Conda plugin entry point for the conda-ship runtime builder.
Project description
conda-ship
Build ready-to-run conda runtimes from solved conda environments.
conda-ship is a generic builder for single-binary conda runtimes. It
provides the cs builder CLI, the cs-template generic runtime template, a
composite GitHub Action, and an optional Python adapter that exposes
conda ship inside conda.
The project is currently alpha and pre-1.0. The split from
conda-express is now explicit:
conda-ship owns the reusable build/runtime machinery, while downstream
distributions own their package sets, runtime names, release channels, installer
wrappers, and user documentation. conda-express is one downstream distribution
maintained by Jannis Leidel; it uses conda-ship to publish the cx and cxz
runtimes.
Quickstart
This shortest path uses conda-workspaces to create a solved source environment,
then builds an online runtime named demo:
conda install --name base -c conda-forge conda-pypi
conda create -n cs-demo -c conda-forge python pip conda-workspaces
conda activate cs-demo
conda pypi install conda-ship
mkdir demo-runtime
cd demo-runtime
conda workspace init --format conda --name demo-runtime
conda workspace add --feature ship --no-lockfile-update \
"python>=3.12" \
"conda>=25.1" \
conda-rattler-solver \
"conda-spawn>=0.1.0"
cat >> conda.toml <<'TOML'
[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]
TOML
conda workspace lock
cs inspect
cs build --dry-run
cs build
./dist/demo info
For a guided walkthrough with automatic first-run bootstrap and embedded runtime examples, see the first runtime tutorial.
What It Builds
conda-ship stages a runtime binary plus release metadata:
.runtime.lock: the lockfile stamped into the runtime.packages.txt: tab-separated package records for quick inspection.info.json: artifact metadata for release tooling.sha256: checksums for staged files- optional
.bundle.tar.zst: compressed package archives for offline builds
On first invocation, the runtime automatically bootstraps its managed prefix.
It then passes every argument to the configured delegate executable, usually
conda. The delegate and its plugins handle --help, --version, and every
subcommand. conda-ship does not reserve those arguments.
The finished executable contains the native bootstrap and optional update
machinery from cs-template. Neither the executable nor its managed prefix
needs the conda-ship Python package.
During bootstrap, generated runtimes also write constructor-compatible conda
prefix metadata. The managed prefix gets conda-meta/history and
conda-meta/initial-state.explicit.txt in addition to conda-ship's ownership
metadata. Conda can recognize the prefix as an environment, and runtimes that
include conda-self can use that initial-state snapshot for
conda self reset --snapshot installer-updated or
conda self reset --snapshot installer-exact.
Artifact Layouts
| Layout | Output | Bootstrap behavior |
|---|---|---|
online |
<runtime-name> or <artifact-name> |
Downloads packages from the stamped runtime lock. |
external |
<runtime-name> or <artifact-name> plus <name>.bundle.tar.zst |
Uses a separate package bundle for offline-capable installs. |
embedded |
<runtime-name> or <artifact-name> |
Embeds the compressed package bundle in one binary. |
Project Input
conda-ship builds from an already solved source environment. It does not solve loose matchspecs in the GitHub Action and it does not define a package set of its own.
Supported manifest and lockfile pairs:
conda.tomlplusconda.lockpyproject.tomlwith[tool.conda]plusconda.lockpixi.tomlpluspixi.lockpyproject.tomlwith[tool.pixi]pluspixi.lock
The package and channel intent lives in the selected source environment.
[tool.conda-ship] only records conda-ship build policy:
[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]
The selected source environment defines the complete package set. It must
include the configured delegate executable and any optional commands the
distribution exposes. A conda distribution can include conda,
conda-rattler-solver, and conda-spawn, while a runtime with another delegate
can omit them.
Include conda-self when a conda runtime should
expose conda self reset for restoring the bootstrapped base prefix to the
initial package set shipped by the runtime.
conda-ship does not choose conda configuration. Set condarc-file to copy a
YAML condarc file to <prefix>/.condarc, and set
freeze-base = true when it should write a CEP 22 frozen marker. Both are
disabled by default.
Local Workflow
Packaged builds find cs-template next to the installed cs executable.
