Installing Nexus
Nexus depends on the abm-lab SDK (the former engine/ package), which is
published to Simudyne's private JFrog PyPI repository — not public PyPI. pip
must therefore be told about the private index, with credentials.
- Resolve (pip) index:
https://simudyne.jfrog.io/artifactory/api/pypi/simudyne-python-sdk/simple - Package pinned in
pyproject.toml:abm-lab==0.7.0
Never commit credentials. Supply them at install time via one of the methods below.
Your credentials file
The repo ships a credentials.replace template. Copy it to credentials and fill
in your JFrog user/password (or API token):
cp credentials.replace credentials # then edit user= and password=
credentials is git-ignored, so your real values never get committed. Derive the
authenticated index URL from it:
export PIP_EXTRA_INDEX_URL="https://$(sed -n 's/^user=//p' credentials):$(sed -n 's/^password=//p' credentials)@simudyne.jfrog.io/artifactory/api/pypi/simudyne-python-sdk/simple"
Option A — environment variable (recommended)
pip automatically honours PIP_EXTRA_INDEX_URL; no flags needed.
export PIP_EXTRA_INDEX_URL="https://<user>:<token>@simudyne.jfrog.io/artifactory/api/pypi/simudyne-python-sdk/simple"
pip install -e ".[all]" # or ".[dev]" for a dev checkout
Option B — pip config file
Copy pip.conf.example to pip.conf, fill in <user>:<token>, then:
PIP_CONFIG_FILE=./pip.conf pip install -e ".[all]"
pip.conf (with credentials) and credentials are git-ignored — keep it local.
Option C — local co-development against an unreleased SDK
To develop Nexus against a local SDK checkout instead of the published wheel:
pip install -e ".[dev]" -e ../python-sdk # editable abm-lab overrides the pin
Docker
The image pulls abm-lab via a BuildKit secret so the token never lands in a layer:
export PIP_EXTRA_INDEX_URL="https://<user>:<token>@simudyne.jfrog.io/artifactory/api/pypi/simudyne-python-sdk/simple"
DOCKER_BUILDKIT=1 docker build --secret id=pip_extra_index,env=PIP_EXTRA_INDEX_URL -f nexus/Dockerfile .
# or: cd nexus && PIP_EXTRA_INDEX_URL=... docker compose build
CI
Store the full authenticated index URL as a repository/org secret named
PIP_EXTRA_INDEX_URL. The .github/workflows/ci.yml job exposes it as an env var,
which pip picks up automatically.