Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 16 additions & 4 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,14 @@ name: core-deploy
on:
workflow_dispatch:
inputs:
source_branch:
description: Source branch deployed to the existing production installation
required: true
default: main
type: choice
options: [main, beta]
ref:
description: Release tag or full commit SHA already merged into main
description: Release tag or full commit SHA already merged into the selected source branch
required: true
type: string

Expand All @@ -37,19 +43,25 @@ jobs:
id: source
env:
WORKFLOW_REF: ${{ github.ref }}
SOURCE_BRANCH: ${{ inputs.source_branch }}
run: |
set -euo pipefail
if [ "$WORKFLOW_REF" != "refs/heads/main" ]; then
echo "::error::Run this production workflow from main."
exit 1
fi
case "$SOURCE_BRANCH" in
main|beta) ;;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Enforce production protections on the selected source branch

When beta has weaker branch protection than main, this allows its commits to bypass the documented main-only production restriction: GitHub matches an environment’s deployment-branch rule against the workflow run’s GITHUB_REF, which remains main here, not against the commit later checked out (GitHub documentation). The build and deploy jobs then execute scripts and the local setup-kubectl action from that beta commit with production registry credentials and the cluster kubeconfig. Require beta to satisfy the same review/protection policy as main, or independently gate the selected SHA before exposing production secrets.

Useful? React with 👍 / 👎.

*) echo "::error::Source branch must be main or beta."; exit 1 ;;
esac
git fetch --no-tags origin "refs/heads/$SOURCE_BRANCH:refs/remotes/origin/$SOURCE_BRANCH"
revision="$(git rev-parse HEAD)"
if ! git merge-base --is-ancestor "$revision" origin/main; then
echo "::error::The deployment revision must already be merged into main."
if ! git merge-base --is-ancestor "$revision" "origin/$SOURCE_BRANCH"; then
echo "::error::The deployment revision must already be merged into the selected source branch."
exit 1
fi
echo "revision=$revision" >> "$GITHUB_OUTPUT"
echo "Deploying \`$revision\`" >> "$GITHUB_STEP_SUMMARY"
echo "Deploying $SOURCE_BRANCH at \`$revision\`" >> "$GITHUB_STEP_SUMMARY"

build:
needs: prepare
Expand Down
2 changes: 1 addition & 1 deletion deploy/kubernetes/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ Both images always come from one commit, so the console never talks to a Core of

## Deploy

Merge the deployment workflow into `main`. Run **Actions** → **core-deploy** → **Run workflow** from `main` and give it a release tag or a full commit SHA already merged into `main`. The run builds both images, pushes them, applies the secrets and the environment, rolls Core out and then Web, and checks that both Services have a ready endpoint. It does not create an Ingress or configure DNS or certificates. Route `/v1` and `/api/v1` to `oac-core:8091`, and all other paths to `oac-web:8080`, in the `openagentcore` namespace. After configuring HTTPS, check `/healthz`, verify that unauthenticated `/v1/agents` returns `401`, and qualify a fresh E2B Session and Turn.
Merge the deployment workflow into `main`. Run **Actions** → **core-deploy** → **Run workflow** from `main` and select `source_branch` (`main` by default or `beta`), then give it a release tag or a full commit SHA already merged into that source branch. Both choices replace the same production Core and Web; `beta` does not create a separate environment. Review the [beta integration ledger](https://github.com/sandbaseai/OpenAgentCore/blob/beta/deploy/kubernetes/BETA_CHANGELOG.md) on the beta branch before selecting a beta revision. Keep the workflow branch set to `main`, including when deploying beta. The run builds both images, pushes them, applies the secrets and the environment, rolls Core out and then Web, and checks that both Services have a ready endpoint. It does not create an Ingress or configure DNS or certificates. Route `/v1` and `/api/v1` to `oac-core:8091`, and all other paths to `oac-web:8080`, in the `openagentcore` namespace. After configuring HTTPS, check `/healthz`, verify that unauthenticated `/v1/agents` returns `401`, and qualify a fresh E2B Session and Turn.

**A deployment is an outage.** Core's single replica stops before its replacement starts, and the replacement migrates the schema before it listens, so the Agents API, the machine routes and every running Session are unavailable for the rollout. Deploy in a window you can afford to lose. The Pod that takes over also needs the previous one's leased database connection to be gone; until it is, `AcquireLease` fails and Core exits, and the rollout depends on a restart landing inside the 15-minute deadline.

Expand Down
Loading