---
title: "@playstack/nest-registry"
description: "NestJS binding for the read-only npm registry protocol with an ejectable controller."
tags: ["package","infrastructure","registry","nestjs","pro"]
---

{/* package-access:start */}

> **Pro.** Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/nest-registry` supplies sync and async DI registration for the read-only npm registry protocol, a Node HTTP streaming boundary, and an ejectable Express controller. It does not create credentials, persistence, buckets, subscriptions, or public routes.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/nest-registry@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

## Register

```ts
import { PlaystackRegistryModule, type NestRegistryOptions } from '@playstack/nest-registry'

PlaystackRegistryModule.forRootAsync({
  imports: [ApplicationRegistryModule],
  inject: [APPLICATION_REGISTRY_OPTIONS],
  useFactory: (options) => options as NestRegistryOptions,
})
```

Supply `NestRegistryOptions`: the core npm options (`registry`, trusted `baseUrl`, `authenticate`, `resolvePackage`, `download`) and optional bounds and reporting. Eject `templates/registry.controller.ts.template`, register it in the module that imports `PlaystackRegistryModule`, and review its path against `baseUrl`, including any Nest global prefix. The module is not global and registers no controller itself.

## Transport rules

The controller owns exactly one response per request and never reads bodies: writes are unsupported and answer 501. `handleNode` preserves the original encoded request path, rejects normalized or absolute-form targets, takes the public origin only from `baseUrl`, and passes raw duplicate Authorization headers to the core's strict parser. Core ETags, private `no-store` headers, status codes, and the signed-redirect policy are preserved; nothing buffers a whole tarball. Defaults are an 8 KiB request-target limit and a 60-second whole-response deadline; disconnects abort the download stream.

## Boundary

Keep the application's rate limits, proxy policy, and header and body limits in front of this route. Do not add interceptors that serialize or compress tarball bytes or guards that redirect to a browser login. Fastify is not qualified.

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/nest-registry@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/nest-registry` | `./dist/index.d.ts` |
| `@playstack/nest-registry/playstack.integration.json` | No TypeScript declaration (asset or metadata export). |
| `@playstack/nest-registry/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

| Peer | Compatible range | When needed |
| --- | --- | --- |
| `@nestjs/common` | `^10.0.0 \|\| ^11.0.0` | Required by the package. |
| `@playstack/registry` | `0.1.0-beta.1` | Required by the package. |
| `reflect-metadata` | `^0.1.13 \|\| ^0.2.0` | Required by the package. |
| `rxjs` | `^7.0.0` | Required by the package. |

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
