Skip to content

fix(local): use released GHCR engine images - #4

Merged
jiangpengcheng merged 2 commits into
mainfrom
fix/local-ghcr-release-images
Sep 30, 2026
Merged

jiangpengcheng merged 2 commits into
mainfrom
fix/local-ghcr-release-images

Conversation

@jiangpengcheng

@jiangpengcheng jiangpengcheng commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What changes and why

Update the default ork local engine images to the released GHCR versions:

  • Registry and migrations: ghcr.io/orca-ae/orca-registry-service-ts:0.5.1
  • Harness: ghcr.io/orca-ae/orca-harness-server:0.5.1
  • Optional AI Gateway: ghcr.io/orca-ae/orca-ai-gateway:0.4.3

Document these defaults in the README. Existing ORCA_LOCAL_*_IMAGE overrides continue to work.

Configure LLM_GATEWAY_URL for Harness 0.5.1 and the Registry LLM JWT route/model policy required by the Gateway allowlist. Registry narrows the deployment model pattern to the concrete models pinned by each session. Map the Anthropic vault explicitly to ANTHROPIC_API_KEY. Without these settings, --with-gateway model requests connect to container-local localhost or fail authorization/credential resolution.

Compatibility

  • No change to a command's name, arguments or flags, the default or -o json output, exit statuses, an ORCA_* environment variable, the files and ports of ork local, the container image's user or entrypoint, or the Go API of pkg/cmd/workspace
  • Changes one of the above. The change is described in What changes and why, with its OIP if one is required.

How I tested it

  • CLI build, gofmt -l ., go vet ./..., go test ./..., and scripts/check-license-headers.sh passed.
  • The existing embedded Compose validation test passed.
  • All three GitHub workflows passed on commit 4dbaf8c: CI, E2E - Managed Agents direct, and Release dry run. The updated required checks all report success.
  • Verified that all three GHCR tags publish linux/amd64 and linux/arm64 manifests.
  • Started an isolated ork local start --with-gateway stack using the defaults. Migration exited successfully; Registry and Gateway health/readiness endpoints returned HTTP 200.
  • A real Anthropic session returned GHCR_GATEWAY_OK, and Gateway request metrics confirmed traffic through the Anthropic destination. One HTTP 502 was recovered by the existing retry path. Test resources were archived.
  • Corrected the main ruleset required checks from obsolete integration, test, and lint-and-breaking to the current Test, Check Managed Agents source access, and CLI against pinned Managed Agents stack names. Other branch protections were retained.

AI assistance

  • No AI assistance
  • AI-assisted. Tool: Codex. Updated the Compose image defaults, Gateway configuration and README; verified repository checks, GHCR manifests, startup and a real Gateway model request; diagnosed the stale required check names.

Checklist

  • Every commit is signed off (git commit -s), as described in CONTRIBUTING.md. Human sign-off is pending; no tool-generated sign-off was added.
  • Commits with meaningful AI assistance carry one Assisted-by: trailer
  • gofmt -l . prints nothing, and go vet ./..., go test ./... and scripts/check-license-headers.sh pass locally
  • A new, removed or moved command has its case in tests/e2e/commands/commands_test.go (no command inventory change)
  • The README is updated if behavior changed

@jiangpengcheng
jiangpengcheng merged commit fc112af into main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants