Private registry: acme

This is the acme registry. Access follows your GitHub permissions: you can use a crate if you can read its repository on GitHub. There is no separate account.

Joining the team

If a project already uses this registry, you need one thing: the credential provider.

cargo binstall cargo-credential-privatecrates
# without cargo-binstall, it builds from source:
cargo install cargo-credential-privatecrates --locked

Then build as usual. The first time, Cargo shows a code: approve it on GitHub, and you are signed in for every project using this registry. To sign in before building (for example, before opening the project in an editor):

cargo login --registry acme

A project that does not use the registry yet needs it in .cargo/config.toml:

[registries.acme]
index = "sparse+https://acme.privatecrates.dev/index/"
credential-provider = ["cargo-credential-privatecrates"]

and dependencies that name it, in Cargo.toml:

my_crate = { version = "1", registry = "acme" }

Editors and background builds

Editors such as rust-analyzer run Cargo without a terminal, where there is nowhere to show a sign-in code. If you are not signed in, the build stops at once with not signed in … run cargo login --registry acme in a terminal. Run that once, then reload the editor.

When something does not work

GitHub Actions

Add permissions: id-token: write to the job and install the credential provider with the step in the workflow below, which downloads the prebuilt binary and checks it. No secrets are needed.

Publishing

Crates are published from GitHub Actions, so every version has verifiable provenance. Only people who can create releases in the crate's repository (write access or above) can trigger a publish.

on:
  push:
    tags: ["v*"]
permissions:
  id-token: write
  contents: read
jobs:
  publish:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
      - name: Install cargo-credential-privatecrates 0.2.6 (checksummed and attested)
        env: { GH_TOKEN: "${{ github.token }}", VERSION: "0.2.6" }
        run: |
          cd "$(mktemp -d)"
          name=cargo-credential-privatecrates-$(uname -m)-unknown-linux-gnu
          base=https://github.com/worldbuilding-dev/privatecrates.dev/releases/download/v$VERSION
          curl -fsSL --remote-name-all "$base/$name.tgz" "$base/SHA256SUMS"
          sha256sum --check --ignore-missing SHA256SUMS
          gh attestation verify "$name.tgz" --repo worldbuilding-dev/privatecrates.dev
          tar -xzf "$name.tgz"
          install -D "$name/cargo-credential-privatecrates" ~/.cargo/bin/cargo-credential-privatecrates
      - run: cargo publish --registry acme

The crate's package.repository must be the repository the workflow runs in. cargo privatecrates init sets all of this up.

More: joining a team, all documentation.