Skip to main content

conda-express (cx)

CI Docs License PyPI

A single-binary bootstrapper for conda, powered by rattler. The cx binary is short for conda express.

conda-express is the distribution project for the cx and cxz binaries. It is not an official conda distribution.

cx offers an alternative to the Anaconda Distribution, Miniconda, and Miniforge constructor-style installer pattern: a 7-11 MB native binary that bootstraps a managed conda base environment from a locked package set.

Quick start

Bootstrap conda, create an environment, and activate it

# The first conda command bootstraps the managed prefix
cx info

# Run conda commands through cx
cx create -n myenv python=3.12 numpy pandas
cx create -n science python=3.12 scipy

# Activate environments using conda-spawn, without conda init
cx spawn myenv

On first use, cx automatically installs conda and its plugins into ~/.conda/express from the built-in runtime lock. Subsequent invocations hand off to the installed conda binary.

What gets installed

cx installs a managed conda stack from conda-forge:

Package Role
python >= 3.12 Runtime
conda Package manager
conda-rattler-solver Rust-based solver without libmamba's native dependency chain
conda-spawn >= 0.1.0 Subprocess-based environment activation
conda-completion >= 0.3.0 Shell completion support
conda-exec >= 0.3.0 Ephemeral package execution and PEP 723 script workflows
conda-pypi PyPI interoperability
conda-self Base environment self-management
conda-global Global tool installation and PATH management
conda-workspaces >= 0.7.0 Multi-environment workspace and task management

See the included plugins reference for the commands and workflows these packages add.

Shell completion is available through the included conda-completion plugin:

cx completion status
cx completion install --dry-run --command-name cx

Pass --command-name cx when installing or generating a completion hook so it registers cx instead of the underlying conda executable.

Ad hoc package commands can run through the included conda-exec plugin without adding tools to the managed base prefix:

cx exec ruff --version

The conda-libmamba-solver and its 27 exclusive native dependencies (libsolv, libarchive, libcurl, spdlog, etc.) are excluded by default because cx configures conda-rattler-solver.

Versioning

conda-express versions follow the conda version in the runtime lock. If conda-express needs a packaging-only rebuild without changing the bundled conda version, it uses a post-release version.

Installation

Homebrew (recommended)

Homebrew is the recommended install path on macOS and Linux:

brew tap jezdez/conda-express https://github.com/jezdez/conda-express
brew install jezdez/conda-express/cx

Update later with brew upgrade cx.

Shell script

macOS / Linux:

curl -fsSL https://jezdez.github.io/conda-express/get-cx.sh | sh

Windows (PowerShell):

powershell -ExecutionPolicy ByPass -c "irm https://jezdez.github.io/conda-express/get-cx.ps1 | iex"

The script detects your platform, downloads the right binary, verifies the checksum, updates your shell profile / PATH, and runs cx info to bootstrap the managed prefix. Customize with environment variables:

  • CX_INSTALL_DIR — where to place the binary (default: ~/.local/bin or %USERPROFILE%\.local\bin)
  • CX_VERSION — specific version to install without a v prefix (default: latest)
  • CX_NO_PATH_UPDATE — set to skip shell profile / PATH modification
  • CX_NO_BOOTSTRAP — set to skip the installer's eager bootstrap command
  • CX_SKIP_VERIFY — set to skip checksum verification
  • CX_PREFIX — managed prefix used by automatic bootstrap (default: ~/.conda/express)
  • CX_BUNDLE — bundle directory used during automatic bootstrap
  • CX_OFFLINE — set to a truthy value to force offline bootstrap

GitHub Actions

Use the setup action from a pinned conda-express release tag:

steps:
  - uses: jezdez/conda-express/.github/actions/setup-cx@<release-tag>
  - run: cx info

The action downloads the matching cx release asset, verifies its checksum, adds cx to PATH, and runs cx info by default. That first conda command automatically bootstraps the managed prefix. Artifact Attestation verification is available with verify-attestation: true.

See the GitHub Actions guide for automatic bootstrap, deferred bootstrap, and attestation examples.

From GitHub Releases

Download the binary for your platform from the latest release:

Platform File
Linux x86_64 cx-x86_64-unknown-linux-gnu
Linux ARM64 cx-aarch64-unknown-linux-gnu
macOS x86_64 (Intel) cx-x86_64-apple-darwin
macOS ARM64 (Apple Silicon) cx-aarch64-apple-darwin
Windows x86_64 cx-x86_64-pc-windows-msvc.exe

Windows ARM64 is not published for conda-express yet. conda-ship publishes Windows ARM64 builder assets, but full runtime bootstrap support is still gated by the conda package ecosystem.

