Describe the bug
With [python].resolver = "uv", lockfiles can be generated successfully but building .pex binaries fails when attempting download of package from private repos. In my case, this is a private repo authenticated with via keyring.
Context: I have a private package stored in Google Artifact Registry that pants generate-lockfiles (using uv provider backend) can read correctly and construct a lockfile with, but for pants invokations e.g. pants package pex-binary which depend on this private package, I’m getting a 401 :
ProcessExecutionFailure: Process 'Create venv from uv lockfile at requirements.lock' failed with exit code 1.
...
HTTP status client error (401 Unauthorized) for url
I’m not sure if this is due to:
My current solution for passing creds for GAR repos which sets an env var in .pants.bootstrap and is consumed by indices in pants.toml like: https://oauth2accesstoken/:%(env.GOOGLE_ACCESS_TOKEN)s@index.url/repo/simple
uv is not able to use keyring and the google auth keyring backend in the environment that process is running in. keyring and keyring-gauth are included in my dependencies but this makes no difference. Neither does setting:
[uv]
extra_env_vars = [
"UV_KEYRING_PROVIDER=subprocess"
]
It also isn’t fixed by using uv’s dynamic index username/password env vars in either .pants.bootstrap or [subprocess-environment].env_vars or [uv].extra_env_vars e.g.
[subprocess-environment]
env_vars = [
"UV_INDEX_NAME_OF_REPO_USERNAME=oauth2accesstoken",
"UV_INDEX_NAME_OF_REPO_PASSWORD=%(env.GOOGLE_ACCESS_TOKEN)s",
]
I think this is due to Pants only referencing the index URLs via the lockfile generated by uv in which the username is stripped and Pants does not attempt to referencing the matching index items in either pants.toml or pyproject.toml [tool.uv.index]. Internally, uv fails to check keyring since there is no username passed and doesn’t respect authenticate = always which is set in the pyproject.toml, which unfortunately isn’t resolved by my attempts above.
DEBUG Skipping keyring fetch for https://gcloud-repo/package.whl without username; use `authenticate = always` to force
Pants version
2.32
OS
macOS + Linux
Describe the bug
With
[python].resolver = "uv", lockfiles can be generated successfully but building .pex binaries fails when attempting download of package from private repos. In my case, this is a private repo authenticated with viakeyring.Context: I have a private package stored in Google Artifact Registry that
pants generate-lockfiles(using uv provider backend) can read correctly and construct a lockfile with, but for pants invokations e.g.pants package pex-binarywhich depend on this private package, I’m getting a401:ProcessExecutionFailure: Process 'Create venv from uv lockfile at requirements.lock' failed with exit code 1.
...
I’m not sure if this is due to:
My current solution for passing creds for GAR repos which sets an env var in
.pants.bootstrapand is consumed by indices inpants.tomllike:https://oauth2accesstoken/:%(env.GOOGLE_ACCESS_TOKEN)s@index.url/repo/simpleuvis not able to use keyring and the google auth keyring backend in the environment that process is running in. keyring and keyring-gauth are included in my dependencies but this makes no difference. Neither does setting:It also isn’t fixed by using uv’s dynamic index username/password env vars in either .pants.bootstrap or
[subprocess-environment].env_varsor[uv].extra_env_varse.g.I think this is due to Pants only referencing the index URLs via the lockfile generated by uv in which the username is stripped and Pants does not attempt to referencing the matching index items in either pants.toml or pyproject.toml [tool.uv.index]. Internally, uv fails to check keyring since there is no username passed and doesn’t respect authenticate = always which is set in the pyproject.toml, which unfortunately isn’t resolved by my attempts above.
DEBUG Skipping keyring fetch for https://gcloud-repo/package.whl without username; use `authenticate = always` to forcePants version
2.32OS
macOS + Linux