You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: AGENTS.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,6 +8,8 @@ OpenAgentCore is protocol-first and modular. Core orchestrates operations that p
8
8
9
9
OpenAgentCore is infrastructure. Change a boundary only when the existing protocol cannot express the behavior, and make that the smallest change that leaves the design intact. Hold the code to the standard of a careful, widely used open-source service.
10
10
11
+
Keep it concise. Write elegant code that reuses existing code and standard SDKs as far as possible, and avoid redundant code. Expose nothing that does not need to be exposed: no port, route, command or setting without a caller.
12
+
11
13
### Protocols at every boundary
12
14
13
15
- Each boundary between components has exactly one protocol: one code file (interface, wire types and validators) and one document. A protocol change edits both and every implementation in one change, reviewed on its own.
Copy file name to clipboardExpand all lines: docs/api/index.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ Core serves three namespaces. Each has one kind of caller and its own credential
12
12
13
13
A credential used in another namespace gets 401: a Project API key on `/core/v1` or `/api/v1`, the Core key on `/v1` or `/api/v1`. How Projects and keys behave is in [Projects own assets](../concepts.md#projects-own-assets).
14
14
15
-
**Routing.** Web forwards `/v1`, `/api/v1` and `/docs` to Core unchanged ([console server](../web/console-server.md)). A signed-in browser reaches `/core/v1` through Web, which adds the Core key. Operator scripts call `/core/v1` on `127.0.0.1:8091` ([script the Core API](../getting-started/operations.md#script-the-core-api)).
15
+
**Routing.** Web forwards `/v1`, `/api/v1` and `/docs` to Core unchanged ([console server](../web/console-server.md)). A signed-in browser reaches `/core/v1` through Web, which adds the Core key. Operator scripts call `/core/v1`inside Core's network namespace on the Core host ([script the Core API](../getting-started/operations.md#script-the-core-api)).
16
16
17
17
**API reference.** Core serves a read-only Swagger UI of the three namespaces at `/docs`, and the documents at `/docs/openapi.yaml`, `/docs/core.openapi.yaml` and `/docs/runtime.openapi.yaml`. No credential is required, and the page sends no API requests. Open it on the console origin, for example `http://localhost:8080/docs`. The browser loads Swagger UI from `unpkg.com`.
Copy file name to clipboardExpand all lines: docs/configuration.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,7 +46,7 @@ To change it, point the reverse proxy at the new address first, then edit `OAC_P
46
46
|`OAC_PUBLIC_URL`|`http://localhost:8080`| Origin applications, nodes, sandboxes and self-hosted executors use. Managed domain setup writes the HTTPS origin and recreates Core and Web |
47
47
|`OAC_HOST`|`127.0.0.1`| Address published by `ports.yaml`. `install.sh` sets `0.0.0.0`|
48
48
|`OAC_WEB_PORT`|`8080`| Host port of Web |
49
-
|`COMPOSE_FILE`|`compose.yaml:ports.yaml`| The Compose files. `ports.yaml` publishes Web and Core's loopback admin API; hosting platforms omit it |
49
+
|`COMPOSE_FILE`|`compose.yaml:ports.yaml`| The Compose files. `ports.yaml` publishes Web; hosting platforms omit it |
50
50
|`OAC_LOG_LEVEL`|`info`|`debug`, `info`, `warn` or `error`|
51
51
|`OAC_LOG_FORMAT`|`auto`|`auto`, `text` or `json`|
@@ -135,7 +135,7 @@ The installer creates the installation directory, `~/.oac/core` by default, with
135
135
|`data/state/`| Private Provider state, including E2B receipts | Core |
136
136
|`.oac.lock`| The installation lock | Mutating `oac` commands |
137
137
138
-
The Compose project is named `oac-<10 hex digits>`. Its services are `init`, `database`, `core` and `web`. Core applies database migrations when it starts. `web` serves the console and forwards `/v1` and `/api/v1` to Core, and it is the only service that publishes `OAC_WEB_PORT`. Host installs also publish Core's admin API on `127.0.0.1:8091`. No service receives a Docker socket. Apart from Docker's storage, nothing is written outside the installation directory.
138
+
The Compose project is named `oac-<10 hex digits>`. Its services are `init`, `database`, `core` and `web`. Core applies database migrations when it starts. `web` serves the console and forwards `/v1` and `/api/v1` to Core, and it is the only service with a published port, `OAC_WEB_PORT`. No service receives a Docker socket. Apart from Docker's storage, nothing is written outside the installation directory.
139
139
140
140
## Appendix: Core environment without the installer
Copy file name to clipboardExpand all lines: docs/getting-started/install-options.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -70,7 +70,7 @@ The installer saves no sandbox backend. After signing in, open **System** → **
70
70
71
71
## Listeners and access
72
72
73
-
The default installation publishes Web on `--web-port` (8080) at `--host 0.0.0.0`. Core's admin API stays on `127.0.0.1:8091`. PostgreSQL stays private. `--host` is an IPv4 or IPv6 address, without a port, scheme or zone. Use a concrete server IP in the browser, not a wildcard.
