Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/workflows/check.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
name: core-check

on:
workflow_call:
inputs:
ref:
description: Source commit to check
required: false
type: string
push:
branches: [main]
pull_request:
Expand All @@ -9,7 +15,7 @@ permissions:
contents: read

concurrency:
group: core-check-${{ github.ref }}
group: core-check-${{ github.workflow }}-${{ inputs.ref && github.run_id || github.ref }}
cancel-in-progress: true

jobs:
Expand All @@ -32,6 +38,8 @@ jobs:
--health-retries 10
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.ref || github.sha }}
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
Expand Down
26 changes: 18 additions & 8 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,11 +22,17 @@ permissions:
contents: read

concurrency:
group: core-release-${{ inputs.ref || github.sha }}
group: core-release-${{ github.event_name == 'push' && github.ref || inputs.ref }}
cancel-in-progress: false

jobs:
check:
uses: ./.github/workflows/check.yml
with:
ref: ${{ inputs.ref || github.sha }}

build:
needs: check
runs-on: ubuntu-22.04
timeout-minutes: 120
outputs:
Expand Down Expand Up @@ -97,31 +103,35 @@ jobs:
for asset in "$HOME/.oac/build/core-distribution/"*; do
if [[ -f "$asset" ]]; then ln "$asset" "$HOME/.oac/build/release-upload/"; fi
done
cp deploy/install-release.sh "$HOME/.oac/build/release-upload/install.sh"
(cd "$HOME/.oac/build/release-upload" && sha256sum install.sh > install.sh.sha256)
- uses: actions/upload-artifact@v6
with:
name: core-release-${{ steps.source.outputs.revision }}
path: ~/.oac/build/release-upload/*
compression-level: 0
if-no-files-found: error

draft:
if: github.event_name == 'workflow_dispatch' && inputs.draft_release
release:
if: github.event_name == 'push' || inputs.draft_release
needs: build
runs-on: ubuntu-22.04
permissions:
contents: write
steps:
- uses: actions/checkout@v7
with:
ref: ${{ needs.build.outputs.revision }}
persist-credentials: false
- uses: actions/download-artifact@v6
with:
name: core-release-${{ needs.build.outputs.revision }}
path: release-upload
- name: Create an unpublished draft
- name: Publish the version tag or create a manual draft
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
RELEASE_REVISION: ${{ needs.build.outputs.revision }}
RELEASE_TAG: ${{ needs.build.outputs.release_tag }}
run: |
printf 'Matched Linux amd64 artifacts from commit %s. Build output is not live execution qualification.\n' "$RELEASE_REVISION" > release-notes.md
gh release create "$RELEASE_TAG" --draft --target "$RELEASE_REVISION" \
--title "OpenAgentCore $RELEASE_REVISION" --notes-file release-notes.md release-upload/*
RELEASE_MODE: ${{ github.event_name == 'push' && 'publish' || 'draft' }}
run: python3 scripts/publish-core-release.py --assets release-upload
16 changes: 13 additions & 3 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -1973,9 +1973,19 @@ refers to.
`make build-core-distribution` builds from clean committed source and reuses the
existing API, Runtime, SDK, helper and Web builders. Artifacts record source and
immutable image identities, the actual Runtime manifest digest, checksums and
microsandbox runtime/firmware hashes and executable native payloads. Release generation is not publication or
qualification. A release must be tested from fresh extraction with real models;
no synthetic result may substitute for native execution acceptance.
microsandbox runtime/firmware hashes and executable native payloads. Local distribution builds do not publish. The tag-triggered release workflow
reuses the full repository check on the exact build source, then publishes the
matched assets automatically; manual runs remain artifact-only or draft-only.
Only publication receives repository write permission. Never overwrite release
assets or move an existing version tag. The [maintainer guide](docs/maintainers.md#publish-a-version)
owns tag syntax, prereleases and failed-publication recovery.
Release assets include `deploy/install-release.sh` as standalone `install.sh`
with a checksum. This public downloader resolves latest once (or a selected tag),
verifies the offline archive before safe extraction, and delegates to that bundle's
installer. It introduces no separate installation state, upgrade path or login flow.
Build/test success is distinct from real-model qualification; maintainers assess
that evidence before pushing a release tag, and no synthetic result substitutes
for native execution acceptance.

