Install on a cluster
OAP installs onto any Kubernetes cluster. Which cluster kind you install as decides the install profile — the memory backend, the SpiceDB datastore, the artifact store, and how the platform is reached.
Choosing a cluster kind
Pass --cluster-kind (or --local as shorthand for the local dev kind). Omit it and OAP detects the kind from
the cluster's node providers, falling back to a sensible default — the local and desktop kinds are opt-in only
and never auto-detected, so you can't accidentally land a dev profile on production infrastructure.
STARTERS="user:$(oap identity canonical-id you@example.com)"
oap install --local --builder-starters "$STARTERS" # local dev cluster (kind / Docker Desktop)
oap install --cluster-kind gke --builder-starters "$STARTERS" # a managed GKE cluster
oap install --builder-starters "$STARTERS" # detect from the cluster, default if unknown
oap install needs either --builder-starters (who may start Agent Builder) or --without-builder; see
Agent Builder.
The profiles
| Cluster kind | Memory | SpiceDB datastore | Images | For |
|---|---|---|---|---|
local | SQLite | in-memory (ephemeral) | local :dev | a laptop dev cluster |
desktop | SQLite | in-memory | local | the macOS app |
default | Postgres | Postgres (durable) | registry | on-prem / bare-metal / kind |
gke · eks · aks | Postgres | Postgres | registry | managed cloud, durable |
GKE can provision a bucket for artifacts; EKS and AKS take one you supply with --artifact-store-url. The
managed-cloud kinds require an external hostname (so the platform is reachable and TLS terminates correctly);
the local and desktop kinds keep everything on a local volume. The install validates the kind against the cluster before it changes anything, so a wrong kind fails
fast rather than half-installing.