Skip to main content
Certified BuildRequires the governance package. Available September 2026.

Version Firewall + Author Mirror

Governance builds can limit which Node.js versions install via a local firewall (static allow/block lists) and Author Software's policy-aware Node.js mirror at https://mirror.author.io/runtime/nodejs (lifecycle rules such as blocking end-of-life releases).

For everyday node_mirror/npm_mirror URLs and HTTP proxies, see Download Mirrors.

Firewall​

The NVM for Windows local firewall honors version allow/block lists defined in your organization's security policies (see governance edition registry keys). Static entries are enforced on the client before any download starts whenever nvm install <version> runs. That local check works in air-gapped environments.

Lifecycle aliases such as EOL are not expanded by the local firewall; they are enforced when installs use the Author mirror (below).

For outbound firewall allow-lists, see Requirements. Full key types live in the registry policy reference and basic configuration.

Author Mirror​

The Author mirror adds another layer of protection against unapproved Node.js downloads. It enforces dynamic policies through rules, complementary to local allow/block lists.

Connected Environments Only

The Author mirror is not available in air-gapped environments.

Point node_mirror / MirrorNode at Author's mirror service: https://mirror.author.io/runtime/nodejs

Allow outbound HTTPS to:

  • licensing.author.io — license and verification keys
  • mirror.author.io — Node archives

On Author hosts, NVM may send:

CredentialRegistryPurpose
Access tokenAccessTokenAuthorization: Bearer … on Author downloads; also used for license verification
Access keyAccessKeySigns a short-lived mirror JWT (X-Author-License) on Governance

Set these with portal scripts/policy, not everyday nvm config docs keys. If the only configured mirror is Author and auth fails, install fails with an authorization error. With multiple mirrors, NVM can fall through to the next URL after a failed attempt (unless the failure is a hard auth denial on a solo Author mirror).

Fallback skips Author policy

If nodejs.org (or another non-Author host) is later in node_mirror, a failed Author request can fall through and download without Author lifecycle rules (EOL, hosted rulesets). Put Author first and omit public fallbacks when those rules must always apply.

Optional: ApplyVerboseLicenseMetadata includes machine/user identity claims in mirror JWTs for auditing.

Enforce Dynamic Policies​

Dynamic policies are lifecycle aliases (i.e. EOL) that classify a range of versions. The Author mirror evaluates them when serving downloads. The same machine-policy lists that feed the local firewall can also seed those aliases into the Author license JWT.

There are two (combinable) ways to enforce dynamic policies on the Author mirror.

1. From machine policy (JWT claims)​

VersionAllowList / VersionBlockList (see Governance registry keys) do double duty:

  • Static entries — enforced by the local firewall (above), before any download.
  • Dynamic aliases (EOL, ALPHA, MAINTENANCE) — ignored by the local firewall; included in the short-lived license JWT sent only to mirror.author.io. The mirror applies those lifecycle rules when serving the archive.
Policy entryLocal clientAuthor mirror (mirror.author.io)Public mirror (nodejs.org)
16.x on block listDenied before downloadNot reachedNot reached
EOL on block listAllowed locally (alias ignored)Denied if version is end-of-lifeNo Author JWT — not enforced
Allow 20.x only (no magic)Non-20 denied locally——
Example: Refuse end-of-life downloads via the Author mirror
# Registry Keys
VersionBlockList=EOL
VersionAllowList=20.x
22.x

What this does:

  1. Locally: 20.x / 22.x match the allow list. EOL is not expanded, so an end-of-life release is not stopped on the client by that alias alone. Because a dynamic alias is present, the allow list is also not treated as exclusive: other versions can still pass the local check.
  2. On mirror.author.io: the client sends a license claim derived from these lists (including NOT EOL). The mirror rejects end-of-life archives.
  3. On nodejs.org (or any non-Author mirror): no Author JWT — EOL does nothing. Put Author first in node_mirror, or add static blocks (for example 16.x) if you must enforce without the Author mirror.

Air-gapped/local_install_only installs never hit the mirror, so EOL is not enforced in local environments. Use static allow/block lists (or stage only approved archives).

2. Hosted Rules​

Hosted rules are configured through the customer portal:

Mirror Rulesets

These rules can be applied conditionally based on:

  • IP Address Range(s)
  • Geographic Location
  • Domains (e.g. Active Directory Domain ID, Entra ID)
  • User account/SID
  • Assigned Access Key (License Group)

Rules matching your preferred conditions are applied to each request, providing fine-grained control over which versions are allowed to be downloaded.

Working in a Regulated Environment?

Organizations whose policies prevent storing any organization data on hosted services can disable hosted rules without impacting local rules processed by the mirror. Do this via the Node Mirror configuration page.

Highly regulated organizations, or those with very strict compliance policies, can request this feature be removed entirely. Contact us if you wish to remove hosted rules entirely.

Local (and air-gapped) installs​

ConfigRegistryRole
local_dirLocalInstallDirDirectory of pre-staged Node archives (+ checksums). Preferred over network when present.
local_install_onlyLocalInstallOnlyIf on, never download; fail when the version is missing locally.

AirGapped is separate: it only forces offline license JWKS verification (licensing.author.io skipped). It does not by itself block Node downloads — use LocalInstallOnly (and/or remove remote mirrors) for install air-gaps. See Local Installations and Air-gapped Installations.

TopicDoc
Basic node_mirror / npm_mirrorDownload Mirrors
HTTP proxiesDownload Mirrors
User-facing config keysBasic Configuration
Policy keys and .reg sampleRegistry Policy Reference
Firewall exceptionsRequirements
Edition capabilitiesChoosing an Edition
Inspect mirrors/proxynvm env