Skip to content

Require the installation ID and credential key - #541

Merged
SaladDay merged 1 commit into
mainfrom
refactor/required-installation-files
Oct 8, 2026
Merged

SaladDay merged 1 commit into
mainfrom
refactor/required-installation-files

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Core now always runs with an installation ID and a credential key. The run modes without them are deleted.

  • Process settings. processconfig.Load requires both files, and OAC_PUBLIC_URL with them. A missing file is a typed configuration error that oac check-config reports. main always builds the sandbox manager.
  • Deleted modes. The nil key and nil ID branches, "credential storage is disabled", credential_storage_unavailable, and the "not configured" 503s. Constructors take a required key or ID. Tests share pgtest.CredentialKey.
  • Admin API. installation_id in GET /core/v1/installation is a required string (make openapi; admin-api.md en and zh). Web's null branches are gone.
  • Producers. The dev run and the acceptance harnesses write both files and mount them. The installation ID stays stable for a given database, because Core claims it there: official_client.py uses a fixed test UUID, and the README tells developers to keep the ID and key with their database.
  • Lost key. Under a new key, Core starts, credentials list, deletion works and nothing leaks. A credential sealed with the old key returns the existing typed error. If an old-key E2B credential is stored, hosted execution maps it to 503 execution_unavailable. The recovery path in vaults.md (en and zh): Reset deployment and set up again. Leftover E2B sandboxes expire under their E2B timeout.
  • Docs. configuration.md, vaults.md, admin-api.md, sessions-events, runtime-observability and IMPLEMENTATION.md, en and zh where they exist.

Net lines: non-test −283, test −303.

Checks: go build, go vet, make openapi (no diff); Go tests for every changed and dependent package against a database, including cmd/server, api, execution, processconfig, sandbox/providers and tests/integration; Web and agents-client typecheck and the touched vitest files; docs build, translations and make check-docs. The acceptance scripts changed, so this PR waits for CI before merging.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay force-pushed the refactor/required-installation-files branch from 00972e5 to 541b422 Compare October 8, 2026 02:56
@SaladDay
SaladDay merged commit 6ce0e51 into main Oct 8, 2026
25 checks passed
@SaladDay
SaladDay deleted the refactor/required-installation-files branch October 8, 2026 03:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant