Repository navigation
fix: catch a refused provider key in Lab 0, and three other first-run fixes - #8
Merged
Merged
Conversation
`local/engine.sh --check` and the doctor both passed with a key the provider refuses: the engine check only looked for a key in the gateway's environment. The first sign was Lab 1, where the agent retried its first turn for three minutes and then stopped with `upstream returned 401`. The check now asks the provider. The harness lists models with the key it was started with, so the key stays in the engine and the request costs nothing. A refused key now fails Lab 0, step 2, within seconds and with its fix. A provider that cannot be reached, or that answers with another status, is reported as that, not as a bad key. The gateway cannot be asked instead: its only Anthropic route is `/v1/messages`, every call to it needs a session token, and its image has no HTTP client. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Nq3n2MeC9XrC31wYfdjZv
`docker compose down` keeps the unnamed volumes that the Kafka and RustFS images declare, and the next `up` creates new ones. Each `local/down.sh` and restart left four more empty volumes, and each `local/engine.sh` one more: nine after one pass through the course. `local/down.sh` now removes the containers with `rm --volumes` before `down`, and `local/engine.sh` removes the engine's stopped containers with `--volumes`. Named volumes hold the data and are not touched: after a stop and a start, the topic, the view and the table are still there. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Nq3n2MeC9XrC31wYfdjZv
On a Mac with no other Python, `python3` is 3.9.6. `runorca` needs 3.10 or newer, so the lab's `pip install -r requirements.txt` stops at `No matching distribution found for runorca==0.3.0`, which does not mention Python. Both courses now say to check `python3 --version` first, and both troubleshooting pages list the symptom. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Nq3n2MeC9XrC31wYfdjZv
The pages gave only `brew install orca-ae/tap/ork`. A new Mac has no Homebrew, and installing it takes an administrator password. The release archive needs neither. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Nq3n2MeC9XrC31wYfdjZv
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
I took the Local course end to end on a new Mac (macOS 26.7 on Apple silicon, Docker Desktop 29.8.2 with Compose 5.5.1,
ork0.6.0, the Python path). Every step and every check matched the pages. Four things got in the way of a first run. This PR fixes them, one commit each.What changes
1. A key the provider refuses is caught in Lab 0, not in Lab 1
local/engine.sh --checkand the doctor both passed with a key Anthropic rejects: the engine check only looked for a key in the gateway's environment. The first sign was Lab 1, where the agent retried its first turn for 183 seconds and then stopped withupstream returned 401 … "API key is invalid."The engine check now asks the provider. With a refused key,
local/engine.shends like this after about four seconds, and exits 1:GET /v1/models?limit=1) with the key it was started with, throughdocker exec … node. The key never leaves the engine, and the request costs nothing./v1/messages, every call needs a session token, and its image has no HTTP client.2. Stopping no longer leaves unnamed volumes behind
docker compose downkeeps the unnamed volumes that the Kafka and RustFS images declare, and the nextupcreates new ones. Eachlocal/down.shand restart left four more empty volumes, and eachlocal/engine.shone more: nine after one pass through the course.local/down.shnow removes the containers withrm --volumesbeforedown, andlocal/engine.shremoves the engine's stopped containers with--volumes. Named volumes hold the data and are not touched.3. Docs: what Apple's Python 3.9 does to the install command
On a Mac with no other Python,
python3is 3.9.6.runorcaneeds 3.10 or newer, sopip install -r requirements.txtstops atNo matching distribution found for runorca==0.3.0, which does not mention Python. Both courses and "Before you arrive" now say to checkpython3 --versionfirst, and both troubleshooting pages list the symptom.4. Docs:
orkwithout HomebrewThe pages gave only
brew install orca-ae/tap/ork. A new Mac has no Homebrew, and installing it takes an administrator password. The pages now also name the release archive.How it was tested
local/tests/run.shgoes from 44 checks to 82. Againstmain's scripts, 16 of the new ones fail.local/tests/run.shandscripts/check-labs.shpass at each of the four commits.local,labsandclipass, and so does the credential scan. I did not run thepythonandtypescriptjobs: nothing underpython/ortypescript/changes.the engine cannot reach ….local/engine.sh, and went back to 11 onlocal/down.sh. After the restart the doctor passed, the topic still held its 253 events, andflagged_accountsstill held its row.Not covered: the Cloud course (it gets only the Python note), and the CLI and TypeScript paths of the Local course.
For the reviewer
nodein the harness image, which is a Node server. If a harness cannot make the request, the line fails withthe harness could not ask the provider; it does not blame the key.docker volume pruneremoves them.labs/local/README.mdis unchanged: it records your own run.🤖 Generated with Claude Code
https://claude.ai/code/session_014Nq3n2MeC9XrC31wYfdjZv