- integrations
- Python
- Environment & exit codes: Auth
Environment & exit codes: Auth
Part 2 of 3 of Environment & exit codes.
Auth — OCX_AUTH_<SLUG>_*
Section titled “Auth — OCX_AUTH_<SLUG>_*”For every registry in OcxConfig.auth, the SDK writes (and first clears the
full existing triple for) the slug ocx’s own registry_slug canonicalizes
to:
| Variable | Value |
|---|---|
OCX_AUTH_<SLUG>_TYPE |
basic or token |
OCX_AUTH_<SLUG>_USER |
Only for BasicAuth. |
OCX_AUTH_<SLUG>_TOKEN |
The password (BasicAuth) or bearer token (BearerAuth). |
<SLUG> is every character outside [A-Za-z0-9] in the registry name,
replaced with _, case preserved — ghcr.io becomes ghcr_io, so the
SDK writes OCX_AUTH_ghcr_io_TOKEN. ocx’s own to_slug does not case-fold
and neither does this. An ambient OCX_AUTH_* for
a registry not named in config.auth passes through untouched; explicit
configuration only overrides its own slug. The clear is case-insensitive
across the whole name, so a configured ghcr.io also removes an ambient
ocx_auth_ghcr_io_* rather than shipping two credential sets for one
registry. Two registries that canonicalize to the same slug, or a registry
that canonicalizes to an empty slug, raise OcxError rather than silently
dropping or colliding credentials.
Credentials the host exported are redacted from logs and error text
alongside the ones the SDK wrote, in whatever case they were spelled. The
forge rungs — OCX_ANNOUNCE_TOKEN, OCX_ANNOUNCE_GIT_TOKEN, CI_JOB_TOKEN
— are redacted the same way, ambient or configured.
Propagation: ocx does not scrub non-forwarded variables from a spawned
child’s environment, so a tool started through Project.exec or
package.exec inherits OCX_AUTH_*. See
Errors & credentials for the
credential-free pattern.
Bootstrap-only — OCX_INSTALL_*
Section titled “Bootstrap-only — OCX_INSTALL_*”Read by bootstrap.ensure, one rung below
its explicit keyword arguments and one above its own defaults. Never written
by the SDK.
This is the same OCX_INSTALL_* grammar
setup.ocx.sh defines, so an environment already
configured for the shell installer needs no code change here — export the
variable and bootstrap.ensure() picks it up. The two exceptions are called
out as No-op below, and the setup script’s remaining variables
(OCX_INSTALL_NO_SETUP, OCX_INSTALL_NO_SMOKETEST, OCX_INSTALL_PRINT_PATH,
OCX_INSTALL_DOWNLOADER, OCX_NO_MODIFY_PATH) have no meaning here: this SDK
never runs setup, never prints, never modifies PATH, and has no
curl-or-wget choice to make.
| Variable | ensure() argument |
|---|---|
OCX_INSTALL_VERSION |
version — pins an exact release. Empty or unset takes the channel’s latest. |
OCX_INSTALL_DIST_URL |
consulted by the default DistSource only — an explicitly constructed one does not honor it |
OCX_INSTALL_MIRROR_URL |
mirror_url — relocates the artifact host, as <mirror_url>/<tag>/<filename>. The manifest digest is still enforced, so a mirror moves bytes and never revalidates them; the manifest itself keeps coming from dist. Setting this makes the manifest sha256= mandatory — see the off-canonical rule. |
OCX_INSTALL_CA_BUNDLE |
ca_bundle — a PEM file trusted for the manifest and artifact downloads instead of the system store, for a TLS-intercepting proxy. Transport trust only: the manifest pin and the artifact digest are still enforced, so the bundle changes who may serve the bytes, never which bytes are accepted. |
OCX_INSTALL_REPO |
No-op. Listed for grammar parity with the setup script’s OCX_INSTALL_* vars only — this SDK resolves artifact URLs from the manifest, never from a GitHub repository guess. |
OCX_INSTALL_FORCE |
no argument — forces a fresh download and install even when the cache already holds a correct binary |
OCX_INSTALL_QUIET |
No-op. Listed for grammar parity only — this module never prints, so there is nothing to quiet. |
Continues on Environment & exit codes: Discovery.