Skip to main content

OCI-only artifact catalog CLI

Project description

artifact-locker

artifact-locker stores a small local catalog of files and syncs that current state through OCI with oras.

The model is intentionally simple:

  • every artifact is a real stored file
  • the local catalog is the source of truth
  • push makes the remote match local current state
  • pull restores that current state on another machine

Commands

  • artifact-locker init
  • artifact-locker add [source-or-url]
  • artifact-locker list [query]
  • artifact-locker find <query>
  • artifact-locker show <query>
  • artifact-locker remove <query>
  • artifact-locker verify --catalog|--local|--all
  • artifact-locker push
  • artifact-locker pull

Repo Layout

.
├── catalog/
│   ├── artifacts.json
│   └── checksums.txt
├── config.json
└── staging/
    └── release-assets/

config.json stores the OCI repository and the local artifact directory. By default the managed repo lives under ~/.local/share/artifact-locker/ and the managed payload directory is ~/.local/share/artifact-locker/artifacts.

Managed payloads are stored by platform, category, and artifact ID:

~/.local/share/artifact-locker/artifacts/<platform>/<category>/<artifact_id>/<filename>

Registry authentication is external. For ECR Public:

aws ecr-public get-login-password --region us-east-1 | \
  oras login -u AWS --password-stdin public.ecr.aws

Usage

artifact-locker init
artifact-locker add ./Seatbelt.exe --platform windows --category bin --no-input
artifact-locker add https://example.test/tool.zip --platform linux --category archive --no-input
artifact-locker find seatbelt
artifact-locker show Seatbelt.exe
artifact-locker remove seatbelt
artifact-locker push
artifact-locker pull

The OCI repository is treated as fully owned by artifact-locker. Any remote tag not part of the current live state may be removed on push.

Development

python3 -m pytest
python3 -m build

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

artifact_locker-0.3.1.tar.gz (27.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

artifact_locker-0.3.1-py3-none-any.whl (25.5 kB view details)

Uploaded Python 3

File details

Details for the file artifact_locker-0.3.1.tar.gz.

File metadata

  • Download URL: artifact_locker-0.3.1.tar.gz
  • Upload date:
  • Size: 27.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for artifact_locker-0.3.1.tar.gz
Algorithm Hash digest
SHA256 9704170d8c1a0004f1f10d2201c62266eac975529168fbdc95fdcaabc534ad88
MD5 3197fe7c1dc3f9226bbe1e63f110ea41
BLAKE2b-256 b10111b8f3c8af1439a2388cd78794aecf6bdcc4f77a61d079bd104b4963653f

See more details on using hashes here.

Provenance

The following attestation bundles were made for artifact_locker-0.3.1.tar.gz:

Publisher: publish-pypi.yml on CameronCandau/Artifact-Locker

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file artifact_locker-0.3.1-py3-none-any.whl.

File metadata

File hashes

Hashes for artifact_locker-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 60c1d232e5a0167e626ff9f1f2a679e7fa5e1866b7e5e020002651d39055c0f9
MD5 d0c052cc62ab2ce90d556eae7a98445a
BLAKE2b-256 c837a0e6cea166fc5485c0a7d7b5a1825e3c132613748b5d85cd7901da832134

See more details on using hashes here.

Provenance

The following attestation bundles were made for artifact_locker-0.3.1-py3-none-any.whl:

Publisher: publish-pypi.yml on CameronCandau/Artifact-Locker

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page