Skip to content

Run the deployment's agent host - #534

Merged
SaladDay merged 4 commits into
aos/cutoverfrom
aos/pr5a-agent-host-deployment
Oct 8, 2026
Merged

SaladDay merged 4 commits into
aos/cutoverfrom
aos/pr5a-agent-host-deployment

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

The deployment runs its own agent host. Nothing places Sessions on it yet; PR5c does.

Registration

  • The aos migration *_sandbox_link_authority.sql is edited in place: an agent-host device needs no tenant. It has never shipped.
  • oac init generates the agent-host identity secrets/agent-host/identity.json ({runtime_id, credential}) once, next to its peers, and creates the agent host's state directory agent-host/.
  • After migrations, Core upserts the agent-host device from OAC_AGENT_HOST_IDENTITY_FILE, storing the credential the way Link authentication reads it. A new credential advances the revision, and a revocation is never undone. The identity is required while the Runtime gateway runs (OAC_PUBLIC_URL set).

Compose and release

  • An agent-host service on the agent-host image runs oac-daemon agent-host --identity-file --core-url http://127.0.0.1:8091 in Core's network namespace, with the container flags from docs/configuration.md#agent-host-container, the identity mounted read-only and the Session homes in the data volume's agent-host/.
  • The distribution build publishes the agent-host image beside Core and Web, reusing the Harness payload steps of build-agent-host-images.sh; install.dev.sh builds it.
  • The Compose smoke builds a placeholder agent-host image (the real base and CA roots, oac-daemon, oac-process-shim, a manifest without Harnesses) and waits until the agent host connects, after the first start and after a restart. Daemon changes now select the smoke job.

Docs

docs/configuration.md (the Compose agent host, the identity secret, the data directory), docs/maintainers.md (the release builds the image) and services/core/IMPLEMENTATION.md, with the zh translations.

Checks

  • Go tests for cmd/oac, cmd/server, processconfig, sessionpg, runtimegateway; the Link-authority and agent-host integration tests, including TestRegisteredAgentHostAuthenticates; test_compose.py, the distribution and installer tests; make check-names check-docs check-ci.
  • The full compose-smoke.py could not build its images on the dev host (no internet from Docker); a run with the smoke's own Core and agent-host images connected after start, restart and down/up. CI runs the full smoke.

Open: the agent-host image is linux/amd64 only (arm64 decision pending before the final merge).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

oac init generates the agent-host identity, a runtime ID and credential,
next to the other secrets. With OAC_PUBLIC_URL, Core requires
OAC_AGENT_HOST_IDENTITY_FILE and registers that identity as a device with
no tenant after migrations, so the Link and the Runtime gateway accept it.
Compose runs the agent-host service in Core's network namespace with the
identity mounted read-only, and Core reads the same file. The distribution
builds the agent-host image from the payloads its Runtime image builders
prepare and the release publishes it for Linux amd64 beside Core and Web,
which removes the prebuilt Harness image inputs. The local installer and the
Compose smoke build the agent-host image from the checkout.
The agent-host service mounts the data volume's agent-host/ at its state
directory, which initialization creates and treats like other existing data,
so Session homes outlive the container and travel with the installation's
backup. The Compose smoke builds the agent host with its CA roots and process
shim and checks that it connects to Core, and daemon changes now select the
smoke. The configuration guide keeps each agent-host fact in one place.
@SaladDay
SaladDay merged commit 92dbb51 into aos/cutover Oct 8, 2026
25 checks passed
@SaladDay
SaladDay deleted the aos/pr5a-agent-host-deployment branch October 8, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant