Skip to main content

Automatically update Python Eggs on application startup – or, you know, whenever, really.

Overview

The idea behind this module is to support self-updating Python applications, namely command-line tools. Transmute probes remote repositories for updated components, fetches updates and adds them to sys.path, making them available for use in the application.

Components are assumed to be standard Python Eggs. Repositories are then simple containers for these eggs. Currently PyPI and S3 “folders” are supported as repositories. (Mostly for testing purposes, local directories are also supported as repositories).

Under the hood, pkg_resources (from setuptools) is used to parse and fulfill requirements, based on listings of available eggs obtained from each repository. Once updated packages are made available, their modules can be imported or the application can be re-launched with an adjusted environment to pick up updated modules.

The application writer controls the packages to update, repositories each package will be grabbed from, and when an update is actioned.

The philosophy has been that an absent or flaky network should not prevent (or significantly delay) an application from running on top of outdated packages, if they’ve been cached locally. That said, there are currently no provisions for testing and verifying a successful update or rolling back a failed update.

Example

This is a script that requests the ‘hello’ package to be updated from the dist folder in the current working directory:

import transmute

transmute.require([ 'hello' ], sources=[ 'dist' ])
transmute.update()

import hello
hello.greet('world')

Bootstrapping an application with bootstrap.py

The submodule in `transmute/bootstrap.py <https://github.com/comoyo/python-transmute/blob/master/transmute/bootstrap.py>`__ can be used on its own to bootstrap other Python modules and applications. It is capable of downloading packages from PyPI. In this way, transmute itself can be loaded and further used to download additional packages.

The script provides a bunch of hooks where users can place their code. In particular, main() can be filled in to fetch application specific packages and actually launch the application. At the point it is called transmute has been added to sys.path (after downloading from PyPI, if needed).

def main():
    import transmute
    import transmute.s3

    transmute.require([ 'foobar' ],
            sources=[ 's3://foobar-repository/eggs/foobar' ])
    transmute.update()

    import foobar.cli
    return foobar.cli.run()

It can also be used as a placeholder for a Python module. If the module itself is available from PyPI, the corresponding package name would be added to the requirements variable. For other use cases, I sense a pull request coming :-)

At the time of this writing, the only non-standard dependency of the script is the pkg_resources module from the setuptools package. The assumption here is that the module is more or less available everywhere. If this turns out to be a problem in practice, I suppose the script could be simplified to not require it.

Supported package formats

Currently, only standard Python eggs are supported. I don’t mind adding support for other formats, formats supported natively by Python are preferred.

In that regard, source tarballs look particularly interesting for pure Python packages, and seem to be more generally available from PyPI. Unpacking and importing the packages locally could be a way forward.

Python wheels also look interesting and gaining some traction.

Supported repositories

Local repositories

Just a directory with eggs in it. This is mostly useful for testing.

transmute.require([ 'foobar' ], sources=[ '/opt/basket' ])

PyPI

Transmute supports PyPI’s PyPIJSON interface.

transmute.require([ 'foobar' ], sources=[ transmute.PYPI_SOURCE ])

Amazon Simple Storage Service (S3)

Packages can be uploaded to a directory in S3.

While technically Amazon’s S3 doesn’t have the concept of a folder, the slash ('/') in S3 key names is abused to sustain the illusion of directories.

Credentials can be provided as environment variables. transmute recognizes a few fairly standard variables:

- AWS_CREDENTIAL_FILE
- AWS_ACCESS_KEY, AWS_SECRET_KEY, and (optionally) AWS_SECURITY_TOKEN
- AWS_DEFAULT_REGION and EC2_REGION

When running in an EC2 instance, transmute may also pick credentials from the IAM role associated with it.

import transmute.s3
transmute.require([ 'foobar' ], sources=[ 's3://bucket/key-prefix' ])

Missing a repository format?

I’m missing a pull request. :-)

Open issues

  • Logging is sorely missing. This can be helpful in debugging, but also to keep track of updates and possibly tie in to enabling rollbacks.

  • Rolling back a b0rked update.

  • Provide hooks for verifying an update before activating it.

  • We shouldn’t use the network on every run of a given command. Keeping track of metadata about repository queries would allow us to limit updates to daily or weekly schedules.

  • Currently MD5 hashes are used to verify integrity of downloaded packages, as advertised by repositories. It would be nice to be able to verify package signatures.

  • Your pet peeve?

Metadata

Release files for transmute 5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for transmute 5.0
File Size Uploaded
transmute-5.0.tar.gz 14.2 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for transmute 5.0
File Interpreter ABI Platform
transmute-5.0-py2.7.egg Legacy Egg format - - Details
transmute-5.0-py2.6.egg Legacy Egg format - - Details

Total release size: 65.2 kB

Release files / transmute-5.0.tar.gz

Download URL transmute-5.0.tar.gz
Size 14.2 kB
Tags Source
SHA-256 checksum
How to use checksums
aa6be7418705807deb88da293ab7d9524c30edd4f5d339b6adaa2ef62a3e20c4
BLAKE2b-256 checksum
How to use checksums
ed4c512163d96411f67d90c52f102f53fc261c37be1718ffed5f013c54b8bda2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / transmute-5.0-py2.7.egg

Download URL transmute-5.0-py2.7.egg
Size 25.5 kB
Tags Egg
SHA-256 checksum
How to use checksums
9289159f1d34826ed7fcd929a2170df6c6e9170a433b7f87ee6d816768719d46
BLAKE2b-256 checksum
How to use checksums
0803c68c6b9bcb5bb9be15d77bb2fd148f1df622cfee19205d0ca82523bfc20a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / transmute-5.0-py2.6.egg

Download URL transmute-5.0-py2.6.egg
Size 25.6 kB
Tags Egg
SHA-256 checksum
How to use checksums
d32ef03122e04e998d514b6ebf34760c7007201fd76302de2c12aaf276a1435a
BLAKE2b-256 checksum
How to use checksums
3ff8805b0ea690d95d37db560dd5f2d3fbffa0270e8c712497209edc8060fb05
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

5.0 This release

3 release files

4

2 release files

3.1

2 release files

3

2 release files

2

2 release files

1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page