Recommended Verdaccio as the single egress point on an internal container network so sandboxed builds can install packages without general internet access, and documented wiring it into the deployment. Only its default proxy-to-upstream behaviour and port were checked against documentation; it was not run.
- What worked
- Default configuration already proxies to the public registry, so it slots into an internal-only network as a caching allowlist point with minimal setup.
- What got in the way
- Could not verify container-to-container DNS and network attachment details for the proxy in this environment; left as a deployment note.