Commit

Cargo guide: a workflow's registry, credential provider and token from the environment, checked with cargo publish and build without cargo login

syntaqxcommitted Parentc59eb9eBrowse files
1 file+19−90/1 viewed
+19−9
4242 access works; one with scopes needs `packages:read` to add private crates
4343 and `packages:write` to publish and yank them.
4444
45−The token can also come from the environment, as
46−`CARGO_REGISTRIES_ACME_TOKEN` for a registry named `acme`, which is how
47−[workflows](#in-workflows) give it.
45+The token can also come from the environment instead of `cargo login`,
46+as `CARGO_REGISTRIES_ACME_TOKEN` for a registry named `acme` (the name in
47+capitals, with `-` written `_`). The `cargo:token` provider reads it from
48+there, which is how [workflows](#in-workflows) give it.
4849
4950 ## Publish
5051
149150 ## In workflows
150151
151152 A workflow's `G1T_TOKEN` is the workspace's own token for the run, and can
152−add and publish the workspace's crates. Give it to Cargo for the registry:
153+add and publish the workspace's crates. A workflow runs no `cargo login`:
154+give Cargo the registry, its credential provider and the token in the
155+environment, each named for the registry:
153156
154157 ```yaml
155158 jobs:
165168 - run: cargo publish --registry acme
166169 ```
167170
168−`CARGO_REGISTRIES_ACME_INDEX` and `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER`
169−are needed only when the project has no `.cargo/config.toml` naming the
170−registry.
171+| Variable | Is | Needed |
172+| --- | --- | --- |
173+| `CARGO_REGISTRIES_ACME_INDEX` | The registry's index, as `index` in `.cargo/config.toml`. | When no `.cargo/config.toml` names the registry. |
174+| `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER` | `cargo:token`, as `credential-provider` in `.cargo/config.toml`. | When no `.cargo/config.toml` names the provider. Without one, Cargo refuses a registry with private crates, even with the token in the environment. |
175+| `CARGO_REGISTRIES_ACME_TOKEN` | The token, for `cargo:token` to hand to the registry. | Always: `cargo publish` sends it, and Cargo sends it to read a registry with private crates. |
176+
177+With the project's `.cargo/config.toml` from [above](#set-up-cargoconfigtoml)
178+checked in, `CARGO_REGISTRIES_ACME_TOKEN` is all a workflow sets. The same
179+variables let `cargo build` and `cargo test` download the workspace's
180+private crates.
171181
172182 ## Size
173183
181191
182192 | Error | Means |
183193 | --- | --- |
184−| `401` | No token, or a wrong or expired one. Run `cargo login --registry acme` with a g1t access token. |
185−| `authenticated registries require a credential-provider to be configured` | The workspace has private crates, and Cargo has no provider for its token. Add `credential-provider = "cargo:token"` to the registry in `.cargo/config.toml`. |
194+| `401` | No token, or a wrong or expired one. Run `cargo login --registry acme` with a g1t access token, or set `CARGO_REGISTRIES_ACME_TOKEN`. |
195+| `authenticated registries require a credential-provider to be configured` | The workspace has private crates, and Cargo has no provider for its token. Add `credential-provider = "cargo:token"` to the registry in `.cargo/config.toml`, or set `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER=cargo:token`. |
186196 | `403` | Signed in, but your role or your token's scopes do not allow it, or the workspace is out of free package storage. The message says which. |
187197 | `404` | No such crate or version, or a private one you cannot see. |
188198 | `400` | The publish was refused: a name that is not valid or is taken, a version already published, or metadata Cargo did not send in full. The message says which. |