Distribution `images` records each exported image's config digest;
`image_manifest_digests` records its OCI manifest/index digest. Derive and verify
Expand Down
4 changes: 3 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -129,10 +129,12 @@ check-distribution:
go test ./services/core-console -count=1
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s deploy/install -p 'test_*.py'
PYTHONDONTWRITEBYTECODE=1 python3 scripts/core-distribution-manifest.test.py
PYTHONDONTWRITEBYTECODE=1 python3 scripts/publish-core-release.test.py
PYTHONDONTWRITEBYTECODE=1 python3 scripts/install-release.test.py
PYTHONDONTWRITEBYTECODE=1 python3 scripts/promote-qualified-release.test.py
PYTHONDONTWRITEBYTECODE=1 python3 scripts/qualification-control.test.py
PYTHONDONTWRITEBYTECODE=1 python3 scripts/config-reference.py --check
bash -n deploy/install/install.sh scripts/build-core-console.sh scripts/build-core-distribution.sh scripts/prepare-release-runtimes.sh
bash -n deploy/install/install.sh deploy/install-release.sh scripts/build-core-console.sh scripts/build-core-distribution.sh scripts/prepare-release-runtimes.sh
./scripts/build-core-console.sh

build-core-distribution:
Expand Down
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ administrator console.

## Quick start

On a Linux amd64 host with Docker and Python 3.9+, install the latest stable release:

```sh
curl -fsSL https://github.com/MiniMax-AI/parsar-core/releases/latest/download/install.sh | bash
```

1. [Install Core and Web](docs/getting-started/install.md) on a Linux host. The guide
covers prerequisites, release download, local trials and HTTPS setup.
2. Sign in to Web with the installer-created Core key. Configure a model provider,
Expand Down
6 changes: 6 additions & 0 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,12 @@ Web 提供管理员控制台。

## 快速开始

在已准备 Docker 和 Python 3.9+ 的 Linux amd64 主机上,一条命令安装最新正式版:

```sh
curl -fsSL https://github.com/MiniMax-AI/parsar-core/releases/latest/download/install.sh | bash
```

1. 在 Linux 主机上[安装 Core 和 Web](docs/getting-started/install.md)。安装指南包含环境要求、
发行包下载、本地试用和 HTTPS 配置。
2. 用安装器生成的 Core key 登录 Web,配置模型提供方,创建 Project 并签发应用 API key。
Expand Down
63 changes: 29 additions & 34 deletions apps/docs/content/docs/install.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ add nodes. Applications call Core's API with those keys.
6. [Add a node](/hosted-providers).

These pages describe the current source. Every bundle carries the docs that match it
under `docs/`. This private project supports fresh installation and repair of the
under `docs/`. Core supports fresh installation and repair of the
same release; historical-version upgrades and conversion are unsupported.

## Prerequisites
Expand All @@ -28,7 +28,7 @@ same release; historical-version upgrades and conversion are unsupported.
- A non-root user who can run `docker`. The installer refuses root.
- Free loopback ports 8091 (Core) and 8080 (Web), or
[other ports](#ports-and-directory).
- The GitHub CLI, `gh`, to download the bundle.
- curl to fetch the installation script; no GitHub CLI or login is required.

The Core host needs no KVM and no systemd user services, unless you choose
[native Core](#native-core).
Expand All @@ -45,48 +45,43 @@ public URL and set it later.

