Your own winget source for the enterprise
kvellman is a self-hosted, winget-compatible package repository. Register it as an additional winget source — no client changes, no custom installers.
Why kvellman
No client changes
winget stays the only client. Add kvellman as a source and roll out internal software immediately.
On-prem & air-gapped
Fully self-hostable, including offline/air-gapped operation. No SaaS — your data stays with you.
Zero-trust ready
Site context via URL token, subnet, or mTLS client certificates for segmented networks.
Edge mirroring
Local mirror nodes cache installers on demand — the first machine pulls, the rest hit the LAN.
What it does
winget-compatible REST API
Implements the winget Source contract exactly — information, search and manifest delivery.
Manifests & overlays
Versioned YAML manifests, upstream import, and per-package overlay templates for repeatable edits.
Local installer storage
Mirror installers to S3/MinIO or SMB shares; hashes recomputed on delivery.
Approval workflow
Review and approve versions before they reach clients, with an audit trail.
Telemetry & dashboards
Observe searches, manifest fetches and downloads per site and winget version.
Edge / mirror nodes
Headless caching nodes with mTLS enrollment, central scope control and bandwidth savings.
Community & Enterprise
kvellman is open core: the platform is open source; advanced features are commercial plugins.
Community
Apache-2.0, free. Single-node, ideal for small fleets.
Enterprise
Multi-user, SSO/MFA/RBAC, HA and edge nodes. Commercial subscription.