Skip to main content

Conda plugin entry point for the conda-ship runtime builder.

Project description

conda-ship

CI Docs zizmor License Python: 3.10+

Build ready-to-run conda runtimes from solved conda environments.

conda-ship is a generic builder for single-binary conda runtimes. It provides the cs builder CLI, the cs-template generic runtime template, a composite GitHub Action, and an optional Python adapter that exposes conda ship inside conda.

The project is currently alpha and pre-1.0. The split from conda-express is now explicit: conda-ship owns the reusable build/runtime machinery, while downstream distributions own their package sets, runtime names, release channels, installer wrappers, and user documentation. conda-express is one downstream distribution maintained by Jannis Leidel; it uses conda-ship to publish the cx and cxz runtimes.

Quickstart

This shortest path uses conda-workspaces to create a solved source environment, then builds an online runtime named demo:

conda install --name base -c conda-forge conda-pypi
conda create -n cs-demo -c conda-forge python pip conda-workspaces
conda activate cs-demo
conda pypi install conda-ship

mkdir demo-runtime
cd demo-runtime
conda workspace init --format conda --name demo-runtime
conda workspace add --feature ship --no-lockfile-update \
  "python>=3.12" \
  "conda>=25.1" \
  conda-rattler-solver \
  "conda-spawn>=0.1.0"
cat >> conda.toml <<'TOML'

[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]
TOML

conda workspace lock
cs inspect
cs build --dry-run
cs build
./dist/demo info

For a guided walkthrough with automatic first-run bootstrap and embedded runtime examples, see the first runtime tutorial.

What It Builds

conda-ship stages a runtime binary plus release metadata:

  • .runtime.lock: the lockfile stamped into the runtime
  • .packages.txt: tab-separated package records for quick inspection
  • .info.json: artifact metadata for release tooling
  • .sha256: checksums for staged files
  • optional .bundle.tar.zst: compressed package archives for offline builds

On first invocation, the runtime automatically bootstraps its managed prefix. It then passes every argument to the configured delegate executable, usually conda. The delegate and its plugins handle --help, --version, and every subcommand. conda-ship does not reserve those arguments.

The finished executable contains the native bootstrap and optional update machinery from cs-template. Neither the executable nor its managed prefix needs the conda-ship Python package.

During bootstrap, generated runtimes also write constructor-compatible conda prefix metadata. The managed prefix gets conda-meta/history and conda-meta/initial-state.explicit.txt in addition to conda-ship's ownership metadata. Conda can recognize the prefix as an environment, and runtimes that include conda-self can use that initial-state snapshot for conda self reset --snapshot installer-updated or conda self reset --snapshot installer-exact.

Artifact Layouts

Layout Output Bootstrap behavior
online <runtime-name> or <artifact-name> Downloads packages from the stamped runtime lock.
external <runtime-name> or <artifact-name> plus <name>.bundle.tar.zst Uses a separate package bundle for offline-capable installs.
embedded <runtime-name> or <artifact-name> Embeds the compressed package bundle in one binary.

Project Input

conda-ship builds from an already solved source environment. It does not solve loose matchspecs in the GitHub Action and it does not define a package set of its own.

Supported manifest and lockfile pairs:

  • conda.toml plus conda.lock
  • pyproject.toml with [tool.conda] plus conda.lock
  • pixi.toml plus pixi.lock
  • pyproject.toml with [tool.pixi] plus pixi.lock

The package and channel intent lives in the selected source environment. [tool.conda-ship] only records conda-ship build policy:

[tool.conda-ship]
runtime-name = "demo"
runtime-version = "0.1.0"
delegate-executable = "conda"
artifact-layout = "online"
source-environment = "ship"
exclude-packages = ["conda-libmamba-solver"]

The selected source environment defines the complete package set. It must include the configured delegate executable and any optional commands the distribution exposes. A conda distribution can include conda, conda-rattler-solver, and conda-spawn, while a runtime with another delegate can omit them. Include conda-self when a conda runtime should expose conda self reset for restoring the bootstrapped base prefix to the initial package set shipped by the runtime.

conda-ship does not choose conda configuration. Set condarc-file to copy a YAML condarc file to <prefix>/.condarc, and set freeze-base = true when it should write a CEP 22 frozen marker. Both are disabled by default.

