Skip to content

Register a Kubernetes cluster (bridge daemon)

The bridge daemon (oma-bridge-daemon) is a long-lived Deployment in your Kubernetes cluster. It connects out over a reverse WebSocket to an OMA control plane (for example https://app.oma.duyet.net) and executes sandbox ops the platform relays to it.

In the Console this is Runtimes → Register k8s cluster. The daemon shows up under Connected machines. Route sessions with an environment whose sandbox provider is subprocess.

ModeChart valuesWhat happens
In-pod (default)bridge.backend: "" (or subprocess / local) · openshell.enabled: falsebash / read / write / … run inside the daemon pod. One Deployment; sessions share that pod’s process space and filesystem. No extra pods per session.
OpenShellbridge.backend: openshell · openshell.enabled: trueThe daemon relays each session to an OpenShell gateway, which creates isolated sandboxes (pods/microVMs) per turn.

In-pod mode is not “spawn a pod, then spawn containers inside it.” It is literally subprocess execution in the daemon container — the same mental model as oma bridge daemon on a laptop, just packaged as a Deployment.

OpenShell is the path when you want isolation and per-session sandboxes on the cluster.

  • Kubernetes 1.25+, kubectl, Helm 3 (for the Helm path)
  • An OMA control plane that accepts bridge runtimes
  • A multi-use pairing token from the Console (Register k8s cluster → Generate token) or POST /v1/runtimes/pairing-token

Never put the pairing code in Helm --set or in Git. Create a Secret first:

Terminal window
export NS=oma
export CODE='pair_…' # from Console
export STATE='st_…'
kubectl create namespace "$NS" --dry-run=client -o yaml | kubectl apply -f -
kubectl create secret generic oma-bridge-daemon-pairing \
--namespace "$NS" \
--from-literal=OMA_PAIRING_CODE="$CODE" \
--from-literal=OMA_PAIRING_STATE="$STATE" \
--dry-run=client -o yaml | kubectl apply -f -

On first boot the pod redeems the code, writes credentials.json on an emptyDir, then starts the daemon. Subsequent restarts reuse the creds.

values.yaml
pairing:
existingSecret: oma-bridge-daemon-pairing
serverUrl: https://app.oma.duyet.net # your control plane
bridge:
backend: "" # in-pod; use "openshell" for OpenShell
namespace: oma
openshell:
enabled: false # true installs the gateway subchart + wires env
Terminal window
# From a clone of https://github.com/duyet/oma
helm dependency build ./charts/oma-bridge-daemon
helm upgrade --install oma-bridge-daemon ./charts/oma-bridge-daemon \
--namespace oma \
-f values.yaml

OpenShell in one step:

Terminal window
helm upgrade --install oma-bridge-daemon ./charts/oma-bridge-daemon \
--namespace oma \
--set secret.existingSecret= \
--set pairing.existingSecret=oma-bridge-daemon-pairing \
--set pairing.serverUrl=https://app.oma.duyet.net \
--set openshell.enabled=true
  1. Console → Runtimes → the machine should appear Online (heartbeat).
  2. Create or edit an Environment with sandbox_provider: "subprocess" (or leave the default subprocess path).
  3. Start a session on that environment — tool calls relay to the daemon.

Revoke the pairing token in the Console once the pod has paired.