Repository navigation
Run the deployment's agent host - #534
Merged
Merged
Conversation
oac init generates the agent-host identity, a runtime ID and credential, next to the other secrets. With OAC_PUBLIC_URL, Core requires OAC_AGENT_HOST_IDENTITY_FILE and registers that identity as a device with no tenant after migrations, so the Link and the Runtime gateway accept it.
Compose runs the agent-host service in Core's network namespace with the identity mounted read-only, and Core reads the same file. The distribution builds the agent-host image from the payloads its Runtime image builders prepare and the release publishes it for Linux amd64 beside Core and Web, which removes the prebuilt Harness image inputs. The local installer and the Compose smoke build the agent-host image from the checkout.
The agent-host service mounts the data volume's agent-host/ at its state directory, which initialization creates and treats like other existing data, so Session homes outlive the container and travel with the installation's backup. The Compose smoke builds the agent host with its CA roots and process shim and checks that it connects to Core, and daemon changes now select the smoke. The configuration guide keeps each agent-host fact in one place.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The deployment runs its own agent host. Nothing places Sessions on it yet; PR5c does.
Registration
*_sandbox_link_authority.sqlis edited in place: an agent-host device needs no tenant. It has never shipped.oac initgenerates the agent-host identitysecrets/agent-host/identity.json({runtime_id, credential}) once, next to its peers, and creates the agent host's state directoryagent-host/.OAC_AGENT_HOST_IDENTITY_FILE, storing the credential the way Link authentication reads it. A new credential advances the revision, and a revocation is never undone. The identity is required while the Runtime gateway runs (OAC_PUBLIC_URLset).Compose and release
agent-hostservice on the agent-host image runsoac-daemon agent-host --identity-file --core-url http://127.0.0.1:8091in Core's network namespace, with the container flags fromdocs/configuration.md#agent-host-container, the identity mounted read-only and the Session homes in the data volume'sagent-host/.build-agent-host-images.sh;install.dev.shbuilds it.oac-daemon,oac-process-shim, a manifest without Harnesses) and waits until the agent host connects, after the first start and after a restart. Daemon changes now select the smoke job.Docs
docs/configuration.md(the Compose agent host, the identity secret, the data directory),docs/maintainers.md(the release builds the image) andservices/core/IMPLEMENTATION.md, with the zh translations.Checks
cmd/oac,cmd/server,processconfig,sessionpg,runtimegateway; the Link-authority and agent-host integration tests, includingTestRegisteredAgentHostAuthenticates;test_compose.py, the distribution and installer tests;make check-names check-docs check-ci.compose-smoke.pycould not build its images on the dev host (no internet from Docker); a run with the smoke's own Core and agent-host images connected after start, restart and down/up. CI runs the full smoke.Open: the agent-host image is linux/amd64 only (arm64 decision pending before the final merge).
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.