Each file has matching .sha256, .info.json, .packages.txt, .runtime.lock, and CycloneDX .cdx.json files. Release artifacts are also covered by GitHub Artifact Attestations:

gh attestation verify ./cx-x86_64-unknown-linux-gnu \
  -R jezdez/conda-express \
  --signer-workflow jezdez/conda-express/.github/workflows/release.yml

See the artifact verification guide for checksum, metadata, runtime lock, and air-gapped transfer checks.

Docker

A multi-arch image is published to GHCR on every release:

docker run --rm -v cx-data:/home/nonroot/.conda/express ghcr.io/jezdez/conda-express info

The image runs as non-root (uid 65532), can run with a read-only root filesystem when the managed prefix is mounted as a writable volume, and includes provenance attestations and SBOMs. Docker Desktop on macOS and Windows automatically selects the right architecture (linux/amd64 or linux/arm64).

docker run --rm --read-only --tmpfs /tmp \
  -v cx-data:/home/nonroot/.conda/express \
  ghcr.io/jezdez/conda-express info
# Run a conda command through cx
docker run --rm -v cx-data:/home/nonroot/.conda/express ghcr.io/jezdez/conda-express create -n myenv python=3.12

Use as a container in CI (GitHub Actions):

jobs:
  test:
    container: ghcr.io/jezdez/conda-express:latest
    steps:
      - run: cx create -n test python numpy

Use as a base for multi-stage application builds:

FROM ghcr.io/jezdez/conda-express:latest AS conda-builder
RUN cx create -n app python numpy pandas
FROM gcr.io/distroless/cc-debian12:nonroot
COPY --from=conda-builder /home/nonroot/.conda/express/envs/app /opt/conda

PyPI

pip install conda-express

The PyPI package installs the cx release binary built with conda-ship for your platform.

Upgrading from early releases

Current cx releases bootstrap into ~/.conda/express. Early releases used ~/.cx; upgrading the binary does not migrate that prefix automatically. Keep ~/.cx until you have recreated or archived any environments you still need. If an old Cargo-installed cx is still on your PATH, remove it because conda-express no longer publishes new crates.io releases.

See the upgrade guide for commands to export old environments, bootstrap the new prefix, and remove the old directory safely.

Reproducing distribution artifacts

The cx and cxz artifacts published from this repository are built with conda-ship. This repository keeps the conda-express distribution defaults and delegates the generic runtime and builder implementation to conda-ship.

Use this repository's release workflow to reproduce these conda-express artifacts. For custom package sets, binary names, or release channels, use conda-ship directly.

Configuration

The conda-express runtime is defined in pyproject.toml. Pixi solves the runtime source environment, and conda-ship derives the runtime lock from that committed lockfile:

[tool.conda-ship]
runtime-name = "cx"
runtime-version = { from = "project-metadata" }
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "runtime"
exclude-packages = ["conda-libmamba-solver"]
condarc-file = "runtime.condarc"
freeze-base = true
docs-url = "https://jezdez.github.io/conda-express/"
install-scheme = "conda-home"
install-name = "express"

CLI reference

cx <conda-args>                  Bootstrap if needed, then run conda
cx info                          Show conda and prefix information
cx spawn [ENV]                   Open a subshell through conda-spawn
cx self <command>                Run conda-self commands

CX_PREFIX=DIR cx <conda-args>    Use a different managed prefix
CX_BUNDLE=DIR cx <conda-args>    Seed automatic bootstrap from a bundle
CX_OFFLINE=1 cx <conda-args>     Disable network access during bootstrap

cx --help, cx --version, and every subcommand belong to the installed conda CLI. The bootstrapper does not reserve its own commands.

Frozen base prefix

The ~/.conda/express prefix is protected with a CEP 22 frozen marker after bootstrap. This prevents accidental modification of the base environment (e.g., conda install numpy into base). Users should create named environments for their work:

cx create -n myenv numpy pandas
cx spawn myenv

Bootstrap also writes constructor-compatible prefix metadata: conda-meta/history and conda-meta/initial-state.explicit.txt. Conda can recognize the managed prefix as an environment, and the included conda-self plugin can use the initial-state snapshot:

cx self reset --snapshot installer-exact

The snapshot belongs to the prefix that was created during its first bootstrap. Installing a newer cx binary does not replace that snapshot, and conda self reset does not apply the newer binary's stamped runtime lock.