Local Workflow

Packaged builds find cs-template next to the installed cs executable. Use --template only for an explicit template path, custom packaging, or cross-builds.

cs inspect
cs build --dry-run
cs build
cs build --artifact-layout embedded
cs run --install-path /tmp/demo-smoke -- info

cs inspect is the preflight command. It derives the runtime lock, validates the selected source environment, applies package exclusions, and prints the package set without writing artifacts.

Inspect a source environment before shipping it

Use cs build --dry-run to preview the runtime metadata and staged release asset paths before writing files.

Preview conda-ship runtime artifacts

After a real build, verify the staged artifacts and inspect the release metadata before handing them to downstream packaging or signing.

Verify staged conda-ship artifacts

The staged runtime is a stamped copy of the generic runtime template. It bootstraps the managed prefix if needed, then runs the configured delegate.

CONDA_SHIP_PREFIX overrides the managed prefix for every runtime. A runtime-specific variable such as DEMO_PREFIX remains available for other runtime names. A runtime named conda does not use CONDA_PREFIX for this purpose because that variable may describe an activated environment.

GitHub Actions

The repository root is also a composite GitHub Action for downstream release jobs:

- uses: jezdez/conda-ship@FULL_RELEASE_COMMIT_SHA # X.Y.Z
  id: cs
  with:
    conda-ship-version: "X.Y.Z"
    artifact-layout: embedded

The action expects a committed manifest and matching lockfile. It downloads the configured cs, cs-template, and SHA256SUMS release assets for the runner, verifies their GitHub Artifact Attestations, checks the release checksums, runs cs build --dry-run, and then stages the runtime into a dist-path output.

Pin the action source to a full release commit SHA for release builds and pass the matching conda-ship release through conda-ship-version. When the action is invoked by an exact release tag, conda-ship-version can be omitted for backwards compatibility.

Packaging

conda-ship is not an OS installer generator. It does not target .sh, .pkg, or .msi output directly. It produces runtimes that can be distributed as GitHub Release assets or wrapped by Homebrew, constructor, Docker, enterprise packaging systems, and other release tooling.

The PyPI package installs the cs builder, the cs-template runtime template, and the Python adapter together. The adapter makes conda ship a shortcut for the same builder when installed in a conda environment. It does not make conda-ship part of conda itself. A conda package for the builder should install the same pieces together in its builder environment.

What Belongs Downstream

Downstream distributions decide:

  • runtime names and delegates
  • package sets and channels
  • package exclusions
  • install schemes and install names
  • documentation URLs
  • release channels and installers
  • signing, SBOM, and in-toto provenance for final artifacts

conda-ship verifies the inputs it consumes and the package archives it stages or installs, but downstream release systems should sign and attest the final runtime artifacts after cs build.

Documentation

Full documentation is available at jezdez.github.io/conda-ship.

Useful starting points:

Development

pixi install
pixi run test
pixi run lint
pixi run -e test pytest
pixi run docs

pixi run lint runs the repository's prek hooks, including Rust formatting and clippy checks.

The terminal demos are generated from demos/*.tape with VHS:

pixi run demos
pixi run demos inspect

The tapes build local debug cs and cs-template binaries in hidden setup so the visible commands match the packaged workflow.

Run cargo generate-lockfile after changing Cargo metadata and pixi lock after changing pixi metadata.

License

BSD-3-Clause

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

conda_ship-0.6.3.tar.gz (145.6 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

conda_ship-0.6.3-py3-none-win_arm64.whl (7.1 MB view details)

Uploaded Python 3Windows ARM64

conda_ship-0.6.3-py3-none-win_amd64.whl (7.4 MB view details)

Uploaded Python 3Windows x86-64

conda_ship-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (7.4 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

conda_ship-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl (7.4 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

conda_ship-0.6.3-py3-none-macosx_11_0_arm64.whl (6.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

conda_ship-0.6.3-py3-none-macosx_10_12_x86_64.whl (6.9 MB view details)

Uploaded Python 3macOS 10.12+ x86-64

File details

Details for the file conda_ship-0.6.3.tar.gz.

File metadata

  • Download URL: conda_ship-0.6.3.tar.gz
  • Upload date:
  • Size: 145.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.6.3.tar.gz
Algorithm Hash digest
SHA256 be0a19751f5501b2b19cfcd49e540517c6c4ac5a50e2232919945a5e09ff65f5
MD5 1e62441f02b6c3c8fab50bfce1a141f9
BLAKE2b-256 c5601854298c9bd1b775ef6e2ad93563b5259dfe3a0bdc9ed000c6ceb75aff74

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3.tar.gz:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-win_arm64.whl.

File metadata

  • Download URL: conda_ship-0.6.3-py3-none-win_arm64.whl
  • Upload date:
  • Size: 7.1 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.6.3-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 a2e89b700ede9fca9dbc6210111d461823712aebd4b4b8406a0b65f964735340
MD5 04ccc7ecac769fa600d69733e9b7e9a3
BLAKE2b-256 b705ec5b0585faca4e26dde39e33690f40ff68402301e6760c9b4abe8947f787

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-win_arm64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-win_amd64.whl.

File metadata

  • Download URL: conda_ship-0.6.3-py3-none-win_amd64.whl
  • Upload date:
  • Size: 7.4 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for conda_ship-0.6.3-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 c4fc3ccdd925b2b274bb8cf99f7ceb1af93536027adfad4b5fdd1d35e4c53f0c
MD5 aff0427f780e7e6b2993f6675584e288
BLAKE2b-256 c54f35a3dbef816230ae12b756b13d91f9bb0b2abd0617a83ca291502e25da36

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-win_amd64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.

File metadata

File hashes

Hashes for conda_ship-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Algorithm Hash digest
SHA256 c4e75846ed4bc5b1132483d7493b43e392e1424530e68a208c6da96b59fccb37
MD5 6cb572c2aa761468bf10245d0babd1bb
BLAKE2b-256 c36505d1c4456ec4ca122a68a45032c5e506b961802bc37c47335b0c3b43d6a3

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.

File metadata

File hashes

Hashes for conda_ship-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Algorithm Hash digest
SHA256 4f5c35bf12b5376e5fe720b24c2d37ad97e9f7dec3ff3f445d27292e3ef842e8
MD5 c18fdbfeb3cd9fe237fb0651d8b4e07f
BLAKE2b-256 1ddc14ad7be20210a9a88c3551e78a77180b13b9f3193178db98ebff3a49569f

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for conda_ship-0.6.3-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 34726e9ed17bb716ff1518373a90508cb1aa544ef3e3f6dcc7021965b8473f4c
MD5 a42278a4acd58e15ed4465a7a9843d1b
BLAKE2b-256 92c052f839e620e0d5b96a42baec7d4d6aa4902da02d83176b7c08be4e17ceb9

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-macosx_11_0_arm64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file conda_ship-0.6.3-py3-none-macosx_10_12_x86_64.whl.

File metadata

File hashes

Hashes for conda_ship-0.6.3-py3-none-macosx_10_12_x86_64.whl
Algorithm Hash digest
SHA256 568366d8c5aa2d63bc855ae38304481827a6a907c08a17b6699f4dd1c5341837
MD5 a9a77f82817dc9de56a7fe756941807b
BLAKE2b-256 da3dd9c7218cc990f87458cf835ff6943af2f8604b9c6854aa4afca7e1e7f661

See more details on using hashes here.

Provenance

The following attestation bundles were made for conda_ship-0.6.3-py3-none-macosx_10_12_x86_64.whl:

Publisher: release.yml on jezdez/conda-ship

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page