Use --template only for an explicit template path, custom packaging, or
cross-builds.
cs inspect
cs build --dry-run
cs build
cs build --artifact-layout embedded
cs run --install-path /tmp/demo-smoke -- info
cs inspect is the preflight command. It derives the runtime lock, validates the
selected source environment, applies package exclusions, and prints the package
set without writing artifacts.
Use cs build --dry-run to preview the runtime metadata and staged release
asset paths before writing files.
After a real build, verify the staged artifacts and inspect the release metadata before handing them to downstream packaging or signing.
The staged runtime is a stamped copy of the generic runtime template. It bootstraps the managed prefix if needed, then runs the configured delegate.
CONDA_SHIP_PREFIX overrides the managed prefix for every runtime. A
runtime-specific variable such as DEMO_PREFIX remains available for other
runtime names. A runtime named conda does not use CONDA_PREFIX for this
purpose because that variable may describe an activated environment.
GitHub Actions
The repository root is also a composite GitHub Action for downstream release jobs:
- uses: jezdez/conda-ship@FULL_RELEASE_COMMIT_SHA # X.Y.Z
id: cs
with:
conda-ship-version: "X.Y.Z"
artifact-layout: embedded
The action expects a committed manifest and matching lockfile. It downloads the
configured cs, cs-template, and SHA256SUMS release assets for the
runner, verifies their GitHub Artifact Attestations, checks the release
checksums, runs cs build --dry-run, and then stages the runtime into a
dist-path output.
Pin the action source to a full release commit SHA for release builds and pass
the matching conda-ship release through conda-ship-version. When the action
is invoked by an exact release tag, conda-ship-version can be omitted for
backwards compatibility.
Packaging
conda-ship is not an OS installer generator. It does not target .sh, .pkg,
or .msi output directly. It produces runtimes that can be distributed as
GitHub Release assets or wrapped by Homebrew, constructor, Docker, enterprise
packaging systems, and other release tooling.
The PyPI package installs the cs builder, the cs-template runtime template,
and the Python adapter together. The adapter makes conda ship a shortcut for
the same builder when installed in a conda environment. It does not make
conda-ship part of conda itself. A conda package for the builder should install
the same pieces together in its builder environment.
What Belongs Downstream
Downstream distributions decide:
- runtime names and delegates
- package sets and channels
- package exclusions
- install schemes and install names
- documentation URLs
- release channels and installers
- signing, SBOM, and in-toto provenance for final artifacts
conda-ship verifies the inputs it consumes and the package archives it stages or
installs, but downstream release systems should sign and attest the final
runtime artifacts after cs build.
Documentation
Full documentation is available at jezdez.github.io/conda-ship.
Useful starting points:
Development
pixi install
pixi run test
pixi run lint
pixi run -e test pytest
pixi run docs
pixi run lint runs the repository's prek hooks, including Rust formatting
and clippy checks.
The terminal demos are generated from demos/*.tape with
VHS:
pixi run demos
pixi run demos inspect
The tapes build local debug cs and cs-template binaries in hidden setup so
the visible commands match the packaged workflow.
Run cargo generate-lockfile after changing Cargo metadata and pixi lock
after changing pixi metadata.
License
BSD-3-Clause
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file conda_ship-0.6.2.tar.gz.
