Add support for hermetic Python (#29)

diff --git a/README.md b/README.md
index 9ee536a..ad1a86c 100644
--- a/README.md
+++ b/README.md
@@ -57,3 +57,15 @@
 ```starlark
 load("@pybind11_bazel//:build_defs.bzl", "pybind_extension")
 ```
+
+## Hermetic Python
+
+To configure `pybind11_bazel` for hermetic Python, `python_configure` can take
+the target providing the Python runtime as an argument:
+
+```starlark
+python_configure(
+  name = "local_config_python",
+  python_interpreter_target = "@python_interpreter//:python_bin",
+)
+```
diff --git a/python_configure.bzl b/python_configure.bzl
index ade190a..1f5bffa 100644
--- a/python_configure.bzl
+++ b/python_configure.bzl
@@ -87,7 +87,7 @@
         result = find_result.stdout
     return result
 
-def _genrule(src_dir, genrule_name, command, outs):
+def _genrule(src_dir, genrule_name, command, outs, local):
     """Returns a string with a genrule.
 
     Genrule executes the given command and produces the given outputs.
@@ -95,7 +95,8 @@
     return (
         "genrule(\n" +
         '    name = "' +
-        genrule_name + '",\n' +
+        genrule_name + '",\n' + (
+        "    local = 1,\n" if local else "") +
         "    outs = [\n" +
         outs +
         "\n    ],\n" +
@@ -149,11 +150,15 @@
         genrule_name,
         " && ".join(command),
         "\n".join(outs),
+        local = True,
     )
     return genrule
 
 def _get_python_bin(repository_ctx):
     """Gets the python bin path."""
+    if repository_ctx.attr.python_interpreter_target != None:
+        return str(repository_ctx.path(repository_ctx.attr.python_interpreter_target))
+
     python_bin = repository_ctx.os.environ.get(_PYTHON_BIN_PATH)
     if python_bin != None:
         return python_bin
@@ -391,6 +396,7 @@
     ],
     attrs = {
         "python_version": attr.string(default=""),
+        "python_interpreter_target": attr.label(),
     },
 )
 """Detects and configures the local Python.
@@ -409,4 +415,7 @@
       If set to "2", will build for Python 2 (`which python2`).
       By default, will build for whatever Python version is returned by
       `which python`.
+  python_interpreter_target: If set to a target providing a Python binary,
+      will configure for that Python version instead of the installed
+      binary. This configuration takes precedence over python_version.
 """