Simplify Core installation onto Compose and a Go oac command - #402
Merged
Merged
Conversation
The release renders compose.yaml from the template with that build's image digests and uploads it with ports.yaml. Manual build-<sha> drafts push the same GHCR images, so a candidate can be pulled before a version tag exists. Co-authored-by: Cursor <cursoragent@cursor.com>
Core validates its environment in one place, including oac-core check-config, and no longer reads the installer settings file. Co-authored-by: Cursor <cursoragent@cursor.com>
The host installer only needs Docker. Core reports and checks its own process settings, and managed HTTPS is a small domain service instead of generated Caddy configuration. Co-authored-by: Cursor <cursoragent@cursor.com>
Process settings live in .env, the gateway is the only public listener, and a failed first start no longer treats a free port as busy. Co-authored-by: Cursor <cursoragent@cursor.com>
…setup. The gateway image initializes data and is the only image with a Docker client. Core no longer carries one. Co-authored-by: Cursor <cursoragent@cursor.com>
The initializer travels in the rendered Compose file, and the Chinese configuration heading uses the English anchor. Co-authored-by: Cursor <cursoragent@cursor.com>
Stable releases move the latest tag, and PostgreSQL stays on the 16 Alpine line without a digest pin. Co-authored-by: Cursor <cursoragent@cursor.com>
PostgreSQL can still hold the advisory lock after the previous worker's connection cleanup returns. Co-authored-by: Cursor <cursoragent@cursor.com>
Managed HTTPS no longer starts a separate domain container. https.yaml turns the gateway into `oac gateway`, which runs Caddy as 65532 beside the domain API, so it is the only service with the Docker socket. Caddy keeps its certificates under data/caddy/storage, and COMPOSE_PROFILES is gone. Co-authored-by: Cursor <cursoragent@cursor.com>
`oac init` replaces deploy/distribution/init.py with the same directory ownership, receipt verification and streamed release check, and `oac healthcheck` replaces the gateway's inline Python. The ingress image no longer installs Python, and the Compose smoke builds it from the checkout so init and gateway changes are tested before release. Co-authored-by: Cursor <cursoragent@cursor.com>
The Python modules that remained in deploy/install build node-install.pyz, which installs sandbox nodes, not Core. They move to deploy/node with their design rules restored in its README. Compose tests sit beside the Compose files, the install.sh test beside install.sh, and the opt-in real-model acceptance under scripts/acceptance. deploy/README.md describes the Core installation and the oac command. Co-authored-by: Cursor <cursoragent@cursor.com>
Core applies migrations at startup under a Postgres session lock, reads the installation ID from OAC_INSTALLATION_ID_FILE, and treats empty process settings as their defaults, enabling every registered Harness when OAC_HARNESSES is unset. The Core image declares its own artifact and native installer paths. Web derives literal-IP bootstrap from a managed HTTP origin and prints the Core key with `oac-web core-key`. The separate migrate command and `oac setup-sandbox` are removed. Co-authored-by: Cursor <cursoragent@cursor.com>
Compose drops the migrate and credentials services and the duplicated defaults; host installs still publish Core on loopback for scripts. The installer verifies one checksum list, writes only the Compose selection and listener settings, and leaves the sandbox backend to Web. The smoke test builds Core, Web and the gateway from the checkout, and the CI plan selects it for their changes. Documentation follows in both languages. Co-authored-by: Cursor <cursoragent@cursor.com>
The Harness catalog check no longer reads defaults from the Compose template, which now passes them through to Core. The native installer directory returns to the Compose file: the Core image used by other checks ships no catalog, so declaring it in the image stopped startup. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
oac reaches Docker through its client library and only execs caddy, so the docker:cli base, Compose plugin, buildx, git and openssh were never used. Alpine with ca-certificates plus the two static binaries is enough. Co-authored-by: Cursor <cursoragent@cursor.com>
Web forwards /v1 and /api/v1 to Core unchanged, so the gateway service, its image's Caddy, https.yaml and the domain setup (oac domain, the domain API and the System page) are gone. An installation is init, database, core and web; the operator's reverse proxy or hosting platform terminates HTTPS and routes to web:8080. No service receives a Docker socket. Co-authored-by: Cursor <cursoragent@cursor.com>
This comment has been minimized.
