Skip to content

Simplify Core installation onto Compose and a Go oac command - #402

Merged
RyanLee-Dev merged 23 commits into
mainfrom
release-compose-assets
Oct 3, 2026
Merged

RyanLee-Dev merged 23 commits into
mainfrom
release-compose-assets

Conversation

@RyanLee-Dev

@RyanLee-Dev RyanLee-Dev commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • A release still publishes digest-pinned compose.yaml, ports.yaml and ports-https.yaml. Managed installs publish 80 and 443 from the start. Data stays bind-mounted under the installation directory.
  • install.sh is the whole host installer: it checks Docker, downloads those files, writes .env and starts Compose. The host does not need Python. The first successful start also saves the default microsandbox deployment.
  • oac is a Go command in the Core image. It implements status, start, stop, apply, domain, core-key, rotate-core-key, backup, uninstall and setup-sandbox. apply runs oac-core check-config before recreating services.
  • Managed HTTPS uses a fixed Caddyfile plus data/caddy/site.caddy. The domain service is the only container with the Docker socket. Web still calls it on the installation socket. Core reports the process settings it loaded and no longer reads an installer snapshot.
  • The Python Core installer, config.json rendering and oac.pyz are removed. The node installer stays Python.

Test plan

  • go test ./services/core/cmd/oac ./services/core/internal/processconfig ./services/core/cmd/server ./services/core/internal/api
  • python3 deploy/install/test_compose.py
  • python3 scripts/publish-core-release.test.py
  • python3 scripts/core-distribution-manifest.test.py
  • python3 scripts/ci_plan_test.py
  • python3 scripts/generate-harness-catalog.test.py
  • python3 -m unittest discover -s deploy/install -p 'test_*.py'
  • python3 scripts/compose-smoke.py against published images (needs Docker and network)
  • A clean host: install.sh, sign in, add a node, oac domain, failed certificate rollback

yuanhe and others added 2 commits October 2, 2026 23:35
The release renders compose.yaml from the template with that build's image digests and uploads it with ports.yaml. Manual build-<sha> drafts push the same GHCR images, so a candidate can be pulled before a version tag exists.

Co-authored-by: Cursor <cursoragent@cursor.com>
Core validates its environment in one place, including oac-core check-config, and no longer reads the installer settings file.

Co-authored-by: Cursor <cursoragent@cursor.com>
@RyanLee-Dev RyanLee-Dev changed the title Publish each release's Compose files and draft images Publish Compose assets and report the settings Core loaded Oct 2, 2026
The host installer only needs Docker. Core reports and checks its own process settings, and managed HTTPS is a small domain service instead of generated Caddy configuration.

Co-authored-by: Cursor <cursoragent@cursor.com>
@RyanLee-Dev RyanLee-Dev changed the title Publish Compose assets and report the settings Core loaded Simplify Core installation onto Compose and a Go oac command Oct 2, 2026
yuanhe and others added 14 commits October 3, 2026 00:27
Process settings live in .env, the gateway is the only public listener, and a failed first start no longer treats a free port as busy.

Co-authored-by: Cursor <cursoragent@cursor.com>
…setup.

The gateway image initializes data and is the only image with a Docker client. Core no longer carries one.

Co-authored-by: Cursor <cursoragent@cursor.com>
The initializer travels in the rendered Compose file, and the Chinese configuration heading uses the English anchor.

Co-authored-by: Cursor <cursoragent@cursor.com>
Stable releases move the latest tag, and PostgreSQL stays on the 16 Alpine line without a digest pin.

Co-authored-by: Cursor <cursoragent@cursor.com>
PostgreSQL can still hold the advisory lock after the previous worker's connection cleanup returns.

Co-authored-by: Cursor <cursoragent@cursor.com>
Managed HTTPS no longer starts a separate domain container. https.yaml turns
the gateway into `oac gateway`, which runs Caddy as 65532 beside the domain
API, so it is the only service with the Docker socket. Caddy keeps its
certificates under data/caddy/storage, and COMPOSE_PROFILES is gone.

