Skip to content

fix: support tutorial on a local Orca stack - #2

Merged
jiangpengcheng merged 3 commits into
mainfrom
fix/local-stack-compatibility
Oct 1, 2026
Merged

jiangpengcheng merged 3 commits into
mainfrom
fix/local-stack-compatibility

Conversation

@jiangpengcheng

Copy link
Copy Markdown
Member

The tutorial could not use a local Agent Engine workspace key because every path sent SN_API_KEY as a Bearer token. Cleanup also tried to delete environments that already had session history. This change makes L1 and cleanup work against ork local start --with-gateway while retaining hosted team-card authentication.

  • Use ORCA_API_KEY as x-api-key in the Python, TypeScript, and CLI paths; fall back to the hosted SN_API_KEY Bearer token. Keep the two Registry credentials mutually exclusive.
  • Accept loopback HTTP Registry URLs and add --agent-only doctor checks for L1 without data-service configuration.
  • Archive environments during cleanup so sessions do not cause a deletion conflict.
  • Use security.login_events as the Kafka topic, distinguish it from the SQL source avro.security.login_events, and inspect existing-topic metadata without requesting creation of a missing topic.
  • Document local setup and cover authentication and cleanup regressions.

Validation:

  • Python: 104 tests passed; offline doctor passed.
  • TypeScript: 110 tests passed; typecheck passed.
  • CLI: 83 checks passed; shellcheck passed.
  • Python, TypeScript, and CLI L1 each completed a real model call through a local Agent Engine and AI Gateway; cleanup passed for all three paths.
  • Kafka and Schema Registry connectivity and Python Avro injection were verified. TypeScript live injection timed out. Full L2–L4 validation remains pending a SQL MCP endpoint with the required query and insert tools.

The staged files were checked for credentials; .env and local runtime state are excluded.

Use Registry workspace keys for local Agent Engine requests while retaining
hosted Bearer authentication. Add an Agent-only doctor mode, archive used
environments during cleanup, and align Kafka preflight with the actual topic.

Assisted-by: Codex
Delegate first-time MCP authorization to ork across the Python, TypeScript
and CLI paths, then reuse the server-side credential by URL and auth type.
Retire a mismatched auth mode before creating its replacement, and retain
an explicit static_bearer option for API-key MCP servers. Validate OAuth
credentials through the Registry instead of sending the service-account
key directly to MCP.

Include all required flag-table columns and schema-read permissions in L4.
Document the ork prerequisite and how to align the L2 SQL source name with
LOGIN_TOPIC in .env. Cover authorization, reuse, failures and auth isolation.

Assisted-by: Codex
Align tutorial defaults and OAuth guidance with orca-cli PR #8.
Keep issuer selection optional and update all three paths' error hints.

Assisted-by: Codex
@jiangpengcheng
jiangpengcheng merged commit 4340c6b into main Oct 1, 2026
0 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants