maven and npm. The content shown on the repository’s page in the UI.
| Field | Type | Default |
|---|---|---|
page_type |
Markdown | HTML | None |
— |
content |
string or null | null |
A good place for the .cargo/config.toml your team should be using.
Repository-level settings
Section titled “Repository-level settings”Visibility. Public downloads need no credentials; Private requires a token with read access,
and sets auth-required so Cargo knows to send one. Hidden is readable but absent from search and
listings. Writes always require authentication.
Active. An inactive repository refuses every request from everyone.
No push rules
Section titled “No push rules”There is no Cargo equivalent of maven_push_rules. The behaviour those would control is fixed:
- Re-publishing an existing version is always refused.
- Overwriting is never allowed.
- Any user with
Writemay publish any crate name. Ownership is recorded on first publish and governscargo owner, but it does not reserve the name in advance.