## Download a release

The repository is internal for now, so GitHub asks you to sign in first:
Every Release includes a standalone [install.sh](https://github.com/MiniMax-AI/parsar-core/releases/latest/download/install.sh).
It selects the latest published stable release by default, downloads that release's
offline bundle and checksum, verifies the archive, and runs its bundled installer.
You do not need to find a tag, commit SHA or archive filename.

```sh
gh auth login
```
## Install

Pick a release, download its offline bundle and check it:
Install the latest stable release:

```sh
gh release list --repo MiniMax-AI/parsar-core
mkdir -p "$HOME/.oac/releases" && cd "$HOME/.oac/releases"
gh release download <tag> --repo MiniMax-AI/parsar-core --pattern '*-linux-amd64-offline.tar.gz*'
sha256sum -c oac-<commit>-linux-amd64-offline.tar.gz.sha256
tar -xzf oac-<commit>-linux-amd64-offline.tar.gz
cd oac-<commit>-linux-amd64
curl -fsSL https://github.com/MiniMax-AI/parsar-core/releases/latest/download/install.sh | bash
```

`<tag>` is the release tag from the list, and `<commit>` is the source commit in the
asset names. The installer also checks every file in the bundle against its
`SHA256SUMS` before it changes anything.

Each release has two bundles:

| Bundle | Contains | Use it for |
| --- | --- | --- |
| `oac-<commit>-linux-amd64-offline.tar.gz` | Core, Web and PostgreSQL images, the installers and every node and Runtime file | Any installation. Web serves the node files to your nodes and self-hosted executors |
| `oac-<commit>-linux-amd64.tar.gz` | The same without the node and Runtime files | Core-only hosts, and installations that use only E2B. Web can't add nodes or connect self-hosted executors until the files are present |

To add the node files to the smaller bundle, create an `artifacts/` directory in the
extracted bundle, download the release's other `oac-<commit>-linux-amd64-*`
assets (not the two bundles) into it, then run `./install.sh`, or rerun it if the
installation already exists. Nodes download these files only from your Web console,
never from GitHub, so node hosts need no GitHub access.

## Install

From the extracted bundle:
For an HTTPS deployment, pass the public address:

```sh
./install.sh --public-url https://core.example
curl -fsSL https://github.com/MiniMax-AI/parsar-core/releases/latest/download/install.sh | bash -s -- --public-url https://core.example
```

To select a version, add `--version v1.2.3` after `bash -s --`. Explicit versions
may include prereleases; the default never selects one. Other arguments go unchanged
to the bundled installer. You can also download `install.sh` from the Release page
and run `bash install.sh --version v1.2.3`. The examples below use this saved script
or the bundle's existing `./install.sh`.

The downloader resolves the release once, verifies SHA-256 before extraction, and
retains the verified bundle under `~/.oac/releases/` for repair. It never replaces
an existing installation or upgrades it. To repair an installed version, select
that same version explicitly. The bundled installer also checks its own
`SHA256SUMS` before changing installation state.

For machines without GitHub access, transfer the Release's
`*-linux-amd64-offline.tar.gz` and matching `.sha256` file, verify and extract
them locally, then run the bundled `./install.sh`. The smaller non-offline archive
omits node and Runtime files and is intended for advanced Core-only or E2B setups;
use the offline bundle for the ordinary installation path.

The installer:

1. checks the host and the bundle, and loads the Core, Web and PostgreSQL images;
Expand Down
4 changes: 2 additions & 2 deletions apps/docs/content/guide-sources.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"docs/getting-started/README.md": "cdf8046c616574102a0ffc7644ac0fe82e63eb1906e6c9f1f6b635810e223757",
"docs/design-principles.md": "a33acd6e7bc80105a5c934d0be214c0cff59103e96c098f5b09179c86156c01d",
"docs/web/architecture.md": "80bdb8053c06c2b2030b193aae17d5434545f9c72af50e9d3df3ade522fe25ed",
"docs/getting-started/install.md": "e2043e0abdd7fc77bbad8d7fe3e17310421a94497c3b73236e653d525c8d34c1",
"docs/getting-started/install.md": "93213e3d2f8829ff1d5d32d89c30168c210a63d8073ede80d5e9382677ece239",
"docs/configuration.md": "0c15f6253233f4766cae5dda4d33a120c7c53a4770353a86db4890e2a8e7e078",
"docs/web/core-connection.md": "46f86520e70bf41079708e2c398655aa9087ad9488c8e661d9a73035d11098c4",
"docs/getting-started/quickstart.md": "238b4de1137edb8c2998b38f4525fea345a19fd4de7a455aa9c4c9e4fc3c9b36",
Expand All @@ -31,7 +31,7 @@
"content/docs/index.mdx": "13c2f2274ba4a7d2845e003a92b6816e0ae4a8c216029183acd0079c9b5ba094",
"content/docs/concepts.mdx": "bdb3d5e96d2c9c7912a52a3cda48bf3c120b8d7518b7e429213c1ca02e7be2f2",
"content/docs/execution-model.mdx": "c76a992e8f4ca175e8db7192a1c5eba4e3baf4889f47b001bc3749ee708b3e54",
"content/docs/install.mdx": "56dc38120a2ac7974c08497c0a18bff16df4b9c521575f2c7fbe16a27055e575",
"content/docs/install.mdx": "41d44ed9e8df1a4123815348151bb052ef39aad503b2e90c945e6a3e82d28d3c",
"content/docs/configure.mdx": "af63fb2ff5d61c3198fd54f1610f3782513682c3c0e13cfea425ba0de1dc4ca1",
"content/docs/bootstrap-projects-keys.mdx": "db119f9a3ad91fadd2558fa17681a6045910d0d02991db4b75e87d73e72c2bd5",
"content/docs/quickstart.mdx": "8b4794b3ec34aa068f41b4fdc7dadd5daebcbf35e9cbd37964f4a30ba20808b4",
Expand Down
10 changes: 3 additions & 7 deletions deploy/distribution/Runtime.Dockerfile
Original file line number Diff line number Diff line change
@@ -1,29 +1,25 @@
# Each input is an immutable Linux amd64 image built from the same Core revision.
# Reuse the native packages and isolation configuration from existing profiles.
# Reuse the native packages from existing profiles.
ARG CODEX_IMAGE
ARG CLAUDE_IMAGE
ARG MCODE_IMAGE
FROM ${CODEX_IMAGE} AS codex
FROM ${CLAUDE_IMAGE} AS claude
FROM ${MCODE_IMAGE}

# Keep the shared daemon, helpers and prebuilt tool-system seed from this base.
# Native harness packages remain outside the tool-system seed and workspace.
# Keep the shared daemon and dependencies from the MiniMax base.
# Native harness packages remain outside the workspace.
COPY --from=codex /usr/local/bin/codex /usr/local/bin/codex
COPY --from=codex /usr/local/codex-resources /usr/local/codex-resources
COPY --from=codex /etc/codex /etc/codex
COPY --from=claude /opt/claude-sdk /opt/claude-sdk
COPY --from=claude /usr/local/bin/oac-claude-shell-prefix /usr/local/bin/oac-claude-shell-prefix

ENV OAC_RUNTIME_CODEX_BIN=/usr/local/bin/codex \
OAC_RUNTIME_CODEX_PERMISSION_PROFILE=managed-workspace \
OAC_RUNTIME_CLAUDE_SDK_NODE=/usr/local/bin/node \
OAC_RUNTIME_CLAUDE_SDK_ENTRYPOINT=/opt/claude-sdk/dist/main.js \
OAC_RUNTIME_CLAUDE_SDK_WORKSPACE=managed

USER 1000:1000
RUN test "$(codex --version)" = "codex-cli 0.153.4" \
&& test -r /etc/codex/requirements.toml \
&& node /opt/claude-sdk/dist/runtime_check.js /opt/claude-sdk/dist/main.js \
&& node /opt/mcode-harness/check.mjs \
&& /opt/mcode-harness/native/cli.js --version
Loading
Loading