Skip to main content

OCI-only artifact catalog CLI

Project description

artifact-locker

artifact-locker stores a small local catalog of files and syncs that current state through OCI with oras.

The installed CLI is available as both artifact-locker and the shorter artlock.

The model is intentionally simple:

  • every artifact is a real stored file
  • the local catalog is the source of truth
  • push makes the remote match local current state
  • pull restores that current state on another machine

Commands

  • artifact-locker bootstrap [--repository <oci-repo>] [--artifact-dir <dir>]
  • artifact-locker init
  • artifact-locker add [source-or-url]
  • artifact-locker list [query]
  • artifact-locker find <query>
  • artifact-locker show <query>
  • artifact-locker remove <query>
  • artifact-locker verify --catalog|--local|--all
  • artifact-locker push
  • artifact-locker pull

Repo Layout

.
├── catalog/
│   ├── artifacts.json
│   └── checksums.txt
├── config.json
└── staging/
    └── release-assets/

config.json stores the OCI repository and the local artifact directory. By default the managed repo lives under ~/.local/share/artifact-locker/ and the managed payload directory is ~/.local/share/artifact-locker/artifacts.

Managed payloads are stored in a flat local tree by platform and filename:

~/.local/share/artifact-locker/artifacts/<platform>/<filename>

Artifact IDs remain in the catalog and OCI tags. Older local trees that still use per-artifact ID directories are tolerated and are migrated forward on write. Category remains catalog metadata for filtering and notes, but it is no longer part of the local serving path.

Registry authentication is external. For ECR Public:

aws ecr-public get-login-password --region us-east-1 | \
  oras login -u AWS --password-stdin public.ecr.aws

Usage

artifact-locker bootstrap \
  --repository public.ecr.aws/o7l3z5i2/artifact-locker \
  --artifact-dir ~/tools/payloads
artifact-locker init
artifact-locker add ./Seatbelt.exe --platform windows --category bin --no-input
artifact-locker add https://example.test/tool.zip --platform linux --category archive --no-input
artifact-locker find seatbelt
artifact-locker show Seatbelt.exe
artifact-locker remove seatbelt
artifact-locker push
artifact-locker pull

The OCI repository is treated as fully owned by artifact-locker. Any remote tag not part of the current live state may be removed on push.

bootstrap is the intended first-run setup command for a consumer machine:

  • initializes the local repo layout if needed
  • writes config.json overrides when provided
  • pulls the current remote catalog by default

Use --skip-pull if you only want local initialization/config without a networked sync.

Development

./scripts/test.sh

Install:

pipx install artifact-locker

Upgrade:

pipx upgrade artifact-locker

Uninstall:

pipx uninstall artifact-locker

Release:

./scripts/release.sh patch

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

artifact_locker-0.3.6.tar.gz (29.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

artifact_locker-0.3.6-py3-none-any.whl (26.5 kB view details)

Uploaded Python 3

File details

Details for the file artifact_locker-0.3.6.tar.gz.

File metadata

  • Download URL: artifact_locker-0.3.6.tar.gz
  • Upload date:
  • Size: 29.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for artifact_locker-0.3.6.tar.gz
Algorithm Hash digest
SHA256 cd73e12d503fb743f909e5e91b34dbf390b7ec1f72ab333dfac2eafd6514a762
MD5 5bb9804dc8fd5c96b3a7aabd57d496b0
BLAKE2b-256 69dfa992b371715ab19bde83f661c4aba1685b026b408624dee2e0c0eb46d69a

See more details on using hashes here.

Provenance

The following attestation bundles were made for artifact_locker-0.3.6.tar.gz:

Publisher: publish-pypi.yml on CameronCandau/Artifact-Locker

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file artifact_locker-0.3.6-py3-none-any.whl.

File metadata

  • Download URL: artifact_locker-0.3.6-py3-none-any.whl
  • Upload date:
  • Size: 26.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for artifact_locker-0.3.6-py3-none-any.whl
Algorithm Hash digest
SHA256 1fa936c9ac6623aa1418450495b07ef549fce10af161f0d9d0bda1667c5de72e
MD5 2d4ae51661e5b648fc4f4bfa300d7bba
BLAKE2b-256 d00f50e6671a37e73c2007a1785a551b9d626347b2f987a5de3d302e230a2471

See more details on using hashes here.

Provenance

The following attestation bundles were made for artifact_locker-0.3.6-py3-none-any.whl:

Publisher: publish-pypi.yml on CameronCandau/Artifact-Locker

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page