The catalog
Controllers get server software and plugins from a catalog: a signed list of versions and their official download links, published at catalog.shardkeep.gg. Shardkeep does not host the files: they are downloaded from their publishers (Mojang, PaperMC, PurpurMC, Modrinth and Hangar).
What is in it
Section titled “What is in it”- Server software: Vanilla, Paper, Purpur, Folia (stable and beta builds) and Velocity, with the Java version each needs.
- Plugins: popular server plugins from Modrinth and Hangar, with their supported platforms and Minecraft versions, dependencies and checksums.
- A denylist of plugin versions withdrawn for security reasons.
It is rebuilt every hour, and Controllers check for a new one every hour.
How it is verified
Section titled “How it is verified”- Each snapshot is signed with Ed25519. Controllers trust only the keys built into their release, and refuse unsigned or wrongly signed snapshots.
- Each snapshot has a sequence number that only grows. Controllers refuse an older one, so a stale mirror or a replay cannot roll the catalog back.
- Every download is checked against the catalog’s hash and size before the Controller stores it. Agents check the hash again before using a file.
Without it
Section titled “Without it”A Controller does not need the catalog to keep servers running. Software already cached keeps working. Run it fully offline, or point it at a mirror with -catalog-url.
The catalog’s builder and format are free software: shardkeep/catalog.
Shardkeep is free software under the AGPL-3.0. Minecraft is a trademark of Mojang AB; Shardkeep is not affiliated with or endorsed by Mojang or Microsoft.