Skip to content

Stop publishing Core's admin port on the host - #406

Merged
RyanLee-Dev merged 2 commits into
mainfrom
stop-publishing-core-admin-port
Oct 3, 2026
Merged

RyanLee-Dev merged 2 commits into
mainfrom
stop-publishing-core-admin-port

Conversation

@RyanLee-Dev

@RyanLee-Dev RyanLee-Dev commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • ports.yaml publishes only Web. Core stays on the Docker-internal core:8091; nothing on the host needs it.
  • install.dev.sh copies the official ports.yaml instead of writing its own.
  • The "Script the Core API" helper runs curl in Core's network namespace (--network container:<core>) and passes the Core key on stdin.
  • Remove the unused oac healthcheck (compose uses oac-web healthcheck).
  • install.sh: containers own data/ (UIDs 65532/70), so an ordinary user's rm -rf failed both in failure cleanup and in the documented uninstall. Both now clear data/ through the init image first. Drop the redundant chmod (docker cp keeps the image's 0555).
  • AGENTS.md: keep it concise, reuse existing code and standard SDKs, avoid redundant code, expose nothing without a caller.
  • EN/ZH docs updated together; ZH source_hash recomputed. Dropped a stale ZH-only routing table.

Test plan

  • python3 -m unittest deploy/compose/test_compose.py deploy/test_install.py, go test ./cmd/oac, python3 scripts/ci_plan_test.py
  • Cloud install as an ordinary docker user with the v0.0.6 GHCR images and this branch's install.sh/ports.yaml: all services healthy; only Web published; /, /healthz, /docs 200, /v1/files 401; oac core-key --show works; the helper creates a Project and lists harnesses
  • Injected failure after startup: the installer removes its directory and containers
  • Documented uninstall removes the directory without root

yuanhe added 2 commits October 3, 2026 12:13
Core only needs Docker-internal core:8091; Web is the single published
entry. Operator scripts reach /core/v1 from Core's network namespace.
Remove the now-unused oac healthcheck and record the conciseness rule
in AGENTS.md.
Containers own data/, so the installer's failure cleanup and the
documented uninstall delete its contents through the init image before
removing the directory. docker cp already keeps oac's executable mode.
@RyanLee-Dev
RyanLee-Dev merged commit 5b0da47 into main Oct 3, 2026
19 checks passed
@RyanLee-Dev
RyanLee-Dev deleted the stop-publishing-core-admin-port branch October 3, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant