# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.Project

*class* · *dataclass*

```python
class Project
```

Re-exported from: `ocx_sdk._client`

A project-tier handle: every call carries `--project <file>`.

Obtained from `Ocx.project(path)`, never constructed directly. Because
the path travels explicitly on every call, no method depends on the
working directory, and an ambient `OCX_PROJECT` can never retarget one.
`init` is the exception, and only because ocx's is: it takes no flags and
writes into the working directory, so the handle sets that instead.

> **Example**
>
> ```python
> from ocx_sdk import Ocx
> 
> project = Ocx().project("/srv/build")
> project.add("ocx.sh/go-task/task:3", group="ci")
> project.lock()
> report = project.env()
> environment = report.compose().mapping
> ```

**Attributes**

- `path` (`Path`) — The absolute project file — the `ocx.toml` itself, which is what ocx's `--project` names.
- `session_config` (`OcxConfig`) — The `OcxConfig` every call spawns under.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L860-L1467)

### ocx_sdk.Project.init

*method*

```python
def init(timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> CommandResult
```

Create a minimal `ocx.toml` in the project directory.

The one project-tier call that carries no `--project`: `ocx init`
takes no flags and writes into the working directory, and naming a
project would ask ocx to resolve the very file the call exists to
create. This runs it with the project's directory as its `cwd`
instead, so the file lands where the handle points rather than
wherever the caller happens to be.

Returns the raw result: ocx pins no JSON payload for `init`, so there
is nothing to type yet.

**Parameters**

- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`CommandResult`) — The exit code and whatever ocx printed.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L933-L953)

### ocx_sdk.Project.lock

*method*

```python
def lock(check_only: bool = False, pull: bool | None = None, platform: str | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> tuple[ToolRow, ...] | None
```

Resolve declared tags to digests and write `ocx.lock`.

**Parameters**

- `check_only` (`bool`) (default: `False`) — Verify the lock is current and write nothing — ocx's `--check`. Drift raises `DataError`; a missing lock raises `ConfigError`. Named apart from the `check=` on `run`, which is the `subprocess.run` sense of "raise on a non-zero exit".
- `pull` (`bool | None`) (default: `None`) — Materialize the resolved packages. `None` leaves the choice to ocx's own default.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`tuple[ToolRow, ...] | None`) — The lock rows written, or `None` under `check_only` — ocx reports
- (`tuple[ToolRow, ...] | None`) — a current lock with exit 0 and an empty body.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1010-L1042)

### ocx_sdk.Project.pull

*method*

```python
def pull(dry_run: bool = False, groups: Iterable[str] = (), platform: str | None = None, lazy_mode: LazyMode | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> PullReport | tuple[DryRunEntry, ...]
```

Pre-warm the object store from `ocx.lock`.

**Parameters**

- `dry_run` (`bool`) (default: `False`) — Report what would be fetched without writing. Changes the return type: ocx previews with a different upstream report at a different JSON root, so this answers a tuple of `DryRunEntry` rows rather than a `PullReport`.
- `groups` (`Iterable[str]`) (default: `()`) — Groups to restrict the pull to.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`PullReport | tuple[DryRunEntry, ...]`) — The materialized paths and any advisories — or, under `dry_run`,
- (`PullReport | tuple[DryRunEntry, ...]`) — one row per package describing what a real pull would do.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1104-L1139)
