Securing Software Delivery at Scale. How the MCA Transformed Artifact Management Across 50+ Services
The Maritime and Coastguard Agency works to prevent the loss of life on the coast and at sea. It develops maritime legislation and guidance, provides certification to seafarers and operates more than 50 digital services.
>99.9%
Service availability achieved
Daily or weekly
Deployments increased from monthly or yearly
Real time
Vulnerability detection reduced from months
THE CHALLENGE
Removing a critical barrier to automated software delivery
The MCA wanted its engineering teams to release software more frequently, consistently and securely. However, it did not have an in-house artifact repository service through which teams could store, share and control the components used within their applications.
This created a significant gap in its CI/CD capability. Teams could automate parts of the build and deployment process, but they lacked a trusted central service for managing the binaries, libraries, packages, container images and other artifacts passing through those pipelines.
Key challenges included:
- No secure central location in which to store and share software artifacts
- Large, infrequent deployments, with some services going months or years between releases
- Long manual testing cycles involving several rounds of rework
- Limited versioning and traceability around software changes
- Security and compliance risks associated with unverified artifacts and unidentified vulnerabilities
- Slow onboarding for teams and engineers needing access to appropriate repositories
- Inconsistent artifact-management practices across an IT estate supporting more than 50 services
The MCA needed more than a storage solution. It required a resilient repository service that could become part of its engineering infrastructure, support multiple teams and integrate security controls directly into software delivery.
THE SOLUTION
A secure, self-service artifact repository integrated into CI/CD
Catapult deployed a self-hosted Sonatype Nexus Repository within the MCA’s private cloud environment, supported by software bill of materials management and continuous vulnerability scanning.
The service created a single, controlled location for storing and managing software artifacts across the MCA’s engineering estate. High availability and disaster recovery were built into the architecture to support the operational demands of teams responsible for more than 50 services.
Key elements of the solution included:
- A consolidated artifact repository hosted securely within the MCA’s private cloud environment
- High-availability and disaster-recovery capabilities
- Support for multiple artifact types, including binaries, libraries, container images, configuration files, packages and documentation
- Automatic digital signing to verify the authenticity and integrity of each artifact
- Encryption both in transit and at rest
- Self-service provisioning of new repositories
- Self-service access allowing teams to manage their own repositories within defined controls
- Continuous scanning of software dependencies for known vulnerabilities
- Software bill of materials management to improve visibility of application components
- Direct integration with CI/CD pipelines operating across cloud and on-premises environments
By embedding artifact management and vulnerability detection within the delivery process, the MCA could identify potential risks as software was being built rather than discovering them months later through separate reviews.
The self-service model also removed the need for teams to wait for repositories and access to be provisioned manually. New teams and engineers could begin working within minutes while security, signing and encryption requirements remained consistently enforced.
THE RESULTS
From infrequent releases to secure, repeatable delivery
The repository service gave MCA teams a secure and consistent foundation for building, testing and releasing software.
Deployment frequency increased from monthly or yearly releases to daily or weekly delivery. Teams gained immediate access to controlled repositories, while continuous scanning reduced the time taken to identify vulnerable dependencies from months to real time.
Key outcomes included:
- Deployment frequency increased from monthly or yearly to daily or weekly
- Vulnerability detection reduced from months to real time
- Team onboarding reduced to minutes
- Engineer onboarding reduced to minutes
- Digital signing enforced across stored artifacts
- Encryption enforced both in transit and at rest
- More consistent versioning and traceability across software changes
- Better than 99.9% availability achieved for the repository service
- Secure artifact management established across an IT department supporting more than 50 services
- Engineering teams able to automate more of the build, test and release process
The project did not simply introduce a new repository. It established a shared engineering service that improved release flow, strengthened software supply-chain security and made secure delivery practices easier for teams to adopt.