Official upstream source mirror. Do not make UH changes here.
  • Ruby 88.6%
  • HTML 10.7%
  • Dockerfile 0.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-22 09:45:34 +01:00
.github Bump ruby/setup-ruby from 1.321.0 to 1.324.0 2026-09-22 07:03:11 +00:00
app Remove .gitkeep files 2026-09-14 15:18:51 +01:00
bin Add binstubs 2026-05-06 10:01:28 +01:00
config Mount SidekiqUniqueJobs web UI 2026-08-05 12:06:35 +01:00
db Address linting issues 2019-08-06 15:32:10 +01:00
docs Split scanned_infected event in two 2026-07-29 04:16:43 +01:00
lib Remove .gitkeep files 2026-09-14 15:18:51 +01:00
public Accept some Rails 8.1 changes 2026-04-07 14:28:37 +01:00
spec Finalise Pact v2 migration 2026-09-10 16:21:27 +01:00
.dockerignore Remove obsolete Jenkinsfile. 2024-01-31 16:20:47 +00:00
.gitignore Update .gitignore to exclude all log files 2024-09-11 16:01:55 +01:00
.govuk_dependabot_merger.yml Upgrade govuk_dependabot_merger config to use v2 2024-04-30 10:42:23 +01:00
.rspec Jump to rspec-rails 3.3.x 2015-10-12 10:45:02 +01:00
.rubocop.yml Add standard header to protect .rubocop.yml 2021-11-09 09:51:49 +00:00
.ruby-version Update ruby to version 4.0.6 2026-07-21 13:33:58 +01:00
config.ru Run app:update task 2021-08-23 14:04:20 +01:00
Dockerfile Upgrade Ruby to version 4.0.3 2026-05-06 09:41:02 +01:00
Gemfile Finalise Pact v2 migration 2026-09-10 16:21:27 +01:00
Gemfile.lock Merge pull request #2057 from alphagov/dependabot/bundler/aws-sdk-core-3.257.0 2026-09-22 09:45:34 +01:00
LICENCE Add MIT licence 2016-01-08 10:23:14 +00:00
Procfile Add web task to Procfile 2018-02-15 10:38:34 +00:00
Rakefile Finalise Pact v2 migration 2026-09-10 16:21:27 +01:00
README.md Re-enable Sidekiq dashboard with authentication 2026-03-09 14:40:45 +00:00

Asset Manager

Manages uploaded assets (images, PDFs etc.) for applications in the GOV.UK Publishing stack.

The app receives uploaded files from publishing applications and returns the URLs that they will be made available at. Before an asset is available to the public, it is virus scanned. Once a file is found to be clean, Asset Manager serves it at the previously generated URL. Unscanned or Infected files return a 404 Not Found error. Deleted files return a 410 Gone response.

Scanning uses ClamAV and occurs asynchronously via govuk_sidekiq.

Technical Documentation

This is a Ruby on Rails app, and should follow our Rails app conventions.

You can use the GOV.UK Docker environment to run the application and its tests with all the necessary dependencies. Follow the usage instructions to get started.

Use GOV.UK Docker to run any commands that follow.

Running the test suite

bundle exec rspec

Assets on S3

All assets are uploaded to the S3 bucket via a separate govuk_sidekiq job triggered if virus scanning succeeds. Assets are currently still also saved to the NFS mount as per the original behaviour.

In non-production environments if the AWS_S3_BUCKET_NAME environment variable is not set, then a fake version of S3 (S3Storage::Fake) is used and the other AWS_* environment variables do not need to be set. In this case, files are saved to the local filesystem instead of S3 and are served via an instance of Rack::Files mounted on the appropriate route path prefix.

Manuals and decisions

Check the docs directory for detailed instructions, including API documentation.

Viewing the Sidekiq UI

We have access to the Sidekiq UI at the following paths:

This endpoint is authenticated and accessible by adding the 'Sidekiq Admin' permission to your account for Asset Manager in Signon for the relevant environment.

This is only accessible through the draft-assets host, as Signon's redirect URI for Asset Manager has been configured to this host, as it is used for serving access restricted draft assets.

Licence

MIT License