Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions deploy/kubernetes/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,3 +85,15 @@ Keep the existing claim's class and size. This cluster's `cbs` StorageClass does
- **No domain setup in Web.** There is no installer socket, so the public origin comes from `OAC_PUBLIC_URL` and your external ingress, not from the console.
- **No `oac` command.** The maintenance commands ship in the Core image: `kubectl exec deploy/oac-core -- oac-core-device …`. [Operations](../../docs/getting-started/operations.md) covers keys and backup.
- **A rollout signs operators out** of the console, because Web holds its sessions in memory.

## Public routing on TKE

The Services use NodePort for the existing qcloud CLB controller. Keep DNS, certificates and ingress separate from the image rollout workflow. `prod/ingress.yaml.tpl` adds one host to an existing CLB and routes `/v1` and `/api/v1` to Core and other paths to Web. It preserves the original request paths.

Prepare an Opaque Secret in the deployment namespace with `qcloud_cert_id` referencing a Tencent Cloud certificate covering the hostname. Set `OAC_CLB_ID`, `OAC_PUBLIC_HOST` and `OAC_TLS_SECRET`, then apply the template:

```sh
envsubst '$OAC_CLB_ID $OAC_PUBLIC_HOST $OAC_TLS_SECRET' < deploy/kubernetes/prod/ingress.yaml.tpl | kubectl --context sandbase-prod -n openagentcore apply -f -
```

For this installation, the host is `agentcore.sandbase.ai`, the shared CLB is `lb-9cr62q4u` and the certificate reference Secret is `oac-tls-cert`. After the controller reports Ready, verify HTTPS `/healthz`, the Web home page, unauthenticated `/v1/agents` returning 401 and a Runtime WebSocket upgrade on `/api/v1/agent-daemon/ws`.
2 changes: 1 addition & 1 deletion deploy/kubernetes/prod/core.yaml.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,7 @@ metadata:
app.kubernetes.io/name: oac-core
app.kubernetes.io/part-of: openagentcore
spec:
type: ClusterIP
type: NodePort
selector:
app: oac-core
ports:
Expand Down
47 changes: 47 additions & 0 deletions deploy/kubernetes/prod/ingress.yaml.tpl
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# Applied separately after DNS and the qcloud certificate reference are ready.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: oac
labels:
app.kubernetes.io/part-of: openagentcore
annotations:
kubernetes.io/ingress.class: qcloud
kubernetes.io/ingress.existLbId: "${OAC_CLB_ID}"
ingress.cloud.tencent.com/enable-group: "true"
ingress.cloud.tencent.com/auto-rewrite: "true"
ingress.cloud.tencent.com/rewrite-support: "true"
kubernetes.io/ingress.rule-mix: "true"
kubernetes.io/ingress.extensiveParameters: '{"ConnectTimeout":300000,"SendTimeout":900000,"ReadTimeout":900000}'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Configure timeouts on the existing listener

When the reused CLB does not already have these timeout values, this annotation will not apply them: Tencent documents kubernetes.io/ingress.extensiveParameters as parameters used only when creating a CLB and says changes after creation are ineffective, while this manifest explicitly selects an existing CLB with existLbId (TKE Ingress annotations). Consequently, long HTTP streams and Runtime WebSocket connections remain subject to the existing listener defaults; configure the listener through a referenced TkeServiceConfig or make the existing-CLB prerequisite explicit instead.

Useful? React with 👍 / 👎.

kubernetes.io/ingress.http-rules: "null"
kubernetes.io/ingress.https-rules: |
[{"host":"${OAC_PUBLIC_HOST}","path":"/v1","backend":{"serviceName":"oac-core","servicePort":"8091"}},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Derive the ingress hostname from OAC_PUBLIC_URL

If an operator sets OAC_PUBLIC_HOST differently from the hostname in OAC_PUBLIC_URL, the CLB routes only the former while Core advertises and Web accepts only the latter, so either the configured public URL has no matching rule or requests through the ingress are rejected by Web's host check. Avoid this independently configured second copy by deriving the ingress hostname from the canonical public URL, or at minimum validating equality before applying the template.

AGENTS.md reference: AGENTS.md:L46-L46

Useful? React with 👍 / 👎.

{"host":"${OAC_PUBLIC_HOST}","path":"/api/v1","backend":{"serviceName":"oac-core","servicePort":"8091"}},
{"host":"${OAC_PUBLIC_HOST}","path":"/","backend":{"serviceName":"oac-web","servicePort":"8080"}}]
spec:
ingressClassName: qcloud
tls:
- hosts: ["${OAC_PUBLIC_HOST}"]
secretName: "${OAC_TLS_SECRET}"
rules:
- host: "${OAC_PUBLIC_HOST}"
http:
paths:
- path: /v1
pathType: Prefix
backend:
service:
name: oac-core
port: {number: 8091}
- path: /api/v1
pathType: Prefix
backend:
service:
name: oac-core
port: {number: 8091}
- path: /
pathType: Prefix
backend:
service:
name: oac-web
port: {number: 8080}
2 changes: 1 addition & 1 deletion deploy/kubernetes/prod/web.yaml.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@ metadata:
app.kubernetes.io/name: oac-web
app.kubernetes.io/part-of: openagentcore
spec:
type: ClusterIP
type: NodePort
selector:
app: oac-web
ports:
Expand Down
Loading