Skip to content
ocx
install

Environment & exit codes: Auth

Part 2 of 3 of Environment & exit codes.

For every registry in OcxConfig.auth, the SDK writes (and first clears the full existing triple for) the slug ocx’s own registry_slug canonicalizes to:

Variable Value
OCX_AUTH_<SLUG>_TYPE basic or token
OCX_AUTH_<SLUG>_USER Only for BasicAuth.
OCX_AUTH_<SLUG>_TOKEN The password (BasicAuth) or bearer token (BearerAuth).

<SLUG> is every character outside [A-Za-z0-9] in the registry name, replaced with _, case preserved — ghcr.io becomes ghcr_io, so the SDK writes OCX_AUTH_ghcr_io_TOKEN. ocx’s own to_slug does not case-fold and neither does this. An ambient OCX_AUTH_* for a registry not named in config.auth passes through untouched; explicit configuration only overrides its own slug. The clear is case-insensitive across the whole name, so a configured ghcr.io also removes an ambient ocx_auth_ghcr_io_* rather than shipping two credential sets for one registry. Two registries that canonicalize to the same slug, or a registry that canonicalizes to an empty slug, raise OcxError rather than silently dropping or colliding credentials.

Credentials the host exported are redacted from logs and error text alongside the ones the SDK wrote, in whatever case they were spelled. The forge rungs — OCX_ANNOUNCE_TOKEN, OCX_ANNOUNCE_GIT_TOKEN, CI_JOB_TOKEN — are redacted the same way, ambient or configured.

Propagation: ocx does not scrub non-forwarded variables from a spawned child’s environment, so a tool started through Project.exec or package.exec inherits OCX_AUTH_*. See Errors & credentials for the credential-free pattern.

Read by bootstrap.ensure, one rung below its explicit keyword arguments and one above its own defaults. Never written by the SDK.

This is the same OCX_INSTALL_* grammar setup.ocx.sh defines, so an environment already configured for the shell installer needs no code change here — export the variable and bootstrap.ensure() picks it up. The two exceptions are called out as No-op below, and the setup script’s remaining variables (OCX_INSTALL_NO_SETUP, OCX_INSTALL_NO_SMOKETEST, OCX_INSTALL_PRINT_PATH, OCX_INSTALL_DOWNLOADER, OCX_NO_MODIFY_PATH) have no meaning here: this SDK never runs setup, never prints, never modifies PATH, and has no curl-or-wget choice to make.

Variable ensure() argument
OCX_INSTALL_VERSION version — pins an exact release. Empty or unset takes the channel’s latest.
OCX_INSTALL_DIST_URL consulted by the default DistSource only — an explicitly constructed one does not honor it
OCX_INSTALL_MIRROR_URL mirror_url — relocates the artifact host, as <mirror_url>/<tag>/<filename>. The manifest digest is still enforced, so a mirror moves bytes and never revalidates them; the manifest itself keeps coming from dist. Setting this makes the manifest sha256= mandatory — see the off-canonical rule.
OCX_INSTALL_CA_BUNDLE ca_bundle — a PEM file trusted for the manifest and artifact downloads instead of the system store, for a TLS-intercepting proxy. Transport trust only: the manifest pin and the artifact digest are still enforced, so the bundle changes who may serve the bytes, never which bytes are accepted.
OCX_INSTALL_REPO No-op. Listed for grammar parity with the setup script’s OCX_INSTALL_* vars only — this SDK resolves artifact URLs from the manifest, never from a GitHub repository guess.
OCX_INSTALL_FORCE no argument — forces a fresh download and install even when the cache already holds a correct binary
OCX_INSTALL_QUIET No-op. Listed for grammar parity only — this module never prints, so there is nothing to quiet.

Continues on Environment & exit codes: Discovery.