Ship a zero-node Core installer with opt-in local sandboxes - #48
Merged
Merged
Conversation
SaladDay
marked this pull request as ready for review
September 23, 2026 11:09
This was referenced Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Install Core, the existing Web console and PostgreSQL with zero execution nodes by default. Local sandbox provisioning is explicit:
Default Core receives no Docker socket, host devices or managed-provider configuration, and installation imports no Runtime or invokes a model. Core-only and Web-only modes remain available. Repeat installation preserves identities, secrets and data; automatic revision/provider migration is excluded.
The matched distribution contains immutable service/Runtime images, source provenance and checksums, a public landing page, and deployment/API/operations docs. A standalone server-side console proxy keeps the Core caller key out of browser assets. Optional microsandbox runs Core as a native user service to preserve compute during a Core restart. Its SDK-owned
/environmentdisk supports workspace export and native full checkpoint recovery. The build entrypoint normalizes payload permissions for non-root services even when invoked with umask 077.Validation
Candidate
a5b4d140f5dd3ee6315baa5a90e6700882c73562, based on maine4b124c:make checkon zju with a dedicated PostgreSQL database passed, including 94/94 browser checks; 33 installer tests and 5 manifest tests passed.Archive SHA256:
88172cde7f35f6cc56cdc89992e5b7b31838eb2fa5d5b73f0478af60e04c6032.Evidence:
~/.parsar/acceptance/landing-mx1-zero/on mx1 and the operator workstation; build and full-gate evidence under~/.parsar/acceptance/landing-mx1-build-release/andlanding-mx1-check/on zju. Test Sessions/Runtime resources are released through the public API; the default zero-node deployment is retained for inspection.Boundaries
Linux amd64 is qualified. Microsandbox requires host KVM access and user-service lingering; host reboot/cold recovery and automatic upgrades/provider migration are not qualified. No Web application redesign, future node enrollment, PR #30, advanced Templates or new public protocol behavior is included. This is installer acceptance, not a claim of complete Agents API compatibility.