# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.ConfigOverrides

*class*

```python
class ConfigOverrides(TypedDict)
```

Bases: `TypedDict`

Re-exported from: `ocx_sdk._config`

The `OcxConfig` fields a `with_config` call may replace, all optional.

What makes `Ocx.with_config(...)` and `Project.with_config(...)` check
their keyword arguments instead of accepting `**overrides: Any`, so a
misspelled field is a type error rather than a `TypeError` at runtime.
Public for the same reason `MaybeRetry` is: a wrapper around this SDK can
forward a caller's overrides with `**overrides: Unpack[ConfigOverrides]`
rather than re-declaring the field list itself.

Mirrors `OcxConfig` field for field — a field added there and not here is
a field `with_config` would refuse.

Optional at the class level rather than per field: this module postpones
annotation evaluation, and a `NotRequired[...]` inside a string annotation
is invisible to `__required_keys__`, so anything introspecting the type at
runtime would be told every field was mandatory. Every field is optional
here anyway, which is exactly what `total=False` says.

> **Example**
>
> ```python
> from typing import Unpack
> 
> from ocx_sdk import ConfigOverrides, Ocx
> 
> 
> def hermetic(ocx: Ocx, **overrides: Unpack[ConfigOverrides]) -> Ocx:
>     return ocx.with_config(no_config=True, **overrides)
> ```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L40-L95)

### ocx_sdk.ConfigOverrides.auth

*attribute* · *instance attribute*

```python
auth: Mapping[str, Auth]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L77-L77)

### ocx_sdk.ConfigOverrides.config

*attribute* · *instance attribute*

```python
config: Path | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L74-L74)

### ocx_sdk.ConfigOverrides.consent

*attribute* · *instance attribute*

```python
consent: bool
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L87-L87)

### ocx_sdk.ConfigOverrides.index

*attribute* · *instance attribute*

```python
index: Path | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L81-L81)

### ocx_sdk.ConfigOverrides.insecure_registries

*attribute* · *instance attribute*

```python
insecure_registries: Collection[str] | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L78-L78)

### ocx_sdk.ConfigOverrides.jobs

*attribute* · *instance attribute*

```python
jobs: int | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L82-L82)

### ocx_sdk.ConfigOverrides.log_level

*attribute* · *instance attribute*

```python
log_level: LogLevel | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L83-L83)

### ocx_sdk.ConfigOverrides.no_update_check

*attribute* · *instance attribute*

```python
no_update_check: bool
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L85-L85)

### ocx_sdk.ConfigOverrides.offline

*attribute* · *instance attribute*

```python
offline: bool
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L72-L72)

### ocx_sdk.ConfigOverrides.records_dir

*attribute* · *instance attribute*

```python
records_dir: Path | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L88-L88)

### ocx_sdk.ConfigOverrides.records_name

*attribute* · *instance attribute*

```python
records_name: str | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L89-L89)

### ocx_sdk.ConfigOverrides.retry

*attribute* · *instance attribute*

```python
retry: RetryPolicy | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L94-L94)

### ocx_sdk.ConfigOverrides.sigstore_trusted_root

*attribute* · *instance attribute*

```python
sigstore_trusted_root: str | Path | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_config.py#L79-L79)
