OpenClaw EnterpriseDOCSGitHub

Docker-compatible Namespace execution and Agent admission

Continue from the initialized Compose stack through Namespace provisioning and the current Agent deployment boundary. See the parent flow.

Execution trace

6. Authenticated API calls create Namespace resources

internal/occclient/client.go, packages/occ/src/index.ts:OpenClawController

After dev-up prints the loopback API URL and private bootstrap key path, the operator uses OCC_URL and OCC_SERVICE_KEY_FILE for authenticated OCC calls. Namespace creation commits state, audit evidence, and durable provisioning work. Configuration and Agent drafts can be saved subject to normal admission rules; saving an Agent does not create its runtime.

7. The selected engine prepares the Namespace network

apps/controller/src/drivers/compute/docker/index.ts:DockerComputeDriver.ensureNamespace

The worker claims Namespace work and the Docker Driver creates or verifies one owned, labeled network through the selected engine's Docker-compatible API. The network is separate from the Compose management network. Readiness does not start a gateway or prove model access.

8. Agent deployment stops at harness authentication admission

packages/occ/src/index.ts:OpenClawController.deployAgent, apps/controller/src/drivers/compute/docker/index.ts:DockerComputeDriver.validateHarnessAuth

Deployment requires Agent harnessAuth. The Docker Driver rejects bindings, so deployment cannot queue a new AgentRevision or reach workload preparation. Exporting a model key to the worker cannot bypass this admission boundary. The retained container preparation and TUI test helpers do not establish a supported authenticated Agent journey. Use the Kubernetes Agent procedure for model execution and TUI verification.

The retained preparation code still handles interrupted dedicated startup: reconcileAgent verifies the surviving Codex container's ownership and recovers its existing transport token; reconcileGateway replaces a gateway whose transport token does not match. Missing tokens on reused Codex containers fail closed. These safeguards do not make the current binding-based Agent path supported on Docker or Podman.

9. Cleanup removes only owned development resources

apps/controller/src/drivers/compute/docker/index.ts:DockerComputeDriver.deleteNamespace

Namespace deletion removes only resources labeled for that exact Namespace; foreign resources with colliding names are not adopted or removed. Use the dev-up cleanup command to stop the Compose stack. Add volume removal only when intentionally deleting its persisted development Installation.

Search documentation