openclaw/docs/install
Peter Steinberger 1ea2640f54
refactor(state): consolidate wide rows, plugin index, workspace attestations, and shared auth singletons at schema v13 (#130466)
* refactor(state): make cron and subagent rows JSON-canonical

* refactor(state): make gateway origin device tokens canonical at v13

The lazy ensure predates the table joining the canonical schema; at the
v13 bump the schema owns creation, so the feature-local DDL, WeakSet
dedupe, and lazy-list entry retire. The legacy-file guard the ensure
carried stays at each call site.

* test: drop obsolete lazy-ensure coverage for origin device tokens

The table is canonical at v13; same-version lazy creation no longer
exists to protect. Origin CRUD, isolation, and rotation coverage remains
in the surviving cases.

* refactor(state): fold installed_plugin_index into config_machine_state

The singleton index row becomes one JSON value under
plugins.installedIndex with its rollback-fencing revision inside the
value; reads, CAS restore, and the lease-held write transactions use
direct Kysely on config_machine_state so the state_leases assertion
stays in-transaction. The v13 migration imports the row and drops the
table; the additive workspace_dir entry folds with it. Doctor guidance,
docker staging, and the e2e probes name the machine-state row.

* refactor(state): merge workspace_attestations into workspace_setup_state

One row per workspace now carries both setup milestones and the
attestation clock: nullable setup columns represent attestation-only
workspaces (replaceWorkspaceAttestation can precede any setup write) and
setupExists derives from a non-null version. The bootstrap-hash FK
repoints to the merged table; migration receipts keep the historical
workspace_attestations discriminator string. The v13 migration grows and
rebuilds the table, merges attestation rows (orphans without a path
alias drop — their hashes re-derive at the next bootstrap attestation),
and the consolidation kind is renamed state-consolidation-v13 to cover
the batch.

* test(state): cover the workspace merge and consolidation fallout

The v12-to-v13 regression seeds merged, attestation-only, and orphan
attestation workspaces; the 13-to-12 downgrade fixture recreates
workspace_attestations and installed_plugin_index from the folded data;
the fold-in migration gates the additive workspace_dir column for
pre-additive rows; the workspace merge now triggers on the setup table's
own shape so stable-era databases without an attestations table still
reshape; the consolidation applied-message covers the batch.

* refactor(state): fold shared auth profile singletons into config_machine_state

The shared-state auth_profile_stores/auth_profile_state rows (fixed key
'shared') become authProfiles.store/authProfiles.state machine-state
values; the agent-DB tables of the same names are untouched. Git-backup
redaction moves from table-drop to the authProfiles. secret prefix with
seeded-secret absence proof; migration receipts keep the historical
table-name discriminators; the shared-auth relocation and receipt
verification project the KV cells back to the receipt-era row shapes so
persisted digests stay byte-compatible. mcp_oauth_stores stays a table —
its multi-key fold is a named follow-up.

* test(state): finish shared-auth fold coverage and annotate boundary casts

Auth seeders and assertions across the e2e/scripts/secrets suites target
the authProfiles machine-state cells; the v12-to-v13 regression proves
payload-byte fidelity, non-shared-row drop, and insert-if-absent
precedence; the downgrade fixture recreates and repopulates both v12
tables. Boundary type assertions in the plugin-index store carry SAFETY
invariants per the ratchet.

* chore: shrink assertion-safety baseline for plugin-index store

* refactor(doctor): delete the dead onboarding-recommendations migration

Its input — the unscoped 'primary' onboarding row — existed only between
9a93a52a8a and 473962b7de, a two-day beta window; no shipped stable
can produce it and the runtime table folded away at v12. The audit
backup list keeps recognizing system-agent.jsonl artifacts because beta
installs that ran that import may still carry its backups.

