Skip to main content
Archived

This project has been archived by its maintainers, and is no longer receiving any updates.

git-buckets-keyring

A stateless keyring backend for git-buckets package registries. It turns your ambient AWS profile into a short-lived package token so uv sync and pip install can reach a private index with no login step.

It stores nothing. On each lookup it SigV4-signs an sts:GetCallerIdentity call with your profile, trades that proof for a 1-hour token at https://<host>/auth/token, and hands the token to the client as the HTTP Basic password. Tokens are cached in-process only, never on disk.

Setup

Once per machine:

uv tool install git-buckets-keyring
export UV_KEYRING_PROVIDER=subprocess         # or tool.uv.keyring-provider = "subprocess"
export GB_KEYRING_HOSTS=git.example.cloud     # hosts this backend is allowed to answer for
export GB_KEYRING_PROFILE=my-profile          # optional: the AWS profile to mint with

Then in the consuming project's pyproject.toml:

[[tool.uv.index]]
name = "demos"
url = "https://gb@git.example.cloud/packages/demos/pypi/"
explicit = true

[tool.uv.sources]
demos-cli = { index = "demos" }

The gb@ in the URL is load-bearing: uv only performs keyring discovery when the index URL carries a username.

GB_KEYRING_HOSTS

A comma-separated allowlist of hostnames, empty by default. The backend returns None for every host that is not listed, and for every username other than gb, so it is inert on other machines and other indexes. It is an allowlist, not a target: the host used is the one the client asked about, admitted only if it is listed.

GB_KEYRING_PROFILE

The AWS profile to mint with, overriding AWS_PROFILE and the rest of the default chain. Unset, the backend uses the ambient session as before. Set it when a project works against one AWS account while pulling packages entitled through another, so AWS_PROFILE is already pointed somewhere else. A profile that does not exist is treated like any other failure: no token, no exception.

GB_KEYRING_DEBUG

Set to anything non-empty to have the backend print one line on stderr explaining why it declined — wrong username, host not on the allowlist, or the mint failed and why. Off by default, and stdout stays clean either way so keyring get output is still just the token. The token is never printed to stderr.

Printing a token by hand

keyring get https://git.example.cloud/packages/demos/pypi/ gb

If the bundled keyring script collides

uv tool install git-buckets-keyring installs a keyring executable of its own. If that clashes with an existing one, install the other way round:

uv tool install keyring --with git-buckets-keyring

Release files for git-buckets-keyring 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for git-buckets-keyring 0.1.2
File Size Uploaded
git_buckets_keyring-0.1.2.tar.gz 9.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for git-buckets-keyring 0.1.2
File Interpreter ABI Platform
git_buckets_keyring-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 20.2 kB

Release files / git_buckets_keyring-0.1.2.tar.gz

Download URL git_buckets_keyring-0.1.2.tar.gz
Size 9.1 kB
Tags Source
SHA-256 checksum
How to use checksums
ea2f6319b73fc7529424bca8d98de73ca81c9d21d33761231480efec73858504
BLAKE2b-256 checksum
How to use checksums
8cfd62a381ac1db2a548657b0448f68f21e83c41f271190cdfd177612823d6e5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release files / git_buckets_keyring-0.1.2-py3-none-any.whl

Download URL git_buckets_keyring-0.1.2-py3-none-any.whl
Size 11.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
56346ede87b644d4260d3e3fcb8d10f9d2a323193709f00d0df593966652a9d3
BLAKE2b-256 checksum
How to use checksums
2dc0cc4883feb7d68c7967c74f89656e9e9d10bf6cbad4e0dca9a020eee8e0a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page