SEED_DEVELOPMENT_DATA; each new workspace receives the final
starter bundle once, with no startup upgrade or repair pass.
Kubernetes
Use theacornops-platform Helm chart to deploy the central platform into a Kubernetes cluster. The chart deploys:
- management console,
- control plane,
- execution engine,
- LLM gateway,
- optional platform admin console when explicitly enabled,
- database migration Jobs.
Required platform inputs
Prepare these inputs before installing the chart:
Review these value groups before installing or upgrading:
Internal service TLS
The chart can harden control-plane, execution-engine, and LLM gateway traffic with operator-supplied HTTPS/mTLS. It is disabled by default. AcornOps does not generate or chart-manage the CA or certificates. Create a CA Secret and one TLS Secret per service:acornops-platform-control-plane.acornops-platform.svc.
If you use a different release name or namespace, render the chart and use the
service DNS names from your deployment.
Public ingress stays on the control-plane HTTP service port. Existing bearer
tokens and run-scoped JWT checks remain required.
cert-manager can create the same Secrets, but it is optional. A representative
control-plane certificate looks like this:
Workspace roles
Configure deployment-supported workspace roles withworkspaceRoles in chart values:
enabledBuiltIns is omitted, all built-ins are enabled. If it is provided, it must include owner. Custom roles may only use supported workspace capabilities and cannot include owner-only governance capabilities. Every workspace inherits the same catalog.
Example install:
acornopsPlatform entry in the
stack-versions.yaml release matrix.
Production exposure
Expose only the management console and control-plane public routes:https://console.example.com/https://api.example.com/api/v1wss://api.example.com/api/v1/agent/connect
exposure.ingress.enabled controls whether the chart renders an Ingress; it does not authorize packets. When networkPolicies.enabled=true, configure networkPolicies.ingressController.from with the exact namespace and pod selectors allowed to reach the management console and control plane. An empty list fails closed and allows no ingress-controller source through the chart’s default-deny policy.
This applies equally when an external controller or GitOps system owns the Ingress resource.
Replicas
The chart defaults to multiple replicas for stateless or Redis-coordinated services where supported:
During a control-plane rollout, connected agents reconnect to an available pod. Commands that are active during the rollout can fail or time out and should be retried.
VM Compose
Use the VM Compose stack for a single-machine central platform installation. This path is useful for smaller environments and production-style testing with separate Kubernetes clusters and VM targets. Typical flow:- Generate unique internal service tokens and encryption keys.
- Set production hostnames and OIDC settings.
- Keep
TRUST_PROXY=1when the edge proxy owns TLS and forwarded host headers. - Point database and Redis settings at durable services.
- Review JWKS readiness, request-size, rate-limit, and MCP egress variables.
- Pin all image references from the
vm-prod-v1release matrix instead of using mutable or independently selected tags. - Confirm the reverse proxy terminates TLS for the console and API hosts.