Cargo guide: a workflow's registry, credential provider and token from the environment, checked with cargo publish and build without cargo login
1 file+19−90/1 viewed
| 42 | 42 | access works; one with scopes needs `packages:read` to add private crates | |
| 43 | 43 | and `packages:write` to publish and yank them. | |
| 44 | 44 | ||
| 45 | − | The token can also come from the environment, as | |
| 46 | − | `CARGO_REGISTRIES_ACME_TOKEN` for a registry named `acme`, which is how | |
| 47 | − | [workflows](#in-workflows) give it. | |
| 45 | + | The token can also come from the environment instead of `cargo login`, | |
| 46 | + | as `CARGO_REGISTRIES_ACME_TOKEN` for a registry named `acme` (the name in | |
| 47 | + | capitals, with `-` written `_`). The `cargo:token` provider reads it from | |
| 48 | + | there, which is how [workflows](#in-workflows) give it. | |
| 48 | 49 | ||
| 49 | 50 | ## Publish | |
| 50 | 51 | ||
| 149 | 150 | ## In workflows | |
| 150 | 151 | ||
| 151 | 152 | A workflow's `G1T_TOKEN` is the workspace's own token for the run, and can | |
| 152 | − | add and publish the workspace's crates. Give it to Cargo for the registry: | |
| 153 | + | add and publish the workspace's crates. A workflow runs no `cargo login`: | |
| 154 | + | give Cargo the registry, its credential provider and the token in the | |
| 155 | + | environment, each named for the registry: | |
| 153 | 156 | ||
| 154 | 157 | ```yaml | |
| 155 | 158 | jobs: | |
| 165 | 168 | - run: cargo publish --registry acme | |
| 166 | 169 | ``` | |
| 167 | 170 | ||
| 168 | − | `CARGO_REGISTRIES_ACME_INDEX` and `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER` | |
| 169 | − | are needed only when the project has no `.cargo/config.toml` naming the | |
| 170 | − | registry. | |
| 171 | + | | Variable | Is | Needed | | |
| 172 | + | | --- | --- | --- | | |
| 173 | + | | `CARGO_REGISTRIES_ACME_INDEX` | The registry's index, as `index` in `.cargo/config.toml`. | When no `.cargo/config.toml` names the registry. | | |
| 174 | + | | `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER` | `cargo:token`, as `credential-provider` in `.cargo/config.toml`. | When no `.cargo/config.toml` names the provider. Without one, Cargo refuses a registry with private crates, even with the token in the environment. | | |
| 175 | + | | `CARGO_REGISTRIES_ACME_TOKEN` | The token, for `cargo:token` to hand to the registry. | Always: `cargo publish` sends it, and Cargo sends it to read a registry with private crates. | | |
| 176 | + | ||
| 177 | + | With the project's `.cargo/config.toml` from [above](#set-up-cargoconfigtoml) | |
| 178 | + | checked in, `CARGO_REGISTRIES_ACME_TOKEN` is all a workflow sets. The same | |
| 179 | + | variables let `cargo build` and `cargo test` download the workspace's | |
| 180 | + | private crates. | |
| 171 | 181 | ||
| 172 | 182 | ## Size | |
| 173 | 183 | ||
| 181 | 191 | ||
| 182 | 192 | | Error | Means | | |
| 183 | 193 | | --- | --- | | |
| 184 | − | | `401` | No token, or a wrong or expired one. Run `cargo login --registry acme` with a g1t access token. | | |
| 185 | − | | `authenticated registries require a credential-provider to be configured` | The workspace has private crates, and Cargo has no provider for its token. Add `credential-provider = "cargo:token"` to the registry in `.cargo/config.toml`. | | |
| 194 | + | | `401` | No token, or a wrong or expired one. Run `cargo login --registry acme` with a g1t access token, or set `CARGO_REGISTRIES_ACME_TOKEN`. | | |
| 195 | + | | `authenticated registries require a credential-provider to be configured` | The workspace has private crates, and Cargo has no provider for its token. Add `credential-provider = "cargo:token"` to the registry in `.cargo/config.toml`, or set `CARGO_REGISTRIES_ACME_CREDENTIAL_PROVIDER=cargo:token`. | | |
| 186 | 196 | | `403` | Signed in, but your role or your token's scopes do not allow it, or the workspace is out of free package storage. The message says which. | | |
| 187 | 197 | | `404` | No such crate or version, or a private one you cannot see. | | |
| 188 | 198 | | `400` | The publish was refused: a name that is not valid or is taken, a version already published, or metadata Cargo did not send in full. The message says which. | |