Skip to main content

PyPI mirror

Deploy a PyPI package mirror: a single Docker container, built from files/pypi_mirror/, that acts as a pull-through cache for upstream Python packages so the platform's Python/uv-based repos don't hit the public index directly.

Ansible hosts group: pypi_mirror​

Variables​

This service has no user-settable variables. Everything is fixed: the Docker network, the container user and group (devops-server-pypi-mirror, GID 2800, UID 2801), and the install directory (/app/devops-server-pypi-mirror).

Image​

The pypi_mirror_install tag first exports the pypi-mirror dependency group from pyproject.toml to files/pypi_mirror/requirements.txt on the control node, skipping the export when the file already exists. It then copies files/pypi_mirror/ to the host and builds the devops-server-pypi-mirror:localbuild image from it, with the Root CA baked into the image's trust store.

The container keeps its login-token secret in the install directory, generated once on the first run, so tokens issued before a container restart stay valid. The mirror's admin root password is generated fresh on every run and passed to the container as an environment variable; the container resets the root user to that password on every start, so a changed password stays idempotent.

Vault configurations​

  • key: {{ cs_project_code }}/devops-server/hosts/{{ inventory_hostname }}/apps/pypi-mirror/config
{
"port": "(int) Port the mirror listens on, published on the host and opened in the firewall"
}

This field is mandatory. The shared Root CA path is listed in Prerequisites.

  • key: {{ cs_project_code }}/devops-server/hosts/{{ inventory_hostname }}/apps/pypi-mirror/generated: written by the pypi_mirror_install tag on every run
{
"endpoint": "URL the mirror is reachable at, e.g. http://10.8.33.190:3141",
"root_password": "Root password for the mirror's admin user, freshly generated on every run"
}

Tags​

  • pypi_mirror: Deploy the PyPI mirror.
  • pypi_mirror_prepare: Install APT dependencies, and create the Docker network and the container user and group.
  • pypi_mirror_install: Build the image, create the install directory, open the firewall port, start the mirror container, and write the apps/pypi-mirror/generated Vault secret. Runs pypi_mirror_prepare first.
  • dangerously_cleanup_pypi_mirror: Destructive. Removes the mirror container, its Docker network, and its install directory, then deletes the container's user and group. Never included by the plain pypi_mirror tag.

Deployment​

uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml --tags pypi_mirror