Open-core · self-hosted

Your own winget source for the enterprise

kvellman is a self-hosted, winget-compatible package repository. Register it as an additional winget source — no client changes, no custom installers.

Why kvellman

No client changes

winget stays the only client. Add kvellman as a source and roll out internal software immediately.

On-prem & air-gapped

Fully self-hostable, including offline/air-gapped operation. No SaaS — your data stays with you.

Zero-trust ready

Site context via URL token, subnet, or mTLS client certificates for segmented networks.

Edge mirroring

Local mirror nodes cache installers on demand — the first machine pulls, the rest hit the LAN.

What it does

winget-compatible REST API

Implements the winget Source contract exactly — information, search and manifest delivery.

Manifests & overlays

Versioned YAML manifests, upstream import, and per-package overlay templates for repeatable edits.

Local installer storage

Mirror installers to S3/MinIO or SMB shares; hashes recomputed on delivery.

Approval workflow

Review and approve versions before they reach clients, with an audit trail.

Telemetry & dashboards

Observe searches, manifest fetches and downloads per site and winget version.

Edge / mirror nodes

Headless caching nodes with mTLS enrollment, central scope control and bandwidth savings.

Community & Enterprise

kvellman is open core: the platform is open source; advanced features are commercial plugins.

Community

Apache-2.0, free. Single-node, ideal for small fleets.

Enterprise

Multi-user, SSO/MFA/RBAC, HA and edge nodes. Commercial subscription.