# Alternate Sources - SonaType Nexus - Artifact Repository/Repository Management for CI/CD

Canonical: https://abierto.us/opportunities/rfihncsonatype

- Solicitation number: RFI_HNC_SonaType
- Notice type: Sources sought
- Status: Closed. Deadline was August 8, 2024 at 12:00 PM EDT
- Department: Department of the Air Force
- Agency: Department of the Air Force
- Contracting office: FA8307 AFLCMC HNCK HNC Cyber & NTR (FA8307)
- NAICS: 513210 Software Publishers
- Product or service code: 7A21 Business Application off-the-shelf software delivered by perpetual license, which also encompasses enterprise level software enabling mission capability and business operational support.
- Place of performance: San Antonio, Texas
- County: Bexar County (FIPS 48029). https://abierto.us/counties/bexar-county-tx-48029
- City: San Antonio. https://abierto.us/cities/san-antonio-tx-4865000
- First posted: July 30, 2024
- Last posted: August 1, 2024
- SAM.gov: https://sam.gov/workspace/contract/opp/9912d10536cd4f048eb0204f301de488/view

## Description

Our goal is to identify a solution that can provide a repository manager that organizes, stores and distributes development artifacts in a DevSecOps environment. The repository should provide a single point of reference for approved application containers and software artifacts for users.

The repository will store, integrate with keycloak identity credential and access management (ICAM) and make available to operational organizations for evaluation and operational acceptance that have been through Continuous Integration (CI) and automated Continuous Deployment (CD) pipelines. Thereby, creating a DevSecOps compliant express lane for certification to field (CtF) and deployment of applications. The following are some of the key characteristics that we are using to meet our organizational objectives.

While this list is not exhaustive, it does provide a snapshot of some of the most important requirements for our environment: Ability to store artifacts in AWS S3 Create Docker repository mirrors Available as a helm chart / containerized deployment for Kubernetes Supports SAML or OIDC authentication and authorization (Group assertions from the Idp are honored) Role-based access control management (RBAC) for local images Supports the creation and use of apt, docker, raw, maven2, rpm, pypi, npm, conda, go, gitlfs, helm, nuget, r, and yum repositories.

Supports the use of api tokens / personal access tokens to retrieve software programmatically Supports the use of subdomain routing, and the use of multiple subdomains for assigning to repositories Support for multiple authentication systems Proxy access to external repositories Ability to record use in auditable logs so that activity can be traced to a single user Optimized for automation

## Publications

- July 30, 2024: Sources sought, due August 8, 2024 at 12:00 PM EDT. Notice 294ff093ae2c45f9903698d306ff0e6b. https://sam.gov/workspace/contract/opp/294ff093ae2c45f9903698d306ff0e6b/view
- August 1, 2024: Sources sought, due August 8, 2024 at 12:00 PM EDT. Notice 9912d10536cd4f048eb0204f301de488. https://sam.gov/workspace/contract/opp/9912d10536cd4f048eb0204f301de488/view

## Points of contact

- Karin Werner, karin.werner.1@us.af.mil
- Marisa Flores, marisa.flores.2@us.af.mil

---
Source: SAM.gov Contract Opportunities bulk extract. Confirm deadlines on SAM.gov before responding. Cite https://abierto.us/opportunities/rfihncsonatype.