Co-authored-by: Cursor <cursoragent@cursor.com>
`oac init` replaces deploy/distribution/init.py with the same directory
ownership, receipt verification and streamed release check, and `oac
healthcheck` replaces the gateway's inline Python. The ingress image no
longer installs Python, and the Compose smoke builds it from the checkout
so init and gateway changes are tested before release.

Co-authored-by: Cursor <cursoragent@cursor.com>
The Python modules that remained in deploy/install build node-install.pyz,
which installs sandbox nodes, not Core. They move to deploy/node with their
design rules restored in its README. Compose tests sit beside the Compose
files, the install.sh test beside install.sh, and the opt-in real-model
acceptance under scripts/acceptance. deploy/README.md describes the Core
installation and the oac command.

Co-authored-by: Cursor <cursoragent@cursor.com>
Core applies migrations at startup under a Postgres session lock, reads
the installation ID from OAC_INSTALLATION_ID_FILE, and treats empty
process settings as their defaults, enabling every registered Harness
when OAC_HARNESSES is unset. The Core image declares its own artifact
and native installer paths. Web derives literal-IP bootstrap from a
managed HTTP origin and prints the Core key with `oac-web core-key`.
The separate migrate command and `oac setup-sandbox` are removed.

Co-authored-by: Cursor <cursoragent@cursor.com>
Compose drops the migrate and credentials services and the duplicated
defaults; host installs still publish Core on loopback for scripts. The
installer verifies one checksum list, writes only the Compose selection
and listener settings, and leaves the sandbox backend to Web. The smoke
test builds Core, Web and the gateway from the checkout, and the CI plan
selects it for their changes. Documentation follows in both languages.

Co-authored-by: Cursor <cursoragent@cursor.com>
The Harness catalog check no longer reads defaults from the Compose
template, which now passes them through to Core. The native installer
directory returns to the Compose file: the Core image used by other
checks ships no catalog, so declaring it in the image stopped startup.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
oac reaches Docker through its client library and only execs caddy, so the
docker:cli base, Compose plugin, buildx, git and openssh were never used.
Alpine with ca-certificates plus the two static binaries is enough.

Co-authored-by: Cursor <cursoragent@cursor.com>
Web forwards /v1 and /api/v1 to Core unchanged, so the gateway service,
its image's Caddy, https.yaml and the domain setup (oac domain, the
domain API and the System page) are gone. An installation is init,
database, core and web; the operator's reverse proxy or hosting platform
terminates HTTPS and routes to web:8080. No service receives a Docker
socket.

Co-authored-by: Cursor <cursoragent@cursor.com>
@blacksmith-sh

This comment has been minimized.

yuanhe and others added 4 commits October 3, 2026 11:16
The console no longer offers domain setup, so the pages, e2e spec and
copy that pointed at it now say to set OAC_PUBLIC_URL. The English and
Chinese docs describe Web forwarding /v1 and /api/v1, and their headings
and inline literals match again.

Co-authored-by: Cursor <cursoragent@cursor.com>
The acceptance tests still looked for the removed domain setup action.
The notice now points at System, and the E2B rejection follows it there.

Co-authored-by: Cursor <cursoragent@cursor.com>
Web forwards /docs the same way as /v1 and /api/v1, and keeps 64 idle
connections to Core. A test completes a real WebSocket handshake through
that proxy. The install and API docs match this entry path.

Co-authored-by: Cursor <cursoragent@cursor.com>
install.local.sh builds Core, Web and init from the working tree and
starts them on localhost. It publishes only Web, so a host service on
8091 does not block a trial.

Co-authored-by: Cursor <cursoragent@cursor.com>
@blacksmith-sh

This comment has been minimized.

yuanhe and others added 2 commits October 3, 2026 11:49
A shell script that only selects hygiene fails the CI plan. The local
installer is an install input, like install.sh.