File metadata
- Download URL: conda_ship-0.6.2.tar.gz
- Upload date:
- Size: 143.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
23031df058993daebbb62d45e8c28f724c8eab3caf5e2735c683564005067c66
|
|
| MD5 |
4f0a2c6de7e198daa78b251cfc51331e
|
|
| BLAKE2b-256 |
09b8b9c5de98a5a3d089c98353d2a3d85aa4ec0ed9702ec05f99d62b3f63c136
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2.tar.gz:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2.tar.gz -
Subject digest:
23031df058993daebbb62d45e8c28f724c8eab3caf5e2735c683564005067c66 - Sigstore transparency entry: 2221559810
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-win_arm64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-win_arm64.whl
- Upload date:
- Size: 7.0 MB
- Tags: Python 3, Windows ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1e315829a85abae5e0f8c9e07d23f1e1f38194780117babea7e059abb23c31e6
|
|
| MD5 |
98529cbdec5a439ca5b73676e3a48a64
|
|
| BLAKE2b-256 |
c4f0a7f5032f3081bc3cf06f9d3ae73c412ac58852f4838330ef1e3716130945
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-win_arm64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-win_arm64.whl -
Subject digest:
1e315829a85abae5e0f8c9e07d23f1e1f38194780117babea7e059abb23c31e6 - Sigstore transparency entry: 2221561553
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-win_amd64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-win_amd64.whl
- Upload date:
- Size: 7.4 MB
- Tags: Python 3, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3906c440838a4fee435cf063b9cd722a11a674923909fc20f133f70461924cce
|
|
| MD5 |
c9cb864e247b44166046935324e28a08
|
|
| BLAKE2b-256 |
4c05cb8ce79454d22c786a25cd5cc805755868f1d064ac62c9c1eb4855363f1b
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-win_amd64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-win_amd64.whl -
Subject digest:
3906c440838a4fee435cf063b9cd722a11a674923909fc20f133f70461924cce - Sigstore transparency entry: 2221560873
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 7.4 MB
- Tags: Python 3, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c370c88d56565970273f3f61115590a6b76af9b11f573650aa203170d9ceaeaa
|
|
| MD5 |
fba2b1e5afd53a06500375b720803eb8
|
|
| BLAKE2b-256 |
3709871da19685001108e30aa8a7e685efe2c037fa1ed1c1eb42cc478a822415
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl -
Subject digest:
c370c88d56565970273f3f61115590a6b76af9b11f573650aa203170d9ceaeaa - Sigstore transparency entry: 2221560210
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
- Upload date:
- Size: 7.4 MB
- Tags: Python 3, manylinux: glibc 2.17+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c69f044508cbc3f1a1f8f0f13f5efc356bef24152d161c3547d8f3974eeba8c7
|
|
| MD5 |
bf563eafc0522207709543f845c76b13
|
|
| BLAKE2b-256 |
98bbe9775e8bd4870f53f91aa8e04abbc4dec5103fe36a327969d8fec95d900b
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl -
Subject digest:
c69f044508cbc3f1a1f8f0f13f5efc356bef24152d161c3547d8f3974eeba8c7 - Sigstore transparency entry: 2221560554
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-macosx_11_0_arm64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-macosx_11_0_arm64.whl
- Upload date:
- Size: 6.6 MB
- Tags: Python 3, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
283c868436bb45410b5b16d6ffb34287eeba0df4b6e58aabc113248b413dfa0c
|
|
| MD5 |
40de3ec8758415a5de7bf40b32cd96e5
|
|
| BLAKE2b-256 |
6a92480b9e65ab418638e40b9b04949edb44705301cd34a83a8105a3324a7cbc
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-macosx_11_0_arm64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-macosx_11_0_arm64.whl -
Subject digest:
283c868436bb45410b5b16d6ffb34287eeba0df4b6e58aabc113248b413dfa0c - Sigstore transparency entry: 2221561145
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type:
File details
Details for the file conda_ship-0.6.2-py3-none-macosx_10_12_x86_64.whl.
File metadata
- Download URL: conda_ship-0.6.2-py3-none-macosx_10_12_x86_64.whl
- Upload date:
- Size: 6.9 MB
- Tags: Python 3, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ef2c01f72c45823a5c0c00adb99f09bda03d7576f3e9bb060dd6742c34ecd96d
|
|
| MD5 |
3379f67206405663453dfd52c199da53
|
|
| BLAKE2b-256 |
259dd2a10da6c037f681e2a6b5bade4ae6f8359d2e13a24b25d2f0ac4a440a75
|
Provenance
The following attestation bundles were made for conda_ship-0.6.2-py3-none-macosx_10_12_x86_64.whl:
Publisher:
release.yml on jezdez/conda-ship
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
conda_ship-0.6.2-py3-none-macosx_10_12_x86_64.whl -
Subject digest:
ef2c01f72c45823a5c0c00adb99f09bda03d7576f3e9bb060dd6742c34ecd96d - Sigstore transparency entry: 2221562002
- Sigstore integration time:
-
Permalink:
jezdez/conda-ship@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Branch / Tag:
refs/tags/0.6.2 - Owner: https://github.com/jezdez
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@992021e2bb69e573c1475c3bbf5d3d5892e6dfe8 -
Trigger Event:
push
-
Statement type: