This project has been archived by its maintainers, and is no longer receiving any updates.
git-buckets-keyring
A stateless keyring backend for git-buckets package registries. It turns
your ambient AWS profile into a short-lived package token so uv sync and pip install can reach a private
index with no login step.
It stores nothing. On each lookup it SigV4-signs an sts:GetCallerIdentity call with your profile, trades that
proof for a 1-hour token at https://<host>/auth/token, and hands the token to the client as the HTTP Basic
password. Tokens are cached in-process only, never on disk.
Setup
Once per machine:
uv tool install git-buckets-keyring
export UV_KEYRING_PROVIDER=subprocess # or tool.uv.keyring-provider = "subprocess"
export GB_KEYRING_HOSTS=git.example.cloud # hosts this backend is allowed to answer for
Then in the consuming project's pyproject.toml:
[[tool.uv.index]]
name = "demos"
url = "https://gb@git.example.cloud/packages/demos/pypi/"
explicit = true
[tool.uv.sources]
demos-cli = { index = "demos" }
The gb@ in the URL is load-bearing: uv only performs keyring discovery when the index URL carries a username.
GB_KEYRING_HOSTS
A comma-separated allowlist of hostnames, empty by default. The backend returns None for every host that is not
listed, and for every username other than gb, so it is inert on other machines and other indexes. It is an
allowlist, not a target: the host used is the one the client asked about, admitted only if it is listed.
Printing a token by hand
keyring get https://git.example.cloud/packages/demos/pypi/ gb
If the bundled keyring script collides
uv tool install git-buckets-keyring installs a keyring executable of its own. If that clashes with an existing
one, install the other way round:
uv tool install keyring --with git-buckets-keyring
Release files for git-buckets-keyring 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| git_buckets_keyring-0.1.0.tar.gz | 8.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| git_buckets_keyring-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.4 kB
Release files / git_buckets_keyring-0.1.0.tar.gz
| Download URL | git_buckets_keyring-0.1.0.tar.gz |
|---|---|
| Size | 8.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2b257bd5131e2683103f17096798ef297d96e5d43fdc63f7652a1d7d84f29178
|
|
BLAKE2b-256 checksum How to use checksums |
8dded0cd41531067a54d7508ffcb4a695d6ac58542f7fd801bdd64e58bc8afef
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.
Transparency logRelease files / git_buckets_keyring-0.1.0-py3-none-any.whl
| Download URL | git_buckets_keyring-0.1.0-py3-none-any.whl |
|---|---|
| Size | 10.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9651f56a16633f2c4914c3ea5df8f111d0b8da8ee8cb62dfd10ca66bfa22b0f5
|
|
BLAKE2b-256 checksum How to use checksums |
7fcbaf86ee0e24c00eda691c52aa48c1b80cd333446da0cc185a73df76970940
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.
Transparency log