From d3dfcea46ee14cf3c9022324327e374ae6923436 Mon Sep 17 00:00:00 2001 From: jiangpengcheng Date: Wed, 30 Sep 2026 17:37:18 +0800 Subject: [PATCH 1/3] fix: support tutorial on a local Orca stack Use Registry workspace keys for local Agent Engine requests while retaining hosted Bearer authentication. Add an Agent-only doctor mode, archive used environments during cleanup, and align Kafka preflight with the actual topic. Assisted-by: Codex --- .env.example | 9 ++++-- README.md | 29 +++++++++++++++++-- cli/cleanup.sh | 4 +-- cli/env.sh | 16 +++++++---- cli/l1_hello.sh | 2 +- cli/tests/fake-ork | 12 ++++++++ cli/tests/run.sh | 22 +++++++++++++-- python/cleanup.py | 2 +- python/common.py | 12 +++++--- python/doctor.py | 30 +++++++++++++------- python/l1_hello.py | 2 +- python/tests/fakes.py | 7 +++++ python/tests/test_config.py | 37 ++++++++++++++++++++++++- python/tests/test_doctor.py | 15 ++++++++++ python/tests/test_inject.py | 8 +++--- python/tests/test_scripts_support.py | 5 ++-- typescript/src/cleanup.ts | 2 +- typescript/src/common.ts | 17 ++++++++---- typescript/src/doctor.ts | 34 ++++++++++++++--------- typescript/src/l1-hello.ts | 2 +- typescript/test/config.test.ts | 28 ++++++++++++++++++- typescript/test/doctor.test.ts | 15 ++++++++++ typescript/test/fakes.ts | 9 ++++++ typescript/test/scripts-support.test.ts | 5 ++-- 24 files changed, 261 insertions(+), 63 deletions(-) diff --git a/.env.example b/.env.example index 3eff20b..97fe997 100644 --- a/.env.example +++ b/.env.example @@ -11,6 +11,11 @@ SN_API_KEY= # Looks like: @.auth.streamnative.cloud SN_SERVICE_ACCOUNT= +# Optional separate Registry workspace key for ork local (sent as x-api-key). +# Leave empty for a hosted team card; SN_API_KEY then authenticates Agent Engine. +# This key does not authenticate Kafka, Schema Registry, or StreamNative MCP. +ORCA_API_KEY= + # Agent Engine registry endpoint (the External one). Host root only, no /v1. # Looks like: https:// ORCA_BASE_URL= @@ -24,8 +29,8 @@ SN_MCP_URL= # ------------------------------------------------------------- your choices -- -# The preloaded login topic. -LOGIN_TOPIC=avro.security.login_events +# The Kafka topic name (SQL Workspace exposes it as avro.security.login_events). +LOGIN_TOPIC=security.login_events # The model your agent runs on (served by the event's AI gateway). ORCA_MODEL=claude-sonnet-4-6 diff --git a/README.md b/README.md index d4dcb32..057a64c 100644 --- a/README.md +++ b/README.md @@ -18,7 +18,7 @@ them from live data, and flag the account once you say so. ```mermaid flowchart LR - K["Kafka topic
avro.security.login_events"] --> S["SQL Workspace
materialized view
login_failures"] + K["Kafka topic
security.login_events"] --> S["SQL Workspace
materialized view
login_failures"] J["inject
(you, in L3)"] -- "new login burst" --> K S -- "StreamNative MCP
sql_workspace_query" --> A["Orca agent
hello-agent-<you>"] A -- "sql_workspace_insert_rows
(only if you approve)" --> F["SQL table
flagged_accounts"] @@ -57,6 +57,26 @@ Go to your path's folder and run the doctor: Every line should say `PASS`. A failed check prints its fix. Still stuck after two tries? Raise your hand. +### Use a local Agent Engine + +Start the CLI's stack with a provider key in your shell: + +```bash +export ANTHROPIC_API_KEY='' +ork local start --with-gateway +``` + +Set `ORCA_BASE_URL=http://127.0.0.1:8080` in the tutorial's `.env`, and copy the +workspace key from the file printed by `ork local start` into `ORCA_API_KEY`. +The tutorial sends this key as `x-api-key`. A hosted team card continues to use +`SN_API_KEY` as a Bearer token when `ORCA_API_KEY` is empty. + +For L1, run `python doctor.py --agent-only` or `npm run doctor -- --agent-only`. +This checks the Agent Engine without requiring Kafka, Schema Registry, or MCP. +The local stack provides the Agent Engine and AI Gateway; L2–L4 still need the +streaming data services from your team card. For L3/L4, keep `SN_API_KEY` set to +the MCP service key, separately from the local Registry's `ORCA_API_KEY`. + ## L1: Hello, agent (5 min) | CLI | Python | TypeScript | @@ -150,6 +170,8 @@ create a new version when its definition changes. In the StreamNative Cloud console, open **SQL Workspace**, select the hackathon workspace, and pick your team's database. Use a new query tab for each step. +The Kafka topic is `security.login_events` (`LOGIN_TOPIC` in `.env`); SQL Workspace +exposes the Avro source as `"avro.security.login_events"`. **1. Peek at the stream** ([`sql/01_explore.sql`](sql/01_explore.sql)). Each row is one login attempt. The topic name contains dots, so it's double-quoted. @@ -353,8 +375,9 @@ action, and you have your hackathon project. Ideas and next steps: |---|---|---| | `./cleanup.sh` | `python cleanup.py` | `npm run cleanup` | -This archives your agent and deletes your vault and environment. To start L2 -over, run [`sql/99_reset.sql`](sql/99_reset.sql). +This archives your agent and environment, and deletes your vault. An environment +with session history cannot be deleted; archiving keeps that history available. +To start L2 over, run [`sql/99_reset.sql`](sql/99_reset.sql). ## What's in this repository diff --git a/cli/cleanup.sh b/cli/cleanup.sh index 5240f3d..064d443 100755 --- a/cli/cleanup.sh +++ b/cli/cleanup.sh @@ -8,7 +8,7 @@ set -euo pipefail # shellcheck source=lib.sh . "$(dirname "$0")/lib.sh" -hello_setup ORCA_BASE_URL SN_API_KEY +hello_setup ORCA_BASE_URL remove() { # remove