- integrations
- Python
- ocx_sdk
SignatureFormat to ensure
SignatureFormatattribute#
ocx_sdk._typesView sourceSignatureFormatocx --signature-format values. A Literal because nothing but argv consumes it.
TESTED_OCX_VERSIONattributemodule attribute#
ocx_sdk._typesView sourceTESTED_OCX_VERSION: Final = '0.6.2'The ocx version this SDK’s contract tests run against.
Transportattribute#
ocx_sdk._clientView sourceTransportocx --transport values — how a forge write is made. git is GitLab-only.
UNSETattributemodule attribute#
ocx_sdk._clientView sourceUNSET: Final = _Unset.TOKENThe default for every per-call retry=/timeout=, meaning “not given”.
Public so that a wrapper around this SDK can pass a caller’s override
straight through without having to invent its own three-state sentinel:
def deploy(*, retry: MaybeRetry = UNSET): ocx.package.push(..., retry=retry).
ensurefunction#
ocx_sdk._bootstrapView sourcedef ensure(version: str | None = None, *, channel: Channel = Channel.STABLE, dist: _dist.DistSource | None = None, mirror_url: str | None = None, ca_bundle: str | None = None, min_version: str | None = None, cache_dir: Path | None = None, env: HostEnv | None = None, trust_cache: bool = False, retry: RetryPolicy | None = None, timeout: float | None = None) -> PathProvision a verified ocx binary and return its path.
Idempotent and offline-friendly: a cache hit that still hashes correctly
needs no network at all. Every knob resolves explicit argument first, then
the matching OCX_INSTALL_* variable from env, then the default.
Parameters
| Name | Type | Default | Description |
|---|---|---|---|
version | str | None | None | Exact version to install. None takes the channel’s latest,
then OCX_INSTALL_VERSION. |
channel | Channel | Channel.STABLE | Channel consulted when version is None. No variable — the
setup script has none either. |
dist | _dist.DistSource | None | None | Where the manifest comes from. None builds the default source,
which honors OCX_INSTALL_DIST_URL; an explicitly constructed
source does not. |
mirror_url | str | None | None | Base URL that replaces the artifact host, as
<mirror_url>/<tag>/<filename>, falling back to
OCX_INSTALL_MIRROR_URL. The manifest digest is still enforced —
a mirror relocates bytes, it never revalidates them. |
ca_bundle | str | None | None | PEM file trusted for every download, replacing the system
trust store, falling back to OCX_INSTALL_CA_BUNDLE. For a
TLS-intercepting proxy; the digest checks are unaffected. |
min_version | str | None | None | Operator floor. A resolved version below it fails loudly instead of installing something older than the caller allows. |
cache_dir | Path | None | None | Cache root. None uses the per-user cache directory. |
env | HostEnv | None | None | Environment snapshot. None reads the ambient one. |
trust_cache | bool | False | Skip the digest re-check on a cache hit. Orthogonal to
OCX_INSTALL_FORCE, which reinstalls even on a cache hit and has
no argument of its own. |
retry | RetryPolicy | None | None | Policy for transient transport failures; None tries once. |
timeout | float | None | None | Per-attempt network budget in seconds. |
Returns
Path- Path to the installed binary, mode
0o700.
Raises
BootstrapError- The cache root is untrusted, or the resolved version is
below
min_version. DistManifestError- The manifest is unusable, or its archive is.
UnsupportedPlatformError- No release matches this platform.
ChecksumMismatchError- Downloaded bytes do not match the manifest. Never retried — the bytes are wrong, not late.
DownloadError- The manifest or artifact could not be fetched, or the CA bundle could not be loaded.