Skip to main content

Conda plugin entry point for the conda-ship runtime builder.

Project description

conda-ship

CI Docs zizmor License Python: 3.10+

Build ready-to-run conda runtimes from solved conda environments.

conda-ship is a generic builder for single-binary conda runtimes. It provides the cs builder CLI, the cs-template generic runtime template, a composite GitHub Action, and an optional Python adapter that exposes conda ship inside conda.

The project is currently alpha and pre-1.0. The split from conda-express is now explicit: conda-ship owns the reusable build/runtime machinery, while downstream distributions own their package sets, runtime names, release channels, installer wrappers, and user documentation. conda-express is one downstream distribution maintained by Jannis Leidel; it uses conda-ship to publish the cx and cxz runtimes.

Quickstart

This shortest path uses conda-workspaces to create a solved source environment, then builds an online runtime named demo:

conda create -n cs-demo -c conda-forge python pip conda-workspaces
conda activate cs-demo
python -m pip install conda-ship

mkdir demo-runtime
cd demo-runtime
conda workspace init --format conda --name demo-runtime
conda workspace add --feature ship --no-lockfile-update \
  "python>=3.12" \
  "conda>=25.1" \
  conda-rattler-solver \
  "conda-spawn>=0.1.0"
cat >> conda.toml <<'TOML'

[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]
TOML

conda workspace lock
cs inspect
cs build --dry-run
cs build
./dist/demo --version

Quickstart: inspect, preview, build, and run a stamped runtime

For a guided walkthrough with Pixi, bootstrap, status, uninstall, and embedded runtime examples, see the first runtime tutorial.

What It Builds

conda-ship stages a runtime binary plus release metadata:

  • .runtime.lock: the lockfile stamped into the runtime
  • .packages.txt: tab-separated package records for quick inspection
  • .info.json: artifact metadata for release tooling
  • .sha256: checksums for staged files
  • optional .bundle.tar.zst: compressed package archives for offline builds

The runtime itself has a small management surface: bootstrap, status, shell, and uninstall. Other commands pass through to the configured delegate executable after bootstrap, usually conda.

During bootstrap, generated runtimes also write constructor-compatible conda prefix metadata. The managed prefix gets conda-meta/history and conda-meta/initial-state.explicit.txt in addition to conda-ship's ownership metadata. Conda can recognize the prefix as an environment, and runtimes that include conda-self can use that initial-state snapshot for conda self reset --snapshot installer-updated or conda self reset --snapshot installer-exact.

Artifact Layouts

Layout Output Bootstrap behavior
online <runtime-name> or <artifact-name> Downloads packages from the stamped runtime lock.
external <runtime-name> or <artifact-name> plus <name>.bundle.tar.zst Uses a separate package bundle for offline-capable installs.
embedded <runtime-name> or <artifact-name> Embeds the compressed package bundle in one binary.

Project Input

conda-ship builds from an already solved source environment. It does not solve loose matchspecs in the GitHub Action and it does not define a package set of its own.

Supported manifest and lockfile pairs:

  • conda.toml plus conda.lock
  • pyproject.toml with [tool.conda] plus conda.lock
  • pixi.toml plus pixi.lock
  • pyproject.toml with [tool.pixi] plus pixi.lock

The package and channel intent lives in the selected source environment. [tool.conda-ship] only records conda-ship build policy:

[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]

The selected source environment must include the runtime contract packages: conda, conda-rattler-solver, and conda-spawn. Include conda-self in the same source environment when the runtime should expose conda self reset for restoring the bootstrapped base prefix to the initial package set shipped by the runtime.

Local Workflow

Packaged builds find cs-template next to the installed cs executable. Use --template only for an explicit template path, custom packaging, or cross-builds.

cs inspect
cs build --dry-run
cs build
cs build --artifact-layout embedded
cs run -- --path /tmp/demo-smoke bootstrap

cs inspect is the preflight command. It derives the runtime lock, validates the selected source environment, applies package exclusions, and prints the package set without writing artifacts.

Inspect a source environment before shipping it

Use cs build --dry-run to preview the runtime metadata and staged release asset paths before writing files.

Preview conda-ship runtime artifacts

After a real build, verify the staged artifacts and inspect the release metadata before handing them to downstream packaging or signing.

Verify staged conda-ship artifacts

The staged runtime is a stamped copy of the generic runtime template with its own command surface before pass-through to the configured delegate.

Run a generated conda-ship runtime

GitHub Actions

The repository root is also a composite GitHub Action for downstream release jobs:

- uses: jezdez/conda-ship@FULL_RELEASE_COMMIT_SHA # X.Y.Z
  id: cs
  with:
    conda-ship-version: "X.Y.Z"
    artifact-layout: embedded

The action expects a committed manifest and matching lockfile. It downloads the configured cs, cs-template, and SHA256SUMS release assets for the runner, verifies their GitHub Artifact Attestations, checks the release checksums, runs cs build --dry-run, and then stages the runtime into a dist-path output.

Pin the action source to a full release commit SHA for release builds and pass the matching conda-ship release through conda-ship-version. When the action is invoked by an exact release tag, conda-ship-version can be omitted for backwards compatibility.