Building custom binaries

For custom package sets or new distributions, use conda-ship directly. This repository's build workflow is release preparation for this repository's cx and cxz binaries, not a generic downstream builder interface.

Uninstalling

Remove cx with the same method that installed it. For example, use brew uninstall cx for Homebrew or python -m pip uninstall conda-express for PyPI. A standalone script installation can be removed by deleting the installed binary and its PATH entry.

Those operations do not delete ~/.conda/express or its named environments. Export anything you need before removing that directory manually. Until conda-self gains a conda-express adapter, there is no cx uninstall command.

How it works

  1. Build time: Pixi solves the runtime source environment into pixi.lock; the conda-express release workflow asks conda-ship to derive a runtime lock, filter excluded packages, and stamp that lock into the staged binary.

  2. First run: cx reads the stamped runtime lock, downloads packages from conda-forge, installs them into the prefix, and writes conda-compatible prefix metadata. No repodata fetch or solve needed at runtime.

  3. Subsequent runs: cx detects the existing prefix and replaces its own process with the installed conda binary, passing all arguments through.

Activation model

cx delegates conda commands after bootstrap

cx ships with conda-spawn instead of traditional conda activate. There is no need to run conda init or modify shell profiles.

# Optional: expose the managed conda executable directly
export PATH="$HOME/.conda/express/condabin:$PATH"

# Activate an environment (spawns a subshell)
cx spawn myenv

# Deactivate by exiting the subshell
exit

Lockfile format

The stamped runtime lock uses the rattler-lock v6 format (same as pixi.lock). It can be:

  • Read by pixi
  • Imported by conda-lockfiles
  • Checked into version control for reproducibility auditing

License

BSD 3-Clause. See LICENSE.

Release files for conda-express 26.7.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for conda-express 26.7.2
File
conda_express-26.7.2-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
conda_express-26.7.2-py3-none-manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
conda_express-26.7.2-py3-none-manylinux2014_aarch64.whl Python 3 none Linux glibc 2.17+ ARM64 Details
conda_express-26.7.2-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
conda_express-26.7.2-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 19.4 MB

Release files / conda_express-26.7.2-py3-none-win_amd64.whl

Download URL conda_express-26.7.2-py3-none-win_amd64.whl
Size 4.0 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
4c30e0d6e2103a65c65d395c5c4b78cf413fe5a9e23db9fe5718ce7a7ea317d0
BLAKE2b-256 checksum
How to use checksums
e54ea2ecd9a491a0a320037128343532bb7707e576c145881028d11552b630cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / conda_express-26.7.2-py3-none-manylinux2014_x86_64.whl

Download URL conda_express-26.7.2-py3-none-manylinux2014_x86_64.whl
Size 4.0 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
03b19d613630ff3b28fe0330338641b842e6c8ef5439cf732a49fd13f90bc05f
BLAKE2b-256 checksum
How to use checksums
7c35d4e70517316442a5476aa947001d98395743685857a8048ba2f3e2ec34bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / conda_express-26.7.2-py3-none-manylinux2014_aarch64.whl

Download URL conda_express-26.7.2-py3-none-manylinux2014_aarch64.whl
Size 3.9 MB
Tags Linux glibc 2.17+ ARM64 Python 3
SHA-256 checksum
How to use checksums
40d4187f6198065b8a390562b7375fb4d7cc6d6aa463af9b063420a3ab88ae01
BLAKE2b-256 checksum
How to use checksums
1e81d9ff806dd09c5f7c97f397a09ebbd6325927ca9f052ef56038ec118bc436
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / conda_express-26.7.2-py3-none-macosx_11_0_arm64.whl

Download URL conda_express-26.7.2-py3-none-macosx_11_0_arm64.whl
Size 3.6 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
d4c9a76a06f1e1dd2dbffc44a09086b5ee144c3ebcc4748eda87b4a1dd482db7
BLAKE2b-256 checksum
How to use checksums
10fb5dd7ae53694398846370f4312d0bbb05353121faba6ecc150d55ce34adfd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log

Release files / conda_express-26.7.2-py3-none-macosx_10_12_x86_64.whl

Download URL conda_express-26.7.2-py3-none-macosx_10_12_x86_64.whl
Size 3.8 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
aafc7a2bdd605eee09dd3ed7bfd66d4b79208bc3a1c206cfd210ad9029788925
BLAKE2b-256 checksum
How to use checksums
02c0f292c8c233117d5c25d1f0e72dfdec80e720c3a7ce1357af6bc4e04922c3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page