Skip to main content

Artifact Registry tools for Python

This repository contains an alternate keyring backend implementation to help with interacting with Python repositories hosted on Artifact Registry.

Note: This version is identical to the official keyrings.google-artifactregistry-auth package except you may set which domain to validate against. The default is the usual .pkg.dev but if you run a proxy in front of GAR, then you can set environment variable GAR_PROXY_DOMAIN and this plugin will provide tokens when uv/pip are using that proxy domain.

Why would you want to run a GAR proxy? GAR is poor at dependency confusion defense and provides no facilities for dependency cooldown. This keyring backend is motivated by the need to enhance GAR's security by putting a security concious proxy in front of it. The proxy authorizes requests by passing credential straight through to GAR, so there's no need for the proxy to have it's own auth layer.

Authentication

keyrings.google-artifactregistry-auth is a Python package which allows you to configure keyring to interact with Python repositories stored in Artifact Registry.

The backend automatically searches for credentials from the environment and authenticates to Artifact Registry. It looks for credentials in the following order:

  1. Google Application Default Credentials.
  2. From the gcloud SDK. (i.e., the access token printed via gcloud config config-helper --format='value(credential.access_token)')
    • Hint: You can see which account is active with the command gcloud config config-helper --format='value(configuration.properties.core.account)'
  3. If neither of them exist, an error occurs.

To use the keyring backend:

  1. Log in

    Option 1: log in as a service account:

    (1). Using a JSON file that contains a service account key:

    $ export GOOGLE_APPLICATION_CREDENTIALS=[path/to/key.json]
    

    (2). Or using gcloud:

    $ gcloud auth application-default login
    

    Option 2: log in as an end user via gcloud:

    $ gcloud auth login
    
  2. Configure twine (.pypirc) and pip (pip.conf) tools to connect to the repository. Use the output from the following command:

     $ gcloud artifacts print-settings python
    

    In your .pypirc file add:

    [disutils]
    index-servers =
        REPOSITORY_ID
    
    [REPOSITORY_ID]
    repository = https://LOCATION-python.pkg.dev/PROJECT_ID/REPOSITORY_ID/
    

    In your pip.conf file add:

    [global]
    index-url = https://LOCATION-python.pkg.dev/PROJECT_ID/REPOSITORY_ID/simple/
    
  3. Install the keyrings.google-artifactregistry-auth package

    $ pip install keyrings.google-artifactregistry-auth
    

    List backends to confirm the installation.

    $ keyring --list-backends
    

    The list should include

    • keyrings.gauth.GooglePythonAuth (priority: 9)
    • keyring.backends.chainer.ChainerBackend (priority: -1)
    • keyring.backends.fail.Keyring (priority: 0)

Usage with other tools

Usage with tox

The tox tool is a testing and automation tool.

Because the credential helper needs to be installed before any private dependencies are installed, it needs to be bootstrapped into the tox environment via a plugin.

To do this, specify the keyrings.google-artifactregistry-auth package via the requires requirement in your tox.ini file:

[tox]
envlist = py
requires = keyrings.google-artifactregistry-auth

[testenv]
deps = -r requirements.txt

You can then configure your requirement.txt file to use the Artifact Registry repo as the index:

--index-url https://[REGION]-python.pkg.dev/[PROJECT_ID]/[REPOSITORY]/simple

# mypackage will be installed from the Artifact Registry repository
mypackage

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

keyrings_gar_proxy_auth-2.0-py3-none-any.whl (10.5 kB view details)

Uploaded Python 3

File details

Details for the file keyrings_gar_proxy_auth-2.0-py3-none-any.whl.

File metadata

File hashes

Hashes for keyrings_gar_proxy_auth-2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f6959dd7ac9848120bb6b04244ae9698267a9f3e3a14372cfbe063ac12cf8c57
MD5 0fe43125d54fe6dce9994f04453fb994
BLAKE2b-256 16b1b709730215f6a9c1df573219a4f4a41208db8d10b500e6764d96853cda52

See more details on using hashes here.

Release history Release notifications | RSS feed

3.1

1 file

3

1 file

2.0.1

1 file

This release

2.0 This release

1 file

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page