Compare commits

..

No commits in common. "716017521f22e88feb35936b41a285cccf68eb87" and "138f33bc4313f2a13da61e5cb437437cbfee09ef" have entirely different histories.

2 changed files with 18 additions and 63 deletions

View File

@ -1,67 +1,22 @@
# OpenClaw Agent Guide # k8s/openclaw/AGENTS.md
This document provides a comprehensive technical reference for AI agents to manage the **OpenClaw** deployment in this repository. > [!NOTE]
> This directory contains the deployment configuration for **OpenClaw**, an open-source AI agent platform.
## 🏗️ Architecture & Configuration Lifecycle ## Overview
* **Namespace**: `openclaw`
* **Workload**: `openclaw` (Deployment)
* **Dependencies**:
* **LLM**: Connects to `ollama` in `llm` namespace.
* **Secrets**: Requires `GEMINI_API_KEY`.
### 1. Source * **Telegram**: Configured with `dmPolicy: "allowlist"` for users `306373425` and `255114390`. ## Deployment
* **Skills**: Enabled `nano-banana-pro` (Gemini image generation). Installed `uv` persistently into the PVC. 1. **Apply Namespace**: `kubectl apply -f namespace.yaml`
* **Configuration**: Streamlined `openclaw.secret.yaml`. Consolidated JSON into `ConfigMap`. 2. **Secrets**:
* **Status**: **Fully Functional** (Secure: Basic Auth + Gateway Token + Multi-LLM + Image Gen). * Edit `openclaw.secret.yaml` to set `api-key`.
json` * Ensure `openclaw.secret.yaml` is encrypted with `git-crypt`.
3. **Apply Workload**: `kubectl apply -f openclaw.secret.yaml`
### 2. Bootstrap Process ## Configuration
OpenClaw uses an `initContainer` to bootstrap the configuration: * **LLM Provider**: `ollama`
1. The `openclaw-bootstrap-config` volume is mounted at `/mnt/config`. * **Ollama URL**: `http://ollama.llm.svc.cluster.local:11434`
2. The `initContainer` copies `/mnt/config/openclaw.json` to the persistent data volume at `/mnt/data/openclaw.json`.
3. The main `openclaw` container identifies the persistent volume at `/home/node/.openclaw`.
### 3. Applying Changes
To update the configuration:
1. Modify the `openclaw.json` block in [openclaw.secret.yaml](file:///Users/moritz/src/infrapuzzle/k8s/openclaw/openclaw.secret.yaml).
2. Apply the manifest: `kubectl apply -f openclaw/openclaw.secret.yaml`
3. **Rotate Deployment**: You MUST restart the pod to trigger the `initContainer` bootstrap:
`kubectl rollout restart deployment openclaw -n openclaw`
---
## 🔧 Configuration Reference (`openclaw.json`)
### `gateway`
Controls the main server behavior and security.
- `trustedProxies`: List of IPs to trust for `X-Forwarded-For` headers (e.g., `["127.0.0.1"]`).
- `controlUi.dangerouslyDisableDeviceAuth`: Set to `true` to allow login via token/password without device identity verification (useful for initial setup).
- `port`: Default `18789`. Controlled via `OPENCLAW_GATEWAY_PORT` env var in the manifest.
### `agents.defaults`
Global defaults for all agents launched by the gateway.
- `model.primary`: The default LLM (e.g., `google/gemini-flash-latest`).
- `model.fallbacks`: List of model IDs to use if the primary fail.
- `contextTokens`: Maximum context window (e.g., `200000`).
### `models.providers`
Definition of external LLM sources.
- **`ollama`**:
- `baseUrl`: `http://127.0.0.1:11434` (proxied via sidecar).
- `apiKey`: Required for discovery (e.g., `ollama-local`).
- `models`: Array of model objects with `id`, `contextWindow`, etc.
- **`google`**: Built-in provider. Uses `GEMINI_API_KEY` environment variable.
### `channels`
Messaging platform integrations.
- **`telegram`**:
- `enabled`: `true` | `false`.
- `dmPolicy`: `pairing` (default) | `allowlist` (skip approval).
- `allowFrom`: Array of numeric user IDs (e.g., `["306373425"]`) allowed to DM the bot.
### `plugins` (Extensions)
Platform extensions (e.g., WhatsApp, Telegram).
- `entries.<pluginId>.enabled`: Enable/disable specific extension logic.
- `entries.<pluginId>.config`: Plugin-specific settings object.
### `skills`
Modular tool capabilities.
- `entries.<skillKey>.env`: Environment variables injected into the skill run.
### 💡 Special Requirements
- **`nano-banana-pro`**: Requires the `uv` tool. It is installed at `/home/node/.openclaw/bin/uv` (on the PVC) and included in the system `PATH`.

Binary file not shown.