From ce549ce9f96a32afeeb1c28edfe80d151ad976de Mon Sep 17 00:00:00 2001 From: sam Date: Sun, 4 Oct 2026 08:47:04 +0800 Subject: [PATCH] Allow beta source revisions in production deployment workflow --- .github/workflows/deploy.yml | 20 ++++++++++++++++---- deploy/kubernetes/README.md | 2 +- 2 files changed, 17 insertions(+), 5 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 1dc969f7..543b01f9 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -10,8 +10,14 @@ name: core-deploy on: workflow_dispatch: inputs: + source_branch: + description: Source branch deployed to the existing production installation + required: true + default: main + type: choice + options: [main, beta] ref: - description: Release tag or full commit SHA already merged into main + description: Release tag or full commit SHA already merged into the selected source branch required: true type: string @@ -37,19 +43,25 @@ jobs: id: source env: WORKFLOW_REF: ${{ github.ref }} + SOURCE_BRANCH: ${{ inputs.source_branch }} run: | set -euo pipefail if [ "$WORKFLOW_REF" != "refs/heads/main" ]; then echo "::error::Run this production workflow from main." exit 1 fi + case "$SOURCE_BRANCH" in + main|beta) ;; + *) echo "::error::Source branch must be main or beta."; exit 1 ;; + esac + git fetch --no-tags origin "refs/heads/$SOURCE_BRANCH:refs/remotes/origin/$SOURCE_BRANCH" revision="$(git rev-parse HEAD)" - if ! git merge-base --is-ancestor "$revision" origin/main; then - echo "::error::The deployment revision must already be merged into main." + if ! git merge-base --is-ancestor "$revision" "origin/$SOURCE_BRANCH"; then + echo "::error::The deployment revision must already be merged into the selected source branch." exit 1 fi echo "revision=$revision" >> "$GITHUB_OUTPUT" - echo "Deploying \`$revision\`" >> "$GITHUB_STEP_SUMMARY" + echo "Deploying $SOURCE_BRANCH at \`$revision\`" >> "$GITHUB_STEP_SUMMARY" build: needs: prepare diff --git a/deploy/kubernetes/README.md b/deploy/kubernetes/README.md index 419e0f87..97cacaf3 100644 --- a/deploy/kubernetes/README.md +++ b/deploy/kubernetes/README.md @@ -28,7 +28,7 @@ Both images always come from one commit, so the console never talks to a Core of ## Deploy -Merge the deployment workflow into `main`. Run **Actions** → **core-deploy** → **Run workflow** from `main` and give it a release tag or a full commit SHA already merged into `main`. The run builds both images, pushes them, applies the secrets and the environment, rolls Core out and then Web, and checks that both Services have a ready endpoint. It does not create an Ingress or configure DNS or certificates. Route `/v1` and `/api/v1` to `oac-core:8091`, and all other paths to `oac-web:8080`, in the `openagentcore` namespace. After configuring HTTPS, check `/healthz`, verify that unauthenticated `/v1/agents` returns `401`, and qualify a fresh E2B Session and Turn. +Merge the deployment workflow into `main`. Run **Actions** → **core-deploy** → **Run workflow** from `main` and select `source_branch` (`main` by default or `beta`), then give it a release tag or a full commit SHA already merged into that source branch. Both choices replace the same production Core and Web; `beta` does not create a separate environment. Review the [beta integration ledger](https://github.com/sandbaseai/OpenAgentCore/blob/beta/deploy/kubernetes/BETA_CHANGELOG.md) on the beta branch before selecting a beta revision. Keep the workflow branch set to `main`, including when deploying beta. The run builds both images, pushes them, applies the secrets and the environment, rolls Core out and then Web, and checks that both Services have a ready endpoint. It does not create an Ingress or configure DNS or certificates. Route `/v1` and `/api/v1` to `oac-core:8091`, and all other paths to `oac-web:8080`, in the `openagentcore` namespace. After configuring HTTPS, check `/healthz`, verify that unauthenticated `/v1/agents` returns `401`, and qualify a fresh E2B Session and Turn. **A deployment is an outage.** Core's single replica stops before its replacement starts, and the replacement migrates the schema before it listens, so the Agents API, the machine routes and every running Session are unavailable for the rollout. Deploy in a window you can afford to lose. The Pod that takes over also needs the previous one's leased database connection to be gone; until it is, `AcquireLease` fails and Core exits, and the rollout depends on a restart landing inside the 15-minute deadline.