- integrations
- CMake
- Guides
- Build behind a mirror or offline
Build behind a mirror or offline
Use these variables to run a configure in a corporate or air-gapped environment. They are the same knobs as the setup.ocx.sh installer and rules_ocx.
Every variable follows the snapshot pattern. A CMake cache variable wins, otherwise the environment value at the first configure is stored in the cache and stays for that build directory.
Mirror the ocx download
Section titled “Mirror the ocx download”- Set
OCX_INSTALL_DIST_URLto fetch the release manifest from your mirror instead of the embedded snapshot. - Set
OCX_INSTALL_MIRROR_URLto rewrite the binary download to<mirror>/<tag>/<filename>.
The manifest sha256 is still enforced, so a mirror can move bytes but not change them.
Mirror the packages
Section titled “Mirror the packages”Set OCX_MIRRORS to a JSON map such as {"ocx.sh": "https://mirror.corp/ocx"}.
Package pulls go to the mirror, and lock digests stay keyed to the upstream host.
Set OCX_INSECURE_REGISTRIES to a comma list when a mirror speaks plain HTTP.
Pass credentials
Section titled “Pass credentials”Export OCX_AUTH_<REGISTRY>_TYPE, OCX_AUTH_<REGISTRY>_USER and OCX_AUTH_<REGISTRY>_TOKEN in the environment.
These are never stored in CMakeCache.txt, so reconfigure after you change them.
Forbid configure-time downloads
Section titled “Forbid configure-time downloads”Set -DOCX_BOOTSTRAP=OFF and provide a binary with OCX_EXECUTABLE or on PATH.
Any other case is a hard configure error with an actionable message.
Set OCX_OFFLINE to run without network access once the local store holds the content.
Clear a knob
Section titled “Clear a knob”Pass -DVAR= to remove a value from the environment of every ocx call.
The passthrough variables are OCX_HOME, OCX_MIRRORS, OCX_INSECURE_REGISTRIES, OCX_OFFLINE, OCX_FROZEN, OCX_REMOTE, OCX_JOBS, OCX_INDEX and OCX_DEFAULT_REGISTRY.
For the vendored files themselves, see Update the vendored files. Needs addressed: problem 7 of the use-case research.