This project has been archived by its maintainers, and is no longer receiving any updates.
git-buckets-keyring
A stateless keyring backend for git-buckets package registries. It turns
your ambient AWS profile into a short-lived package token so uv sync and pip install can reach a private
index with no login step.
It stores nothing. On each lookup it SigV4-signs an sts:GetCallerIdentity call with your profile, trades that
proof for a 1-hour token at https://<host>/auth/token, and hands the token to the client as the HTTP Basic
password. Tokens are cached in-process only, never on disk.
Setup
Once per machine:
uv tool install git-buckets-keyring
export UV_KEYRING_PROVIDER=subprocess # or tool.uv.keyring-provider = "subprocess"
export GB_KEYRING_HOSTS=git.example.cloud # hosts this backend is allowed to answer for
export GB_KEYRING_PROFILE=my-profile # optional: the AWS profile to mint with
Then in the consuming project's pyproject.toml:
[[tool.uv.index]]
name = "demos"
url = "https://gb@git.example.cloud/packages/demos/pypi/"
explicit = true
[tool.uv.sources]
demos-cli = { index = "demos" }
The gb@ in the URL is load-bearing: uv only performs keyring discovery when the index URL carries a username.
GB_KEYRING_HOSTS
A comma-separated allowlist of hostnames, empty by default. The backend returns None for every host that is not
listed, and for every username other than gb, so it is inert on other machines and other indexes. It is an
allowlist, not a target: the host used is the one the client asked about, admitted only if it is listed.
GB_KEYRING_PROFILE
The AWS profile to mint with, overriding AWS_PROFILE and the rest of the default chain. Unset, the backend uses
the ambient session as before. Set it when a project works against one AWS account while pulling packages entitled
through another, so AWS_PROFILE is already pointed somewhere else. A profile that does not exist is treated like
any other failure: no token, no exception.
GB_KEYRING_DEBUG
Set to anything non-empty to have the backend print one line on stderr explaining why it declined — wrong
username, host not on the allowlist, or the mint failed and why. Off by default, and stdout stays clean either way
so keyring get output is still just the token. The token is never printed to stderr.
Printing a token by hand
keyring get https://git.example.cloud/packages/demos/pypi/ gb
If the bundled keyring script collides
uv tool install git-buckets-keyring installs a keyring executable of its own. If that clashes with an existing
one, install the other way round:
uv tool install keyring --with git-buckets-keyring
Release files for git-buckets-keyring 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| git_buckets_keyring-0.1.2.tar.gz | 9.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| git_buckets_keyring-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.2 kB
Release files / git_buckets_keyring-0.1.2.tar.gz
| Download URL | git_buckets_keyring-0.1.2.tar.gz |
|---|---|
| Size | 9.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ea2f6319b73fc7529424bca8d98de73ca81c9d21d33761231480efec73858504
|
|
BLAKE2b-256 checksum How to use checksums |
8cfd62a381ac1db2a548657b0448f68f21e83c41f271190cdfd177612823d6e5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.
Transparency logRelease files / git_buckets_keyring-0.1.2-py3-none-any.whl
| Download URL | git_buckets_keyring-0.1.2-py3-none-any.whl |
|---|---|
| Size | 11.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
56346ede87b644d4260d3e3fcb8d10f9d2a323193709f00d0df593966652a9d3
|
|
BLAKE2b-256 checksum How to use checksums |
2dc0cc4883feb7d68c7967c74f89656e9e9d10bf6cbad4e0dca9a020eee8e0a3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.
Transparency log