This comment has been minimized.
The console no longer offers domain setup, so the pages, e2e spec and copy that pointed at it now say to set OAC_PUBLIC_URL. The English and Chinese docs describe Web forwarding /v1 and /api/v1, and their headings and inline literals match again. Co-authored-by: Cursor <cursoragent@cursor.com>
The acceptance tests still looked for the removed domain setup action. The notice now points at System, and the E2B rejection follows it there. Co-authored-by: Cursor <cursoragent@cursor.com>
Web forwards /docs the same way as /v1 and /api/v1, and keeps 64 idle connections to Core. A test completes a real WebSocket handshake through that proxy. The install and API docs match this entry path. Co-authored-by: Cursor <cursoragent@cursor.com>
install.local.sh builds Core, Web and init from the working tree and starts them on localhost. It publishes only Web, so a host service on 8091 does not block a trial. Co-authored-by: Cursor <cursoragent@cursor.com>
This comment has been minimized.
This comment has been minimized.
A shell script that only selects hygiene fails the CI plan. The local installer is an install input, like install.sh. Co-authored-by: Cursor <cursoragent@cursor.com>
It builds and starts this tree for development. install.sh remains the published installer.
Contributor
Author
这个 PR 做了什么把 Core 的安装从「Python 安装器 + 正式安装: curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash开发检出用 前后对比以前,安装器、迁移、取密钥、路由、证书各占一个服务。网关镜像基于 flowchart LR
user[浏览器 / 应用 / 节点] --> gw[gateway · root]
gw -->|/v1 /api/v1| core[core]
gw -->|其余| web[web]
init[init] --> db[(PostgreSQL)]
migrate[migrate] --> db
db --> core
cred[credentials] -.-> web
gw -.->|Docker socket · 申请证书| dock[Docker]
现在常驻的是 Web、Core、PostgreSQL。 flowchart LR
user[浏览器 / 应用 / 节点] -->|一个端口| web[web · 65532]
web -->|/v1 /api/v1 /docs 原样转发| core[core · 65532]
web -->|/core/v1 · 附带登录密钥| core
core --> db[(PostgreSQL)]
init[init · 一次性 root] -.->|密钥和目录属主| db
init -.-> web
优点
发布时要注意
|
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
compose.yaml,ports.yamlandports-https.yaml. Managed installs publish 80 and 443 from the start. Data stays bind-mounted under the installation directory.install.shis the whole host installer: it checks Docker, downloads those files, writes.envand starts Compose. The host does not need Python. The first successful start also saves the default microsandbox deployment.oacis a Go command in the Core image. It implementsstatus,start,stop,apply,domain,core-key,rotate-core-key,backup,uninstallandsetup-sandbox.applyrunsoac-core check-configbefore recreating services.data/caddy/site.caddy. Thedomainservice is the only container with the Docker socket. Web still calls it on the installation socket. Core reports the process settings it loaded and no longer reads an installer snapshot.config.jsonrendering andoac.pyzare removed. The node installer stays Python.Test plan
go test ./services/core/cmd/oac ./services/core/internal/processconfig ./services/core/cmd/server ./services/core/internal/apipython3 deploy/install/test_compose.pypython3 scripts/publish-core-release.test.pypython3 scripts/core-distribution-manifest.test.pypython3 scripts/ci_plan_test.pypython3 scripts/generate-harness-catalog.test.pypython3 -m unittest discover -s deploy/install -p 'test_*.py'python3 scripts/compose-smoke.pyagainst published images (needs Docker and network)install.sh, sign in, add a node,oac domain, failed certificate rollback