Co-authored-by: Cursor <cursoragent@cursor.com>
It builds and starts this tree for development. install.sh remains the
published installer.
@RyanLee-Dev

Copy link
Copy Markdown
Contributor Author

这个 PR 做了什么

把 Core 的安装从「Python 安装器 + config.json + 多个辅助服务」收成「一个 Compose 文件、一份 .env、一条 Go 写的 oac」。对外只剩 Web 一个端口。HTTPS 和域名由操作者自己的反向代理或 Dokploy / Coolify 负责,安装本身不再申请证书。

正式安装:

curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash

开发检出用 ./deploy/install.dev.sh 从当前代码构建镜像并在 http://localhost:8080 启动。install.sh 仍是发布出去的安装器。

前后对比

以前,安装器、迁移、取密钥、路由、证书各占一个服务。网关镜像基于 docker:cli,带着用不到的 Docker CLI、Compose 和 buildx。域名设置让网关以 root 常驻,并挂上 Docker socket。

flowchart LR
  user[浏览器 / 应用 / 节点] --> gw[gateway · root]
  gw -->|/v1 /api/v1| core[core]
  gw -->|其余| web[web]
  init[init] --> db[(PostgreSQL)]
  migrate[migrate] --> db
  db --> core
  cred[credentials] -.-> web
  gw -.->|Docker socket · 申请证书| dock[Docker]
Loading

现在常驻的是 Web、Core、PostgreSQL。init 只跑一次:生成密钥、改目录属主、校验节点元数据,然后退出。Web 提供控制台,并把 /v1、/api/v1、/docs 原样转给 Core。

flowchart LR
  user[浏览器 / 应用 / 节点] -->|一个端口| web[web · 65532]
  web -->|/v1 /api/v1 /docs 原样转发| core[core · 65532]
  web -->|/core/v1 · 附带登录密钥| core
  core --> db[(PostgreSQL)]
  init[init · 一次性 root] -.->|密钥和目录属主| db
  init -.-> web
Loading
以前 现在
安装入口 Python 安装器,config.json install.sh + Compose + .env
常驻服务 gateway、core、web、database,另加 migrate、credentials web、core、database
一次性任务 init,以及独立的 migrate init。Core 启动时自己做迁移,并用 Postgres 会话锁避免并发
对外端口 网关 8080,托管 HTTPS 再占 80/443,Core 在 127.0.0.1:8091 Web 的 OAC_WEB_PORT(8080)。Core 仍在 127.0.0.1:8091,只给主机脚本
路由 Caddy:/v1、/api/v1 到 Core,其余到 Web Web 自己转发 /v1、/api/v1、/docs。/docs 是不带登录的接口文档
HTTPS oac domain 在网关里申请证书 反向代理或托管平台终止 TLS,把流量转到 web:8080。OAC_PUBLIC_URL 记录这个源地址
密钥 credentials 服务 docker compose exec web oac-web core-key,或 oac core-key --show
默认值 Compose 和环境变量各写一份 空值即默认,只定义在 Core 的 processconfig
权限 网关常驻 root,并持有 Docker socket 常驻服务都是 65532。没有任何容器挂 Docker socket。root 只出现在一次性的 init 里,用来 chown
网关镜像 约 269 MB,其中约 210 MB 是用不到的 Docker 工具 init 镜像约 18 MB:Alpine、oac、CA 证书

优点

  • 安装面和 Dify 这类多服务产品对齐到「一个入口 + 一个后端 + 一个数据库」。操作者只记一个地址。
  • Web 和 Core 仍然是两个进程。Core 持有数据库密码和凭据加密密钥;Web 只持有登录密钥,并把已登录的 /core/v1 附上这个密钥再转发。沙箱和节点走 /v1、/api/v1 时,用的是调用方自己的凭据。
  • 转发是 Go 的反向代理:流式响应立即刷出,不设读写总超时。WebSocket 在 Core 返回 101 后按字节对拷。到 Core 的空闲连接保留 64 条。
  • 删掉了域名状态机、https.yaml、domain.go 和网关里的 Caddy。证书失败不再是安装本身的故障。

发布时要注意

install.sh 下载的是该版本发布页上的 Compose 文件,镜像标签是 latest。新的 Web 才会转发 /v1,也才会提供 oac-web healthcheck。这一版的 Core、Web、ingress 镜像必须和 Compose 文件一起发布。先发 Compose、镜像还停在旧版本,安装起不来。

@RyanLee-Dev
RyanLee-Dev merged commit a2946a7 into main Oct 3, 2026
24 checks passed
@RyanLee-Dev
RyanLee-Dev deleted the release-compose-assets branch October 3, 2026 03:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant