How to Point pip / PyPI at Chainsaw

Beginner 15 minutes Developers / DevOps Engineers Getting Started

Configure pip to install through your Chainsaw proxy via pip.conf, the PIP_INDEX_URL environment variable, and per-command flags.

Overview

Point pip at your Chainsaw instance so every Python install passes through the firewall. This page covers pip.conf / pip.ini, the PIP_INDEX_URL environment variable, and per-command flags.

Replace chain305.com with your own Chainsaw deployment host and swap CLIENT_ID / CLIENT_SECRET for credentials issued from the Access page in the dashboard. The @default segment is the org slug — confirm yours under Settings → Organization → Slug. Legacy non-org-scoped URLs return HTTP 400 with error CHW-4314.

Prerequisites

  • A running Chainsaw instance (see Tutorial 01)
  • Client credentials (Client ID and Secret)
  • Python and pip installed

Clear Local Caches (First-Time Setup)

pip cache purge

pip.conf / pip.ini

[global]
index-url = https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple/
trusted-host = chain305.com
trusted-host takes a bare hostname (optionally host:port). Appending a path (e.g. chain305.com/chainsaw) will cause pip to reject the configuration. The path belongs in index-url only.

Environment Variable

export PIP_INDEX_URL=https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple/

Per-Command

pip install requests \
  --index-url https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple/
Chainsaw performs format-aware URL rewriting for PyPI, ensuring that pip always fetches through the proxy even when upstream returns absolute URLs.

Verify

Run chainsaw doctor verify-hook from the same shell to confirm the install genuinely reached the proxy, then check the Traffic page in the dashboard.

Next Steps