Skip to content
ocx
install

ocx_package_repo

load("@rules_ocx//ocx:defs.bzl", "ocx_package_repo")

ocx_package_repo(name, allow_unverified, allow_yanked, bins, config, index, isolated_home,
                 no_config, ocx, package, patch_snapshot, pins, platform, resolved_platform,
                 sigstore_trusted_root)

Provisions a single OCX package from an OCI registry.

//:content is the package tree; every executable the package declares as its public surface (ocx package inspect --closure) becomes a runnable target //:<name> (host-platform repos only). A package shipping no complete binaries metadata falls back to scanning the composed PATH, which also exposes its private executables — //:env.bzl’s OCX_SCANNED_PACKAGES names the packages that forced it. For reproducibility, commit an index snapshot and reference it via index (tags then resolve frozen from the snapshot), or pin per-platform manifest digests via pins — plain floating tags resolve at fetch time and log the resolved digest.

With bins, provisioning is lazy: nothing is installed at fetch time, and each named executable becomes a launcher re-entering ocx package exec — content materializes on first execution and never becomes a Bazel action input (//:content is not available in lazy mode).

ATTRIBUTES

Name Description Type Mandatory Default
name A unique name for this repository. Name required
allow_unverified When true, sets OCX_NO_VERIFY=1 for every invocation — ocx’s own documented equivalent of --no-verify, so no verify flag is ever put on an argv. When false, OCX_NO_VERIFY=0 is written anyway, so an ambient value cannot switch verification off. It cannot switch verification on: ocx attaches that only under an operator-configured [[trust.policy]], so this attr can only decline to disable it — and no_config = True prunes the discovered tiers that policy lives in, so there is then nothing to decline and verification is off either way. Boolean optional False
allow_yanked Whether resolution may fall back to a yanked release — sets OCX_ALLOW_YANKED for every invocation. Boolean optional False
bins Lazy provisioning: names of the executables to expose (not validated at fetch time). When set, nothing is installed during the fetch — each name becomes a launcher re-entering ocx package exec, keyed on the digest-pinned reference. Requires a digest-pinned identity (pins or ‘@sha256:’); incompatible with isolated_home and index. List of strings optional []
config An ocx site config.toml (mirrors, registries, [patches]) layered over the host’s discovered config — not the project ocx.toml. Sets OCX_CONFIG for every invocation, overriding an ambient one, and the file is watched. Combine with no_config for a hermetic configuration. With bins it is copied into the repository and uploaded as an input with every action — keep credentials out of it. Label optional None
index Committed ocx index snapshot directory (created with ocx --index <dir> index update <package>). When set, tag resolution is frozen to the snapshot (--index --frozen): floating tags become reproducible until the snapshot is refreshed. Label optional None
isolated_home Keep the ocx store inside this repository instead of the shared user OCX_HOME. It also relocates OCX_HOME, so ocx’s ~/.ocx/sigstore/trusted-root.json rung is not found there — with a trust policy configured, trusted-root resolution falls through to the Rekor trust-root cache and then a live TUF fetch; offline it stops at the cache and fails outright, as ocx ships no embedded root. Boolean optional False
no_config Ignore the host’s discovered config tiers (/etc, the user config, $OCX_HOME/config.toml) and the managed-config snapshot — sets OCX_NO_CONFIG=1, and blanks an ambient OCX_CONFIG, OCX_PATCHES and OCX_PATCH_SNAPSHOT, which OCX_NO_CONFIG alone does not prune. The config and patch_snapshot attrs still apply. Use this when a corporate managed config must not reach the build; it also opts out of the exit-78 gate a required-but-unsynced managed config raises. Boolean optional False
ocx The pinned ocx CLI binary. Label optional "@ocx_tool//:ocx"
package Fully-qualified identifier: ‘registry/repo[:tag][@sha256:…]’. String required
patch_snapshot A committed patches.snapshot.json (written by ocx patch freeze next to ocx.lock) freezing the digests of the patch companions composed onto this environment. Sets OCX_PATCH_SNAPSHOT. ocx lock --check does not cover companions — without a frozen snapshot they resolve at fetch time. With bins it is copied into the repository and uploaded as an input with every action — keep credentials out of it. Label optional None
pins ocx platform key -> ‘sha256:…’ manifest digest overriding the digest of package for that platform. Dictionary: String -> String optional {}
platform ocx platform key (‘linux/amd64’, …) to provision for; empty = host. String optional ""
resolved_platform Real ocx platform sent to -p — lets a declared platform be aliased to a different real one (variant/feature build). Empty = derive from platform. Runnable-target gating compares its os/arch prefix to the host; pins still key on platform. String optional ""
sigstore_trusted_root A sigstore trusted-root.json pinned in-tree. Sets OCX_SIGSTORE_TRUSTED_ROOT for every invocation, overriding the ambient <OCX_HOME>/sigstore/trusted-root.json rung, and the file is watched. Under lazy provisioning (bins on ocx.project/ocx.package) it is copied into the repository and uploaded as an input with every action. Label optional None