You have created a registry on your Repsy Open Source instance. You are now ready to publish Go modules to your registry.
Repsy implements the Go Module Proxy Protocol. Publishing a module means uploading a properly structured zip archive to your registry using HTTP.
Create a Go module
Start by creating a directory for your module. The directory name must match the directory component of your module path.
mkdir mymodule && cd mymodule
Initialize the module with go mod init. The module path must be a valid identifier — for private or internal modules, use a domain you control:
go mod init example.com/mymodule
Add your Go source files. For example, create a simple file:
// mymodule.go
package mymodule
const Version = "v1.0.0"
Run go mod tidy to ensure your go.mod and go.sum files are up to date:
go mod tidy
Package and upload the module
Repsy expects modules to be uploaded as zip archives following the Go module proxy format. The zip must contain all module files under the full module path, for example:
example.com/[email protected]/go.mod
example.com/[email protected]/mymodule.go
To achieve this, a temporary staging directory is used and the zip command runs from within it — this prevents any absolute path prefixes from being included in the archive.
Run these commands from inside your module directory. Replace example.com/mymodule with your actual module path and <username>, <repo-name> with your Repsy credentials.
VERSION=v1.0.0
MODULE_PATH=example.com/mymodule
STAGING=$(mktemp -d)
MODULE_VERSION_DIR="${STAGING}/${MODULE_PATH}@${VERSION}"
mkdir -p "${MODULE_VERSION_DIR}"
cp -r . "${MODULE_VERSION_DIR}/"
(cd "${STAGING}" && find "${MODULE_PATH}@${VERSION}" -type f | xargs zip "${OLDPWD}/module.zip")
curl -u <username>:<password> \
-T module.zip \
-H "Content-Sha256: $(sha256sum module.zip | cut -d' ' -f1)" \
"https://<your-repsy-host>/<repo-name>/${MODULE_PATH}/@v/${VERSION}.zip"
Uploading always needs credentials, also to a public repository, so keep the -u flag. Use your username and password, or a deploy token with the Read/Write access type in place of the password: the username can be any value. https://<your-repsy-host> stands for the address of the package protocol port of your Repsy Open Source instance, see Ports and Repository URLs.
The Content-Sha256 header is optional — remove the -H line if you prefer to skip integrity verification.
If the upload is successful, you will receive an HTTP 200 response.
Verify the upload
Confirm the module is available by querying the version list:
curl -u <username>:<password> \
"https://<your-repsy-host>/<repo-name>/${MODULE_PATH}/@v/list"
Congratulations, you have published a Go module to your registry! You can now install it into any Go project.
Repsy never overwrites a version of a Go module: uploading a version that already exists is refused with 409, whatever the settings of the repository, so publish a new version instead. The commands above pack every file of the directory, including a .git directory if there is one. Publishing a Go Module with curl shows how to build the zip the way the go command does, and lists what Repsy checks on an upload and what each refusal looks like.
The Configure button of a Go repository in the web UI shows the same commands with the address and the name of your repository filled in.