* docs: sync the 13-to-12 downgrade example with the executable fixture

* style: format the synced downgrade example

* style: drop unused import and duplicate union constituent

* fix(state): keep orphan attestations across the v13 workspace merge

The merged workspace_setup_state required a workspace path, but legacy
orphan hashed-key attestations never recorded one. workspace_path is now
nullable (setup rows still enforce it via CHECK), the v13 migration and
the doctor file import keep orphans with a NULL path that heals on the
next live access, and the 13-to-12 downgrade keeps attestation-owned
hashes. Doctor test seeds move to the folded KV row.

* perf(state): retire unused cron indexes

* fix(state): preserve v13 migration recovery

* fix(state): preserve v12 lazy-table upgrade

* docs(state): document v13 auth relocation

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-08-27 15:26:14 +08:00
..
ansible.md docs(install): use managed gateway restart in Ansible guide (#128522) 2026-08-23 23:00:28 -07:00
azure.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
backups.md refactor(state): consolidate wide rows, plugin index, workspace attestations, and shared auth singletons at schema v13 (#130466) 2026-08-27 15:26:14 +08:00
bun.md feat(daemon): support Bun 1.4 managed services (#129593) 2026-08-26 00:45:43 -07:00
clawdock.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
cloudflare.md fix(deploy): repair probes that silently pass and a blueprint that cannot boot (#122963) 2026-08-12 20:49:54 -07:00
daytona.md fix(update): support npm before lifecycle allowlists (#125452) 2026-08-17 17:01:23 -07:00
development-channels.md fix(onboarding): OpenAI setup installs mismatched Codex plugin (#129195) 2026-08-25 17:03:39 -07:00
digitalocean.md docs(install): avoid duplicate onboarding runs (#125246) 2026-08-17 04:28:28 -07:00
docker-vm-runtime.md fix(scripts): build heap ignores its systemd memory budget and takes the full default (#123979) 2026-08-24 14:18:48 +10:00
docker.md fix(openshell): sandbox cleanup, workspace sync, and gateway setup failures (#129641) 2026-08-25 18:08:55 -07:00
exe-dev.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
fly.md fix(gateway): suppress ambient channel auto-enable (#123174) 2026-08-13 11:20:40 -07:00
gcp.md fix(scripts): build heap ignores its systemd memory budget and takes the full default (#123979) 2026-08-24 14:18:48 +10:00
hetzner.md fix(scripts): build heap ignores its systemd memory budget and takes the full default (#123979) 2026-08-24 14:18:48 +10:00
hostinger.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
index.md feat(daemon): support Bun 1.4 managed services (#129593) 2026-08-26 00:45:43 -07:00
installer.md fix(install): avoid success after incomplete lifecycle changes (#125992) 2026-08-18 20:50:15 -07:00
kubernetes.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
macos-vm.md fix(update): support npm before lifecycle allowlists (#125452) 2026-08-17 17:01:23 -07:00
migrating-claude.md feat(onboard): stage migration imports before promotion (#112798) 2026-07-23 07:06:01 -04:00
migrating-hermes.md feat(onboard): stage migration imports before promotion (#112798) 2026-07-23 07:06:01 -04:00
migrating.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
nix.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
node.md docs(install): recommend Node 26 as the OpenClaw runtime (#114399) 2026-07-27 04:32:21 -04:00
northflank.mdx docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
oracle.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
podman.md docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
railway.mdx docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
raspberry-pi.md docs: align systemd host tuning with managed policy (#128752) 2026-08-24 08:38:27 -07:00
render.mdx docs(hosting): fix unsafe deployment instructions (#122971) 2026-08-12 20:56:25 -07:00
uninstall.md fix(install): avoid success after incomplete lifecycle changes (#125992) 2026-08-18 20:50:15 -07:00
update-troubleshooting.md feat(ui): add typed update recovery actions (#125098) 2026-08-18 01:31:21 -07:00
updating.md fix(browser): warn when Chrome extension version drifts after upgrades (#119641) 2026-08-26 10:42:57 -07:00
upstash.md fix(update): support npm before lifecycle allowlists (#125452) 2026-08-17 17:01:23 -07:00