terok-util
Shared utility library for the terok-*
sibling packages.
terok-util sits at the bottom of the terok dependency chain: every
sibling package depends on it, and it depends on nothing else in the
ecosystem. It collects the small set of cross-cutting bits that would
otherwise be duplicated (or quietly diverge) across
terok-shield,
terok-clearance,
terok-sandbox,
terok-executor, and
terok.
What's in the box
| Module | Use case |
|---|---|
cli_types |
CommandDef / ArgDef / CommandTree — argparse-driven CLI registry types used by every sibling that exposes a CLI tree. |
fs |
ensure_dir, ensure_dir_writable, write_sensitive_file (atomic O_CREAT | O_EXCL 0o600 writer). |
paths |
namespace_state_dir, namespace_config_dir, namespace_runtime_dir — XDG-aware path resolution for a per-namespace deployment. |
config_stack |
ConfigStack + deep_merge — layered round-trip YAML config merge engine. |
security |
sanitize_tty — strips C0 / C1 / ANSI sequences from untrusted strings before rendering to the operator's terminal (CWE-150 mitigation). |
podman |
podman_userns_args — rootless --userns=keep-id:uid=1000,gid=1000 builder. |
Installation
pip install terok-util
The package is published as a Python wheel; siblings pin to a specific
GitHub-release wheel URL via pyproject.toml.
Convention
The rule for what belongs here: if two or more terok-* packages
need it, it lives in terok-util. Single-package helpers stay in
the package that owns them. The __all__ declaration in
src/terok_util/__init__.py is the contract — symbols listed there
are stable across minor releases.
License
Apache-2.0. See LICENSE.
Metadata
Release files for terok-util 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| terok_util-0.4.0.tar.gz | 271.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| terok_util-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 393.6 kB
Release files / terok_util-0.4.0.tar.gz
| Download URL | terok_util-0.4.0.tar.gz |
|---|---|
| Size | 271.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f1cc2f48ba533ab81637004930533d745f6fa16a238f2390932ed816032594a2
|
|
BLAKE2b-256 checksum How to use checksums |
b7330e510df33e177b6ae1ab7e182147ad19cd33dacebf4a863ba3b931a13758
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / terok_util-0.4.0-py3-none-any.whl
| Download URL | terok_util-0.4.0-py3-none-any.whl |
|---|---|
| Size | 122.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6b2956b3e407feaefc037aa6d7c92368cd434295538464be2833f06079b4d2d9
|
|
BLAKE2b-256 checksum How to use checksums |
d3df68c7f2ce096f7ebfc5d4664ee1ba9dbf043ca6e7777b6701bfd25ed2300c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log