Repository navigation
fix: support tutorial on a local Orca stack - #2
Merged
Merged
Conversation
Use Registry workspace keys for local Agent Engine requests while retaining hosted Bearer authentication. Add an Agent-only doctor mode, archive used environments during cleanup, and align Kafka preflight with the actual topic. Assisted-by: Codex
Delegate first-time MCP authorization to ork across the Python, TypeScript and CLI paths, then reuse the server-side credential by URL and auth type. Retire a mismatched auth mode before creating its replacement, and retain an explicit static_bearer option for API-key MCP servers. Validate OAuth credentials through the Registry instead of sending the service-account key directly to MCP. Include all required flag-table columns and schema-read permissions in L4. Document the ork prerequisite and how to align the L2 SQL source name with LOGIN_TOPIC in .env. Cover authorization, reuse, failures and auth isolation. Assisted-by: Codex
sijie
approved these changes
Sep 30, 2026
Align tutorial defaults and OAuth guidance with orca-cli PR #8. Keep issuer selection optional and update all three paths' error hints. Assisted-by: Codex
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The tutorial could not use a local Agent Engine workspace key because every path sent
SN_API_KEYas a Bearer token. Cleanup also tried to delete environments that already had session history. This change makes L1 and cleanup work againstork local start --with-gatewaywhile retaining hosted team-card authentication.ORCA_API_KEYasx-api-keyin the Python, TypeScript, and CLI paths; fall back to the hostedSN_API_KEYBearer token. Keep the two Registry credentials mutually exclusive.--agent-onlydoctor checks for L1 without data-service configuration.security.login_eventsas the Kafka topic, distinguish it from the SQL sourceavro.security.login_events, and inspect existing-topic metadata without requesting creation of a missing topic.Validation:
The staged files were checked for credentials;
.envand local runtime state are excluded.