Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 36 additions & 13 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -651,7 +651,7 @@ jobs:
# https://github.com/prefix-dev/pixi/issues/330
if: matrix.os == 'ubuntu-latest'

persist-credentials-false:
auth-logout-after-install:
env:
# We must set this environment variable explicitly to force all
# operating systems to use the same storage mechanism.
Expand All @@ -668,34 +668,57 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Move pixi.toml
run: mv test/default/* .
# Sanity check: Login with default persist-credentials behavior
# auth-logout: post and never are tested in auth-logout-post-never
- uses: ./
with:
cache: false
auth-host: https://custom-conda-registry.com
auth-token: custom-token
- name: Assert that the credentials are stored
auth-logout: after-install
- name: Assert that the credentials are not stored anymore
run: |
# For human log readers
cat "${RATTLER_AUTH_FILE}"

# Actual test
[ $(jq '."*.custom-conda-registry.com".BearerToken' -r "${RATTLER_AUTH_FILE}") = "custom-token" ]
- name: Clean up credentials file
run: rm "${RATTLER_AUTH_FILE}"
# Actual test: Login with persist-credentials: false
! grep -q '"*.custom-conda-registry.com"' "${RATTLER_AUTH_FILE}"

auth-logout-post-never:
env:
# We must set this environment variable explicitly to force all
# operating systems to use the same storage mechanism.
# Otherwise, mac will use the keychain, which is more cumbersome to test.
RATTLER_AUTH_FILE: .rattler-credentials.json
strategy:
matrix:
# action-post-run doesn't support bash on windows
os: [ubuntu-latest, macos-latest]
auth-logout: [post, never]
runs-on: ${{ matrix.os }}
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Move pixi.toml
run: mv test/default/* .
# post steps run in reverse order, so this runs after the post step of setup-pixi
- uses: lisanna-dettwyler/action-post-run@d053b9b43d788b87a409f6cdb3b6fc87c6c8a4fe # v3.1.0
with:
run: |
set -euxo pipefail
cat "${RATTLER_AUTH_FILE}"
${{ matrix.auth-logout == 'post' && '! ' || '' }}grep -q '"*.custom-conda-registry.com"' "${RATTLER_AUTH_FILE}"
- uses: ./
with:
cache: false
auth-host: https://custom-conda-registry.com
auth-token: custom-token
persist-credentials: false
- name: Assert that the credentials are not stored anymore
auth-logout: ${{ matrix.auth-logout }}
- name: Assert that the credentials are still stored
run: |
# For human log readers
cat "${RATTLER_AUTH_FILE}"

# Actual test
! grep -q '"*.custom-conda-registry.com"' "${RATTLER_AUTH_FILE}"
[ $(jq '."*.custom-conda-registry.com".BearerToken' -r "${RATTLER_AUTH_FILE}") = "custom-token" ]

auth-token-install:
strategy:
Expand Down
69 changes: 39 additions & 30 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ GitHub Action to set up the [pixi](https://github.com/prefix-dev/pixi) package m
## Usage

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
pixi-version: v0.66.0

Expand All @@ -35,7 +35,7 @@ GitHub Action to set up the [pixi](https://github.com/prefix-dev/pixi) package m

