Installing with oap init
oap init takes you from an empty cluster to a working, configured OAP in one command. It's the
CLI counterpart to the Desktop flow — it builds the images, installs the
platform, seeds authorization, checks health, and then walks you through the first security and model setup.
Before you start
- A reachable Kubernetes cluster — a local one (kind, Docker Desktop) for development, or a managed cluster for production. Everything runs off your kubeconfig.
- Docker + buildx, if you're building the images locally (the default). A cluster that pulls prebaked images
can skip the build with
--skip-build. - A clone of the repository and the build tools (Git, Go, Mage): see Prerequisites.
Run it
oap init --local # a local dev cluster (kind / Docker Desktop)
oap init --cluster-kind gke # a managed GKE cluster
oap init # detect the kind from the cluster
That's the whole command. On a terminal it runs interactively; add -y (and --defaults, --no-idp,
--no-monitoring) for an unattended run in CI.
What it does, step by step
- Resolves the cluster kind. From
--local/--cluster-kind, or by detecting it from the cluster — which decides the install profile (memory backend, SpiceDB datastore, artifact store). - Builds the images —
oap build allcompiles the first-party components. Skip with--skip-build, or push to a registry with--image-registry <ref>. - Installs the platform —
oap installapplies the operator, CRDs, services, an operator-managed SpiceDB, the web server, the bus, and the memory stores. It renders as a live checklist of named phases, each with a readiness wait — and asks whether to keep waiting rather than aborting when a component is slow. - Seeds authorization — applies the SpiceDB schema the whole platform authorizes against.
- Checks health —
oap check --watchpolls until every component reports✓. - Walks you through first-run setup (interactive on a terminal):
- a security-defaults wizard — the tiered ceilings and defaults (or apply the
recommended baseline non-interactively with
--defaults); - connecting an identity provider for sign-in (skip with
--no-idp); - registering a default model and its key, so agents don't each need their own;
- a monitoring channel (skip with
--no-monitoring).
- a security-defaults wizard — the tiered ceilings and defaults (or apply the
recommended baseline non-interactively with
When it finishes
oap check confirms each component is healthy. From here, install an agent and talk to it —
Your first agent.