Find a file
russell@unturf.com 9b3039fa6f
docs: PyPI Trusted Publishing (OIDC) migration plan
When we're ready to drop the twine<6 + setuptools<77 pins on the
build runner, this doc is the recipe. Covers:

  - PyPI side: registering a pending publisher per project
  - GitLab side: id_tokens: PYPI_ID_TOKEN: aud: pypi
  - What pins to drop after migration
  - Why coordinated across all four python/* repos in one go

Today we ship via classic ~/.pypirc on the build runner. Trusted
Publishing replaces that with short-lived OIDC tokens minted per
pipeline. Per-project scope, per-pipeline expiry, no long-lived
secret on the runner.
2026-06-16 14:20:00 -04:00
docs docs: PyPI Trusted Publishing (OIDC) migration plan 2026-06-16 14:20:00 -04:00
erldistpy cap setuptools<77 in build-system, bump to v0.1.2 2026-06-16 14:19:22 -04:00
tests etf: add MAP_EXT (tag 116) for Erlang/Elixir maps 2026-06-16 12:16:35 -04:00
.gitignore phase 6: TLS dist via inet_tls_dist 2026-06-16 12:06:07 -04:00
.gitlab-ci.yml ci: pin twine<6, bump to v0.1.1 — classic auth on build runner 2026-06-16 14:11:47 -04:00
LICENSE phase 0 + 1: repo bones and ETF codec 2026-06-16 10:39:01 -04:00
Makefile packaging: ship to PyPI via tag + GitLab CI (mirrors ago's pattern) 2026-06-16 13:45:08 -04:00
pyproject.toml cap setuptools<77 in build-system, bump to v0.1.2 2026-06-16 14:19:22 -04:00
README.md packaging: ship to PyPI via tag + GitLab CI (mirrors ago's pattern) 2026-06-16 13:45:08 -04:00

erldistpy

Native Python client for our Erlang distribution protocol. Talk Erlang/Elixir nodes from CPython without HTTP shim layers.

Built to swap into Python web apps as a drop-in for HTTP wallet-bridge clients (see unfeed's WalletTransport and make_post_sell's crypto watcher) so they can call Elixir gen_server processes over native Erlang dist instead of JSON-RPC or HTTPS. Same call semantics, lower latency, fewer moving parts.

Install

pip install erldistpy

Quick start

from erldistpy import Node, Atom

with Node(
    our_name="myapp@host",
    peer_name="wallet",                # short EPMD name
    peer_host="wallet.example.com",
    cookie="SHARED_COOKIE",            # read from a file path, never inline
) as node:
    reply = node.call(
        "Elixir.Wallet.Service",
        (Atom("monero"), Atom("get_height"), []),
        timeout=5.0,
    )
    # reply is whatever the gen_server returned — atoms / binaries /
    # tuples / maps / lists / pids / refs decode to Python natives.

For TLS dist (Erlang inet_tls_dist):

from erldistpy import Node, make_dist_tls_context

ctx = make_dist_tls_context(
    cert="/etc/myapp/client.pem",
    key="/etc/myapp/client.key",
    ca="/etc/myapp/ca.pem",
)
node = Node(our_name=..., peer_name=..., cookie=..., tls_context=ctx)

Scope

  • ETF (External Term Format) codec — encode/decode Erlang terms
  • EPMD client — node name → port lookup
  • v6 distribution handshake — MD5 cookie auth, version negotiation
  • gen_call to registered processes on a remote node
  • TLS dist support (Erlang inet_tls_dist)

Out of scope: full Erlang node impersonation, link/monitor lifecycles, distributed Mnesia. We are a client, not a peer node.

Why not Pyrlang?

Pyrlang implements a full asyncio Erlang node. Heavy, asyncio-first, complex. erldistpy is a small synchronous client that fits behind the same Protocol surface as httpx. Different shape, different audience.

Development

make bootstrap   # create venv, install editable + dev deps
make test        # run pytest (122 tests)
make lint        # ruff check
make build       # build sdist + wheel into dist/
make dist-check  # twine check dist/*

See docs/ROADMAP.md for the phase-by-phase build log.

License

Unlicense (public domain).