73
+
The default installation publishes Web on `--web-port` (8080) at `--host 0.0.0.0`. Core and PostgreSQL stay private. `--host` is an IPv4 or IPv6 address, without a port, scheme or zone. Use a concrete server IP in the browser, not a wildcard.
74
74
75
75
`--public-url` sets `OAC_PUBLIC_URL`, the origin applications, nodes and executors use. Set it to the HTTPS origin your reverse proxy serves.
Copy file name to clipboardExpand all lines: docs/getting-started/install.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,7 +19,7 @@ This page follows the default path. Every flag, existing reverse proxies and off
19
19
- Linux amd64 and curl.
20
20
- Docker Engine with Docker Compose 2.26.0 or newer (`docker compose version`).
21
21
- An account that can run `docker` and write to its home directory. Ordinary users and root both work; the installer never calls sudo.
22
-
- Free port 8080 for Web. Core's admin API uses `127.0.0.1:8091`. See [ports](./install-options.md#ports). Docker must be able to publish them; the installer does not change host policy.
22
+
- Free port 8080 for Web. See [ports](./install-options.md#ports). Docker must be able to publish it; the installer does not change host policy.
23
23
- For anything off this machine, the origin in `OAC_PUBLIC_URL` must be the address browsers, nodes and executors use. You can sign in on this machine first.
24
24
25
25
The Core host needs no KVM; nodes that run microsandbox do.
@@ -40,7 +40,7 @@ The script downloads that release's Compose files, checks their SHA-256, and:
40
40
41
41
1. checks Linux amd64, Docker Compose 2.26 or newer, and that the ports it will publish are free;
42
42
2. creates the [installation directory](../configuration.md#installation-directory), `~/.oac/core`, writes `.env`, and copies the `oac` command out of the Core image;
43
-
3. starts the services with Docker Compose. Web serves the console on port 8080 and forwards `/v1`, `/api/v1` and `/docs` to Core. Core's admin API stays on `127.0.0.1:8091`. PostgreSQL is not published.
43
+
3. starts the services with Docker Compose. Web serves the console on port 8080 and forwards `/v1`, `/api/v1` and `/docs` to Core. Core and PostgreSQL are not published.
44
44
45
45
It saves no sandbox backend, adds no node, creates no Project or key and makes no model request. It ends by printing the console address and how to read the Core key.
|`oac apply`| Runs `oac-core check-config`, then `docker compose up -d --wait`. A failed check changes no service |
21
21
|`oac core-key [--show]`| Prints the Core key path, or the key itself with `--show`|
22
22
|`oac rotate-core-key`| Replaces the Core key and restarts Core and Web |
23
-
|`docker compose down --rmi all`| Removes the containers and images. Delete the installation directory afterwards|
23
+
|`docker compose down`| Removes the containers. Data is kept; to delete it, [uninstall](#uninstall)|
24
24
25
25
For a second installation, use its directory, such as `~/.oac/second`.
26
26
@@ -70,14 +70,15 @@ Keep it private. Web reads `data/secrets/web/core.key`. Core reads only its SHA-
70
70
71
71
### Script the Core API
72
72
73
-
Run scripts on the Core host against Core's loopback port. This helper reads the key from its file, keeping it off the command line:
73
+
Core publishes no host port. On the Core host, this helper runs `curl` in Core's network namespace and passes the key on stdin, keeping it off the command line:
`down` removes the containers and images. `rm` removes the installation directory. Do the first only when you mean to delete the data.
147
+
The containers own `data/`, so the `init` image deletes its contents; then `down --rmi all` removes the images and `rm` removes the installation directory. Run these only when you mean to delete the data.
144
148
145
149
All data goes with it: Projects and API keys, Session history, stored credentials and the Core key. To keep the data, stop the installation with `docker compose stop` instead, or [back it up](#back-up) first.
146
150
@@ -183,7 +187,7 @@ Mutating `oac` commands hold `.oac.lock`. If another command holds it, retry aft
| Web and the API | Web publishes `OAC_WEB_PORT` (8080) on `OAC_HOST`| Web publishes `OAC_WEB_PORT` on `OAC_HOST`. Your proxy should use `127.0.0.1`|
186
-
| Core admin API |`127.0.0.1:8091`. Web forwards `/v1`, `/api/v1` and `/docs`|`127.0.0.1:8091`. Web forwards `/v1`, `/api/v1` and `/docs`|
190
+
| Core | No published port. Web forwards `/v1`, `/api/v1` and `/docs`|No published port. Web forwards `/v1`, `/api/v1` and `/docs`|
187
191
| PostgreSQL | No published port | No published port |
188
192
189
193
Web signs administrators in with the Core key, checks the origin of every request, and forwards signed-in `/core/v1` requests to Core with the Core key, which stays on the server. It forwards `/v1` and `/api/v1` to Core unchanged, with the caller's own credential, serves only the non-secret node payload at `/node-install/`, and has no Docker or KVM access. Machine routes under `/api/v1` use their own enrollment and connection credentials. No service receives a Docker socket.
0 commit comments