Version Firewall + Author Mirror
Governance builds can limit which Node.js versions install via a local firewall (static allow/block lists) and Author Software's policy-aware Node.js mirror at https://mirror.author.io/runtime/nodejs (lifecycle rules such as blocking end-of-life releases).
For everyday node_mirror/npm_mirror URLs and HTTP proxies, see Download Mirrors.
Firewall
The NVM for Windows local firewall honors version allow/block lists defined in your organization's security policies (see governance edition registry keys). Static entries are enforced on the client before any download starts whenever nvm install <version> runs. That local check works in air-gapped environments.
Lifecycle aliases such as EOL are not expanded by the local firewall; they are enforced when installs use the Author mirror (below).
For outbound firewall allow-lists, see Requirements. Full key types live in the registry policy reference and basic configuration.
Author Mirror
The Author mirror adds another layer of protection against unapproved Node.js downloads. It enforces dynamic policies through rules, complementary to local allow/block lists.
The Author mirror is not available in air-gapped environments.
Point node_mirror / MirrorNode at Author's mirror service: https://mirror.author.io/runtime/nodejs
Allow outbound HTTPS to:
licensing.author.io— license and verification keysmirror.author.io— Node archives
On Author hosts, NVM may send:
| Credential | Registry | Purpose |
|---|---|---|
| Access token | AccessToken | Authorization: Bearer … on Author downloads; also used for license verification |
| Access key | AccessKey | Signs a short-lived mirror JWT (X-Author-License) on Governance |
Set these with portal scripts/policy, not everyday nvm config docs keys. If the only configured mirror is Author and auth fails, install fails with an authorization error. With multiple mirrors, NVM can fall through to the next URL after a failed attempt (unless the failure is a hard auth denial on a solo Author mirror).
If nodejs.org (or another non-Author host) is later in node_mirror, a failed Author request can fall through and download without Author lifecycle rules (EOL, hosted rulesets). Put Author first and omit public fallbacks when those rules must always apply.
Optional: ApplyVerboseLicenseMetadata includes machine/user identity claims in mirror JWTs for auditing.
Enforce Dynamic Policies
Dynamic policies are lifecycle aliases (i.e. EOL) that classify a range of versions. The Author mirror evaluates them when serving downloads. The same machine-policy lists that feed the local firewall can also seed those aliases into the Author license JWT.
There are two (combinable) ways to enforce dynamic policies on the Author mirror.
1. From machine policy (JWT claims)
VersionAllowList / VersionBlockList (see Governance registry keys) do double duty:
- Static entries — enforced by the local firewall (above), before any download.
- Dynamic aliases (
EOL,ALPHA,MAINTENANCE) — ignored by the local firewall; included in the short-lived license JWT sent only tomirror.author.io. The mirror applies those lifecycle rules when serving the archive.
| Policy entry | Local client | Author mirror (mirror.author.io) | Public mirror (nodejs.org) |
|---|---|---|---|
16.x on block list | Denied before download | Not reached | Not reached |
EOL on block list | Allowed locally (alias ignored) | Denied if version is end-of-life | No Author JWT — not enforced |
Allow 20.x only (no magic) | Non-20 denied locally | — | — |
# Registry Keys
VersionBlockList=EOL
VersionAllowList=20.x
22.x
What this does:
- Locally:
20.x/22.xmatch the allow list.EOLis not expanded, so an end-of-life release is not stopped on the client by that alias alone. Because a dynamic alias is present, the allow list is also not treated as exclusive: other versions can still pass the local check. - On
mirror.author.io: the client sends a license claim derived from these lists (includingNOT EOL). The mirror rejects end-of-life archives. - On
nodejs.org(or any non-Author mirror): no Author JWT —EOLdoes nothing. Put Author first innode_mirror, or add static blocks (for example16.x) if you must enforce without the Author mirror.
Air-gapped/local_install_only installs never hit the mirror, so EOL is not enforced in local environments. Use static allow/block lists (or stage only approved archives).
2. Hosted Rules
Hosted rules are configured through the customer portal:
These rules can be applied conditionally based on:
- IP Address Range(s)
- Geographic Location
- Domains (e.g. Active Directory Domain ID, Entra ID)
- User account/SID
- Assigned Access Key (License Group)
Rules matching your preferred conditions are applied to each request, providing fine-grained control over which versions are allowed to be downloaded.
Organizations whose policies prevent storing any organization data on hosted services can disable hosted rules without impacting local rules processed by the mirror. Do this via the Node Mirror configuration page.
Highly regulated organizations, or those with very strict compliance policies, can request this feature be removed entirely. Contact us if you wish to remove hosted rules entirely.
Local (and air-gapped) installs
| Config | Registry | Role |
|---|---|---|
local_dir | LocalInstallDir | Directory of pre-staged Node archives (+ checksums). Preferred over network when present. |
local_install_only | LocalInstallOnly | If on, never download; fail when the version is missing locally. |
AirGapped is separate: it only forces offline license JWKS verification (licensing.author.io skipped). It does not by itself block Node downloads — use LocalInstallOnly (and/or remove remote mirrors) for install air-gaps. See Local Installations and Air-gapped Installations.
Related
| Topic | Doc |
|---|---|
Basic node_mirror / npm_mirror | Download Mirrors |
| HTTP proxies | Download Mirrors |
| User-facing config keys | Basic Configuration |
Policy keys and .reg sample | Registry Policy Reference |
| Firewall exceptions | Requirements |
| Edition capabilities | Choosing an Edition |
| Inspect mirrors/proxy | nvm env |