PyPI mirror
Deploy a PyPI package mirror: a single Docker container, built from
files/pypi_mirror/, that acts as a pull-through cache for upstream Python
packages so the platform's Python/uv-based repos don't hit the public index directly.
Ansible hosts group: pypi_mirror
Variables
This service has no user-settable variables. Everything is fixed: the Docker network, the container user and group
(devops-server-pypi-mirror, GID 2800, UID 2801), and the install directory
(/app/devops-server-pypi-mirror).
Image
The pypi_mirror_install tag first exports the pypi-mirror dependency group from
pyproject.toml to files/pypi_mirror/requirements.txt on the control node, skipping the export
when the file already exists. It then copies files/pypi_mirror/ to the host and builds the
devops-server-pypi-mirror:localbuild image from it, with the Root CA baked into the image's trust
store.
The container keeps its login-token secret in the install directory, generated once on the first run, so tokens issued before a container restart stay valid. The mirror's admin root password is generated fresh on every run and passed to the container as an environment variable; the container resets the root user to that password on every start, so a changed password stays idempotent.
Vault configurations
- key:
{{ cs_project_code }}/devops-server/hosts/{{ inventory_hostname }}/apps/pypi-mirror/config
{
"port": "(int) Port the mirror listens on, published on the host and opened in the firewall"
}
This field is mandatory. The shared Root CA path is listed in Prerequisites.
- key:
{{ cs_project_code }}/devops-server/hosts/{{ inventory_hostname }}/apps/pypi-mirror/generated: written by thepypi_mirror_installtag on every run
{
"endpoint": "URL the mirror is reachable at, e.g. http://10.8.33.190:3141",
"root_password": "Root password for the mirror's admin user, freshly generated on every run"
}
Tags
pypi_mirror: Deploy the PyPI mirror.pypi_mirror_prepare: Install APT dependencies, and create the Docker network and the container user and group.pypi_mirror_install: Build the image, create the install directory, open the firewall port, start the mirror container, and write theapps/pypi-mirror/generatedVault secret. Runspypi_mirror_preparefirst.dangerously_cleanup_pypi_mirror: Destructive. Removes the mirror container, its Docker network, and its install directory, then deletes the container's user and group. Never included by the plainpypi_mirrortag.
Deployment
uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml --tags pypi_mirror