> [!WARNING]
> Since pixi is not yet stable, the API of this action may change between minor versions.
> Please pin the versions of this action to a specific version (i.e., `prefix-dev/setup-pixi@v0.10.2`) to avoid breaking changes.
> Please pin the versions of this action to a specific version (i.e., `prefix-dev/setup-pixi@v0.11.0`) to avoid breaking changes.
> You can automatically update the version of this action by using [Dependabot](https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot).
>
> Put the following in your `.github/dependabot.yml` file to enable Dependabot for your GitHub Actions:
Expand Down Expand Up @@ -79,7 +79,7 @@ In order to not exceed the [10 GB cache size limit](https://docs.github.com/en/a
This can be done by setting the `cache-write` argument.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
cache: true
cache-write: ${{ github.event_name == 'push' && github.ref_name == 'main' }}
Expand Down Expand Up @@ -124,7 +124,7 @@ test:
environment: [py311, py312]
steps:
- uses: actions/checkout@v4
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
environments: ${{ matrix.environment }}
```
Expand All @@ -134,7 +134,7 @@ test:
The following example will install both the `py311` and the `py312` environment on the runner.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
# separated by spaces
environments: >-
Expand All @@ -157,7 +157,7 @@ For instance, the `keyring`, or `gcloud` executables. The following example show
By default, global environments are not cached. You can enable caching by setting the `global-cache` input to `true`.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
global-environments: |
google-cloud-sdk
Expand Down Expand Up @@ -190,7 +190,7 @@ Specify the token using the `auth-token` input argument.
This form of authentication (bearer token in the request headers) is mainly used at [prefix.dev](https://prefix.dev).

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
auth-host: prefix.dev
auth-token: ${{ secrets.PREFIX_DEV_TOKEN }}
Expand All @@ -202,7 +202,7 @@ Specify the username and password using the `auth-username` and `auth-password`
This form of authentication (HTTP Basic Auth) is used in some enterprise environments with [artifactory](https://jfrog.com/artifactory) for example.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
auth-host: custom-artifactory.com
auth-username: ${{ secrets.PIXI_USERNAME }}
Expand All @@ -215,7 +215,7 @@ Specify the conda-token using the `auth-conda-token` input argument.
This form of authentication (token is encoded in URL: `https://my-quetz-instance.com/t/<token>/get/custom-channel`) is used at [anaconda.org](https://anaconda.org) or with [quetz instances](https://github.com/mamba-org/quetz).

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
auth-host: anaconda.org # or my-quetz-instance.com
auth-conda-token: ${{ secrets.CONDA_TOKEN }}
Expand All @@ -227,7 +227,7 @@ Specify the S3 key pair using the `auth-access-key-id` and `auth-secret-access-k
You can also specify the session token using the `auth-session-token` input argument.

```yaml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
auth-host: s3://my-s3-bucket
auth-s3-access-key-id: ${{ secrets.ACCESS_KEY_ID }}
Expand All @@ -238,27 +238,36 @@ You can also specify the session token using the `auth-session-token` input argu

See the [pixi documentation](https://pixi.sh/latest/advanced/s3) for more information about S3 authentication.

#### Restricting credentials to the install step
#### Logging out

If you only want pixi to use the authenticated remote channel during the action's own install step
(and not in any subsequent step of the workflow), set `persist-credentials: false`. The action will
then run `pixi auth logout <auth-host>` after `pixi install` has completed but before the action
returns, so that later steps cannot reach the private channel anymore.
By default, the credentials stay available to all subsequent steps of the job and the action runs
`pixi auth logout <auth-host>` in its post step at the end of the job.
You can change this behavior with the `auth-logout` input:

