arch-upload
A small command-line helper that sends a local file to a supplied TUS resumable-upload endpoint. It contains generic file-transfer code, not application permissions or backend logic.
Requires Python 3.11+; the recommended uvx command manages the helper's installation.
Install uv using the official instructions
for macOS, Linux, or Windows if uvx is unavailable.
Use
Request an upload session from the service that will receive the file. Save its session
object as a private JSON file outside source control. On macOS/Linux restrict access with
chmod 600 /absolute/path/session.json; on Windows use an owner-only directory/ACL.
On Windows the helper also restricts newly written state-file ACLs to the current user.
uvx arch-upload@0.1.0 --file "/absolute/path/data.csv" --session "/absolute/path/session.json"
The session contains uploadReference, sizeBytes, endpoint, token, and a metadata
object for TUS creation. The helper uses the token only in the x-signature header. No
permanent account/API credentials are required. Never put session contents into logs or Git.
HTTP redirects are refused so neither the token nor file bytes are forwarded to another host.
The helper sends 6 MiB chunks, writes progress to stderr, and emits a JSON result on stdout. Exit 0 means the transfer finished. The receiving service must still finalize/register it. Exit 1 reports a sanitized failure; exit 130 means interrupted.
Resume
Re-run the same command. A private session.json.state.json companion records the upload URL
and local file identity. The helper asks the server for its offset before resuming. Keep the
local file unchanged, and preserve the state file when replacing expired session credentials.
If credentials expire, request fresh ones from the receiving service for the same upload
reference, replace the session JSON, and rerun. If the resumable session itself expires,
first ask the service to finalize in case the final response was lost. If still incomplete,
renew credentials and pass --restart to transfer again from byte zero. It never silently
restarts a large transfer. Delete both private files after the receiving service confirms readiness.
Development and publishing
uv sync --python 3.13
uv run --python 3.13 pytest
uv build --python 3.13
CI tests Linux, macOS, and Windows. The release workflow publishes a reviewed version tag
through PyPI trusted publishing with GitHub environment pypi; there is no stored publishing
API key. The wheel includes only arch_upload and packaging metadata; the source distribution
also contains this README, NOTICE, pyproject.toml, and .gitignore. Dependencies are downloaded
separately and retain their licenses.
The source is publicly readable. No general reuse or open-source license is granted; see NOTICE.
Metadata
Release files for arch-upload 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| arch_upload-0.1.0.tar.gz | 5.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| arch_upload-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.0 kB
Release files / arch_upload-0.1.0.tar.gz
| Download URL | arch_upload-0.1.0.tar.gz |
|---|---|
| Size | 5.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d8dd170c0bab4356d15d6f3478c06f8517002d372eaabed54fae3a8e282dfcdf
|
|
BLAKE2b-256 checksum How to use checksums |
e37db9e146be0f4ca539d8cc6a46c0542a7b5f63677157a5643cb3ecbd0f3599
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / arch_upload-0.1.0-py3-none-any.whl
| Download URL | arch_upload-0.1.0-py3-none-any.whl |
|---|---|
| Size | 7.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5ac77319495951828e4c919ee50ef6fd3a92ce6fd9ed3f91c4b0981cd3544aa1
|
|
BLAKE2b-256 checksum How to use checksums |
27a0a1e72cb145e0408561c9919d80bf0498eaf8e3c1ee87d9358a4b1f2f0d8c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log