Skip to main content

vocker

Manager for complete Python environments written with security in mind. Mostly for Windows.

Why

OK so here's a typical experience. You're working on different Python projects which require incompatible versions of dependencies. For example, one of them needs libfoo==1.0.0 and the other needs libfoo>3.0.0. There's just no way to satisfy both. Python people encourage you to create different virtualenvs ("venvs") for different purposes. Sometimes a user reports a bug that they experience with some very specific version of a dependency, so you need to create yet another venv just to investigate that.

Here's a problem: every venv you install takes up a few hundred megabytes of disk space, and a lot of it is for completely redundant files. You were conned into buying an overpriced non-modular computer, so now your tiny non-upgradeable SSD space is now filled with many copies of the same files. You regret your life choices. Wouldn't it be nice if the duplicate files across different venvs didn't take up any additional space?

Users often report bugs against very specific versions of your software, and the café you work at has pretty slow WiFi. Installing hundreds of megabytes of the same packages over and over quickly grows tiresome. Wouldn't it be nice if you could just copy an existing venv and just tweak it a bit, for example replace the few packages that are actually different?

Finally, some of your nontechnical users refuse to compile and install their own software, but they do want to sometimes have multiple versions installed for testing purposes. However, they also bought non-upgradeable hardware so they don't want multiple copies of the same files that are identical across different versions of the software. Wouldn't it be nice if installing a new venv somehow recycled the existing files from the currently-installed venvs?

Some of your users are paranoid about security. Wouldn't it be nice if the software integrity of the venv-based software package were guaranteed through hashing and Merkle trees?

That's why.

Goals

  • Developers can easily create images, and then distribute them to users who use them to run applications. The users don't necessarily use vocker directly to create containers, they may use some extra layer on top of it (like an installer that provides a GUI and maybe digital signature verification).
  • Developers can easily create images from existing images by tweaking whatever needs to be different. For example, installing new software or modifying files.
  • Image creation should be reproducible. That is, creating a Python environment and then turning it into an image should give you exactly the same image if you do that a second time. The resulting image hash should be identical.
  • Developers can easily audit existing images by just rebuilding them from scratch and checking whether the final result is the same.

Non-goals

  • Digital signature verification.

Metadata

Release files for vocker 0.6.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vocker 0.6.2
File Size Uploaded
vocker-0.6.2.tar.gz 76.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vocker 0.6.2
File Interpreter ABI Platform
vocker-0.6.2-py3-none-any.whl Python 3 none any Details

Total release size: 136.1 kB

Release files / vocker-0.6.2.tar.gz

Download URL vocker-0.6.2.tar.gz
Size 76.0 kB
Tags Source
SHA-256 checksum
How to use checksums
038f5617973375adaaea4e428cd3fde807d4290f149cb36d820dc711b4dcac3a
BLAKE2b-256 checksum
How to use checksums
5c17a8c5ac81ef126cdc3821ba7d3399e02cb0641c7327066ae39ad8b504ae5a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release files / vocker-0.6.2-py3-none-any.whl

Download URL vocker-0.6.2-py3-none-any.whl
Size 60.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a33ebbbb5b36fed9e34d214371ae828026e2ab70efd1575aa6d5d162836a735c
BLAKE2b-256 checksum
How to use checksums
1dd7dafa6aaefa4bca67804442ba8f7d24857ff5fc4c4edd0d298dc7379c02b4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.6.2 This release

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page