My employer has a self hosted Gitlab instance, and I have a python package (say dep) in one repository. I created a package registry for the same following this guide. I also created a token with read_api access, and afterwards I am able to install the package using the following:
python -m pip install dep --index-url https://__token__:<personal_access_token>@<gitlab_server_host>/api/v4/projects/<gitlab_project_id>/packages/pypi/simple
Now, I have another python package (say main) in another repository where I want to use dep as a dependency. I tried to specify the following:
install_requires =
<other_packages>
dep
<few_more_packages>
When I try to install this package, this fails complaining that no version found.
python -m pip install -e <path_to_main_package>
This is expected as the package is not publicly available on PyPI. Then I tried to use dependency_links the following way:
dependency_links =
https://__token__:<personal_access_token>@<gitlab_server_host>/api/v4/projects/<gitlab_project_id>/packages/pypi/simple
However, this fails as well complaining the same.
Finally specifying as git dependency seems to work:
install_requires =
<other_packages>
dep @ git+https://__token__:<personal_access_token>@<gitlab_server_host>/<gitlab_group_id>/<gitlab_project_id>.git#egg=dep&subdirectory=<relative_path_from_repo_root>
<few_more_packages>
But it stores the token unprotected, and that seems wrong since I have to commit setup.cfg.
So, my questions are as follows:
- How can I pass index URL in
setup.cfg? - How can I pass tokens through environmental variables in
setup.cfg? (Or, some other secure way)
I shall also install main in CI and in Dockerfile for my requirements, so the solutions has to be a way that do not prompt for me to enter credentials manually. I'd like to be able to pass those as environmental variables as well.