# Moving source code and packages to a secured environment

**URL:** <https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068>\
**Category:** General Usage\
**Tags:** question\
**Created:** [May 16, 2025, 2:02pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068 "2025-05-16T14:02:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SGHoekstra](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sghoekstra/32/212152_2.png) [@SGHoekstra](https://discourse.julialang.org/u/SGHoekstra)\
**Post date:** [May 16, 2025, 2:02pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/1 "2025-05-16T14:02:47Z")

</div>

Hey everyone,

I need to move source code and a lot of packages to a secured environment where there is no internet. I have seen the options of SIEGE or PackageCompiler to move images to another system but this excludes possibilities to develop code in the secured environment.

Is there a way how I can copy the source code of the packages in my Manifest.toml into a zipfile and unpack in the secured environment. There is a recent version of Julia installed at the new environment. What complicates the situation is that the destination system is a Windows system and my own computer is a Mac.

Thank you in advance!  
Steven

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [May 16, 2025, 2:32pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/2 "2025-05-16T14:32:53Z")

</div>

There are indeed quite a few challenges:

- Package Compiler doesn’t do cross-compilation. To go that route, you’d need a comparable Windows machine on the outside.
- You need to make sure all artifacts (for the correct platform) are also bundled in, in addition to the source code.
- You need to make sure any dynamic assets that hit the internet while running get artifactorized. Many of these have been tackled, but I’m sure there are many still out there.

And then, generally, the folks who run secure environments like these don’t typically like you just walking in with a few gigabytes of executable code without first vetting it in some way.

This is something we’ve helped a number of companies with at JuliaHub. One half-way solution is the [DepotDelivery.jl](https://github.com/JuliaComputing/DepotDelivery.jl) package. But the entire JuliaHub platform itself can also be installed within air-gapped systems and handle the security auditing and such, too.

---

<div class="post-metadata">

**Author:** ![Janis\_Erdmanis](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/janis_erdmanis/32/10869_2.png) [@Janis\_Erdmanis](https://discourse.julialang.org/u/Janis_Erdmanis)\
**Post date:** [May 16, 2025, 2:36pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/3 "2025-05-16T14:36:01Z")

</div>

You may create a private package registry for your organisation, which gives you complete control over all dependencies. This approach could work well for teams and provides the most seamless development workflow. (Note that I am not an expert on this)

However, if you only need dependencies that are specified in `Manifest.toml`, AppBundler.jl may be well fit for the purpose. To use it, create a folder with a project where all necessary dependencies are added. Then you can build a bundled directory with all relevant dependencies via:

```julia
bundle_app(Windows(:x86_64), project_dir, “output_dir”)

```

Then, you can start Julia from `output_dir/julia/bin/julia`, which should have all the project’s dependencies available. (Note there is a heavy development and refactoring happening underneath so for further steps for now one shall reffer to the codebase).

This is currently a hack, but support for Julia distribution creation is planned for the near future with AppBundler.jl

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 16, 2025, 3:21pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/4 "2025-05-16T15:21:16Z")

</div>

JuliaHub offers an air-gapped package server solution. It’s not cheap, but you could talk to sales and probably get a POC before deciding if you want to commit or not.

---

<div class="post-metadata">

**Author:** ![SGHoekstra](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sghoekstra/32/212152_2.png) [@SGHoekstra](https://discourse.julialang.org/u/SGHoekstra)\
**Post date:** [May 17, 2025, 1:00pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/5 "2025-05-17T13:00:56Z")

</div>

Thank you!  
The secured environment is managed by a governmental agency so convincing them to start using commercial software will probably out of reach even though it might solve many of their problems.

I will give DepotDeliver.jl a try! Thank you for your suggestion

---

<div class="post-metadata">

**Author:** ![SGHoekstra](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sghoekstra/32/212152_2.png) [@SGHoekstra](https://discourse.julialang.org/u/SGHoekstra)\
**Post date:** [May 17, 2025, 1:05pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/6 "2025-05-17T13:05:57Z")

</div>

This also looks good! I will give it a try next week.  
Thank you for the suggestion

---

<div class="post-metadata">

**Author:** ![SGHoekstra](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/sghoekstra/32/212152_2.png) [@SGHoekstra](https://discourse.julialang.org/u/SGHoekstra)\
**Post date:** [May 17, 2025, 1:07pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/7 "2025-05-17T13:07:10Z")

</div>

The owners of the secured environment is a governmental organisation.  
Convincing them to use a new service will probably be very difficult…

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [May 17, 2025, 5:38pm UTC](https://discourse.julialang.org/t/moving-source-code-and-packages-to-a-secured-environment/129068/8 "2025-05-17T17:38:36Z")

</div>

JuliaHub has worked with a number of government agencies so it might be easier than you think. Work a conversation with our govt folks. DM me if you want me to connect you.
