Installing with oap init

oap init takes you from an empty cluster to a working, configured OAP in one command. It's the CLI counterpart to the Desktop flow — it builds the images, installs the platform, seeds authorization, checks health, and then walks you through the first security and model setup.

`oap init --local`, scripted end to end: resolve the kind → build → install (live checklist) → seed authorization → health-check → first-run setup.

Before you start

  • A reachable Kubernetes cluster — a local one (kind, Docker Desktop) for development, or a managed cluster for production. Everything runs off your kubeconfig.
  • Docker + buildx, if you're building the images locally (the default). A cluster that pulls prebaked images can skip the build with --skip-build.
  • A clone of the repository and the build tools (Git, Go, Mage): see Prerequisites.

Run it

oap init --local                 # a local dev cluster (kind / Docker Desktop)
oap init --cluster-kind gke      # a managed GKE cluster
oap init                         # detect the kind from the cluster

That's the whole command. On a terminal it runs interactively; add -y (and --defaults, --no-idp, --no-monitoring) for an unattended run in CI.

What it does, step by step

  1. Resolves the cluster kind. From --local / --cluster-kind, or by detecting it from the cluster — which decides the install profile (memory backend, SpiceDB datastore, artifact store).
  2. Builds the images — oap build all compiles the first-party components. Skip with --skip-build, or push to a registry with --image-registry <ref>.
  3. Installs the platform — oap install applies the operator, CRDs, services, an operator-managed SpiceDB, the web server, the bus, and the memory stores. It renders as a live checklist of named phases, each with a readiness wait — and asks whether to keep waiting rather than aborting when a component is slow.
  4. Seeds authorization — applies the SpiceDB schema the whole platform authorizes against.
  5. Checks health — oap check --watch polls until every component reports ✓.
  6. Walks you through first-run setup (interactive on a terminal):
    • a security-defaults wizard — the tiered ceilings and defaults (or apply the recommended baseline non-interactively with --defaults);
    • connecting an identity provider for sign-in (skip with --no-idp);
    • registering a default model and its key, so agents don't each need their own;
    • a monitoring channel (skip with --no-monitoring).

When it finishes

oap check confirms each component is healthy. From here, install an agent and talk to it — Your first agent.