Packaging

conda-ship is not an OS installer generator. It does not target .sh, .pkg, or .msi output directly. It produces runtimes that can be distributed as GitHub Release assets or wrapped by Homebrew, constructor, Docker, enterprise packaging systems, and other release tooling.

The PyPI package installs the cs builder, the cs-template runtime template, and the Python adapter together. The adapter makes conda ship a shortcut for the same builder when installed in a conda environment; it does not make conda-ship part of conda itself. A future conda package should install the same pieces into one environment.

What Belongs Downstream

Downstream distributions decide:

  • runtime names and delegates
  • package sets and channels
  • package exclusions
  • install schemes and install names
  • documentation URLs
  • release channels and installers
  • signing, SBOM, and in-toto provenance for final artifacts

conda-ship verifies the inputs it consumes and the package archives it stages or installs, but downstream release systems should sign and attest the final runtime artifacts after cs build.

Documentation

Full documentation is available at jezdez.github.io/conda-ship.

Useful starting points:

Development

pixi install
pixi run test
pixi run lint
pixi run -e test pytest
pixi run docs

pixi run lint runs the repository's prek hooks, including Rust formatting and clippy checks.

The terminal demos are generated from demos/*.tape with VHS:

pixi run demos
pixi run demos inspect

The tapes build local debug cs and cs-template binaries in hidden setup so the visible commands match the packaged workflow.

Run cargo generate-lockfile after changing Cargo metadata and pixi lock after changing pixi metadata.

License

BSD-3-Clause

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

conda_ship-0.4.0.tar.gz (104.6 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

conda_ship-0.4.0-py3-none-win_arm64.whl (6.9 MB view details)

Uploaded Python 3Windows ARM64

conda_ship-0.4.0-py3-none-win_amd64.whl (7.2 MB view details)

Uploaded Python 3Windows x86-64

conda_ship-0.4.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (7.2 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

conda_ship-0.4.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (7.1 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

conda_ship-0.4.0-py3-none-macosx_11_0_arm64.whl (6.4 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

conda_ship-0.4.0-py3-none-macosx_10_12_x86_64.whl (6.7 MB view details)

Uploaded Python 3macOS 10.12+ x86-64

File details

Details for the file conda_ship-0.4.0.tar.gz.

File metadata

  • Download URL: conda_ship-0.4.0.tar.gz
  • Upload date:
  • Size: 104.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.4.0.tar.gz
Algorithm Hash digest
SHA256 8b1181c885408ad09cfa743259a73f9425f6c185e465708f5ea1e03f2a3d9be5
MD5 9b7c71844c5ac8e5617c7f10c2380f1a
BLAKE2b-256 de2a04014a70409f049213961e8502dea4d6e15bb08001fafabdf496607e0632

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0.tar.gz:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-win_arm64.whl.

File metadata

  • Download URL: conda_ship-0.4.0-py3-none-win_arm64.whl
  • Upload date:
  • Size: 6.9 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.4.0-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 f4e49edf3b523d1b2554d5db83464fef3bab1d5d7f05a46fa70bfbfbe24520c2
MD5 c3b029c21afd5ea470d8f6e3662082d8
BLAKE2b-256 45855707d3cf84ad50537d0d645d5182a61f2b04cb0028ed12f0d04c53ac2fb3

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-win_arm64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-win_amd64.whl.

File metadata

  • Download URL: conda_ship-0.4.0-py3-none-win_amd64.whl
  • Upload date:
  • Size: 7.2 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.4.0-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 0c543dc5f8ca3d371e3152fde1881f0e833eb0f98d4c7f02836e15e938c56867
MD5 d8af9018b788d1fa7b15445dfc1c4f0b
BLAKE2b-256 7356668f7779a8276b32015c904cd4dd9d5d55343950e1efe039c4d0059ecdd5

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-win_amd64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for conda_ship-0.4.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 7b610134820a6ea548f0f47f78c65ce0348ea460ab19650c2f404a7ea4d479f6
MD5 f835a39ee0d40a22871a50c0ec2f78d5
BLAKE2b-256 092c329eab082e850b18714e4adb9cee05604ab6040b632b5bcdde932c23d3a0

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for conda_ship-0.4.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 4b609fcc04a266a4003539f58f581ee97564c5f77c214c3ca186a346dd2eb217
MD5 bd4ae197f136944dbc78385cb86359ac
BLAKE2b-256 b44d18efa7165eb49a93c15ac2699129ec86747940587127c1c610a2e7b339bf

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for conda_ship-0.4.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 344bd008398b5d253f79a7f9f075c70cdb5e65a8e5e459cae81c9b45598f0e40
MD5 085819f6b2296684f9f3dbecedad48c0
BLAKE2b-256 b0d8acd8faf1b090df2e8329946f16930c2684cbb81eab243d10bcd5cfa42d12

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-macosx_11_0_arm64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.4.0-py3-none-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for conda_ship-0.4.0-py3-none-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 bee6f1f6539728be70f092a57d7394f572461c636c7bd1a8a102ef05b10438f7
MD5 ecf57f45fa1ebc3b09e2384df2458d2a
BLAKE2b-256 2a364dd9bc6b355281a7135349261caad6b7b66511c8d06f7b2ed380f692c12a

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.4.0-py3-none-macosx_10_12_x86_64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page