- `post` (default): log out in the post step at the end of the job.
- `after-install`: log out at the end of the action, after `pixi install` has completed.
Use this if you only want pixi to use the authenticated remote channel during the action's own install step,
so that later steps cannot reach the private channel anymore.
- `never`: never log out, for example on self-hosted runners where the credentials should persist between jobs.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
auth-host: prefix.dev
auth-token: ${{ secrets.PREFIX_DEV_TOKEN }}
persist-credentials: false
auth-logout: after-install
```

> [!NOTE]
> `auth-logout` replaces the removed `persist-credentials` input.
> Use `auth-logout: after-install` instead of `persist-credentials: false` and `auth-logout: never` instead of `persist-credentials: true`.

#### PyPI keyring provider

You can specify whether to use keyring to look up credentials for PyPI.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
pypi-keyring-provider: subprocess # one of 'subprocess', 'disabled'
```
Expand Down Expand Up @@ -326,15 +335,15 @@ To this end, `setup-pixi` adds all environment variables set when executing `pix
As a result, all installed binaries can be accessed without having to call `pixi run`.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
activate-environment: true
```

If you are installing multiple environments, you will need to specify the name of the environment that you want to be activated.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
environments: >-
py311
Expand All @@ -351,7 +360,7 @@ You can specify whether `setup-pixi` should run `pixi install --frozen` or `pixi
See the [official documentation](https://pixi.sh/latest/reference/cli/pixi/install/#update-options) for more information about the `--frozen` and `--locked` flags.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
locked: true
# or
Expand All @@ -370,7 +379,7 @@ The first one is the debug logging of the action itself.
This can be enabled by running the action with the `RUNNER_DEBUG` environment variable set to `true`.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
env:
RUNNER_DEBUG: true
```
Expand All @@ -388,7 +397,7 @@ The second type is the debug logging of the pixi executable.
This can be specified by setting the `log-level` input.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
# one of `q`, `default`, `v`, `vv`, or `vvv`.
log-level: vvv
Expand All @@ -414,7 +423,7 @@ If nothing is specified, `post-cleanup` will default to `false`.
On self-hosted runners, you also might want to alter the default pixi install location to a temporary location. You can use `pixi-bin-path: ${{ runner.temp }}/bin/pixi` to do this.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
post-cleanup: true
# ${{ runner.temp }}\Scripts\pixi.exe on Windows
Expand All @@ -430,7 +439,7 @@ You can also use a preinstalled local version of pixi on the runner by not setti
This can be overwritten by setting the `manifest-path` input argument.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
manifest-path: pyproject.toml
```
Expand All @@ -440,7 +449,7 @@ This can be overwritten by setting the `manifest-path` input argument.
If you're working with a monorepo where your pixi project is in a subdirectory, you can use the `working-directory` input to specify where pixi should look for manifest files (`pixi.toml` or `pyproject.toml`).

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
working-directory: ./packages/my-project
```
Expand All @@ -459,7 +468,7 @@ This will make pixi look for `pixi.toml` or `pyproject.toml` in the `./packages/
You can combine `working-directory` with `manifest-path` if needed:

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
working-directory: ./packages/my-project
manifest-path: custom-pixi.toml
Expand All @@ -470,7 +479,7 @@ You can combine `working-directory` with `manifest-path` if needed:
If you only want to install pixi and not install the current project, you can use the `run-install` option.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
run-install: false
```
Expand All @@ -481,7 +490,7 @@ You can also download pixi from a custom URL by setting the `pixi-url` input arg
Optionally, you can combine this with the `pixi-url-headers` input argument to supply additional headers for the download request, such as a bearer token.

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
pixi-url: https://pixi-mirror.example.com/releases/download/v0.48.0/pixi-x86_64-unknown-linux-musl
pixi-url-headers: '{"Authorization": "Bearer ${{ secrets.PIXI_MIRROR_BEARER_TOKEN }}"}'
Expand All @@ -497,7 +506,7 @@ It will be rendered with the following variables:
By default, `pixi-url` is equivalent to the following template:

```yml
- uses: prefix-dev/setup-pixi@v0.10.2
- uses: prefix-dev/setup-pixi@v0.11.0
with:
pixi-url: |
{{#if latest~}}
Expand Down
14 changes: 9 additions & 5 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,12 +78,16 @@ inputs:
description: Secret access key to use for S3 authentication.
auth-s3-session-token:
description: Session token to use for S3 authentication.
persist-credentials:
auth-logout:
description: |
Whether to keep the credentials configured by `auth-host` available to subsequent workflow
steps. Defaults to `true`. If set to `false`, the action runs `pixi auth logout <auth-host>`
after install, so that later steps cannot reach the private channel anymore. Requires
`auth-host`.
When to run `pixi auth logout <auth-host>`. Requires `auth-host`.
options: post, after-install, never
- `post` (default): The credentials stay available to all subsequent steps and are removed in the post step at the end of the job.
- `after-install`: The credentials are removed at the end of this action, so that later steps cannot reach the private channel anymore.
- `never`: The credentials are never removed.
persist-credentials:
description: Removed, use `auth-logout` instead.
deprecationMessage: '`persist-credentials` has been removed, use `auth-logout: after-install` (instead of `false`) or `auth-logout: never` (instead of `true`).'
pypi-keyring-provider:
description: |
Specifies whether to use keyring to look up credentials for PyPI.
Expand Down
Loading
Loading