Skip to main content
Admin only Channel governance is how you control where your packages are sourced from and which packages your teams can install. As an administrator, you apply policies to a perimeter’s secure channels and register any external package sources, so workloads in each perimeter resolve only packages that meet your organization’s security requirements.

Default channels

When a perimeter is created, the platform automatically provisions the following channels, sourced from Anaconda’s curated repository:
  • main
  • main-x
  • msys2
Channel names are scoped to the organization and perimeter: <ORG>/<PERIMETER>--<CHANNEL>. For example, the main channel in the default perimeter of an organization named acme appears as acme/default--main. Each perimeter has its own channels, so a policy change in one perimeter won’t affect package access in another.
The perimeter's Code tab

How channel policies work

A channel policy defines exclusion criteria for a channel’s packages as a set of rules. A package must meet all of the rules defined in the channel policy to be excluded from the channel. When a rule includes multiple values, a package matching any of those values satisfies that rule. Policies rely on Anaconda’s package security metadata, such as CVE scores, CVE status, and license information. That metadata only exists for Anaconda-curated channels, so you can apply policies to the secure channels provisioned with the perimeter, but not to external channels. Saving a policy rebuilds the channel’s package index:
  1. The platform takes the source channel’s package index (repodata.json), which lists every package file in the channel.
  2. It evaluates the policy’s rules against each package and drops any package that matches the exclude list.
  3. It serves the new filtered index as the channel’s package contents.
Because conda resolves packages from the perimeter channel’s rebuilt package index, excluded packages can’t be installed by users in that perimeter.

Setting a channel policy

To set a policy on a channel:
  1. Select Perimeters in the left-hand navigation.
  2. Select the perimeter where you want to set the policy.
  3. Select the Code tab.
  4. Select a channel to open its details.
  5. Click Manage Policy.
  6. Choose your policy approach:
    • Turn on the Default policy toggle to apply Anaconda’s recommended exclusions.
    • Turn on the Define your own policy toggle to build a custom exclude list. For each rule, select a field, an operator, and value(s). Available fields include CVE Score, License Family, and CVE Status.
  7. Once you are satisfied with the channel policy, click Save.
The Manage Policy panel with Define your own policy turned on, showing exclude list rows for CVE score, license family, and CVE status

The default channel policy

The default policy excludes packages with critical known vulnerabilities:

Removing a channel policy

To remove a channel policy, turn off the policy toggle, then click Save.
Removing a channel policy removes the security baseline for that channel. Consider adjusting the policy thresholds rather than removing it entirely.

Registering an external channel

External channels are any package source that doesn’t come from Anaconda. External channels currently support conda-forge, registered through Anaconda.org.
Support for Artifactory and PyPI external channels is coming soon.
To register an external channel to a perimeter:
  1. Navigate to the perimeter where you want to add the channel.
  2. Open the Code tab.
  3. Click Manage and select Package Sources.
  4. In the Register a new source modal, enter the external source’s details to make it available in this perimeter.
The registered channel appears in the external channels list on the perimeter’s Code tab. To remove an external channel, click the trash icon on its row.