|
1 | 1 | # Lab 0: Set up from a team card |
2 | 2 |
|
3 | | -**Cloud course** · 5 minutes, plus 5 on your own · CLI, Python, or TypeScript |
| 3 | +**Cloud course** · 8 minutes, plus 5 on your own · CLI, Python, or TypeScript |
4 | 4 |
|
5 | | -You put your team card in `.env`, load the login stream into your team's Kafka |
6 | | -cluster, and run the doctor. When this lab is done, the Agent Engine, Kafka, |
7 | | -and Schema Registry on your card all answer, and your topic holds 246 logins. |
| 5 | +The organizers created an environment for your team on StreamNative Cloud. You |
| 6 | +build your **team card** from it, put it in `.env`, load the login stream into |
| 7 | +your team's Kafka cluster, and run the doctor. When this lab is done, the Agent |
| 8 | +Engine, Kafka, and Schema Registry on your card all answer, and your topic |
| 9 | +holds 246 logins. |
8 | 10 |
|
9 | | -No team card? [Lab 0: Set up](00-set-up.md) starts from an instance of your own |
10 | | -instead. Both end in the same place, and Lab 1 is the same after either. |
| 11 | +Your team is not in the organizers' environment sheet? |
| 12 | +[Lab 0: Set up](00-set-up.md) starts from an instance of your own instead. Both |
| 13 | +end in the same place, and Lab 1 is the same after either. |
11 | 14 |
|
12 | 15 | ## Before you start |
13 | 16 |
|
14 | | -- You have your **team card** from the organizers: an **API key**, and the |
15 | | - addresses of the environment they created for your team on StreamNative |
16 | | - Cloud. That environment is a Kafka cluster, a SQL workspace that imports it, |
17 | | - an agent workspace, and the service account the key belongs to. Everything on |
18 | | - the card already exists: you create nothing, and you do not need `snctl`. |
19 | | -- You can log in to StreamNative Cloud, and the organizers added your login to |
20 | | - your team's environment. This lab does not use that login; Labs 2 and 3 do. |
| 17 | +- The organizers created your team's environment and shared the **environment |
| 18 | + sheet** with you. On its **Team Environments** tab, one row is your team's: |
| 19 | + the names and addresses of a Kafka cluster, a SQL workspace that imports it, |
| 20 | + an agent workspace, and a service account. All of it already exists. In this |
| 21 | + lab you create one thing, an API key, and you do not need `snctl`. |
| 22 | +- You know your team's number: it is the **Team ID** of your row. |
| 23 | +- You can log in to the StreamNative Cloud console, in the organization your |
| 24 | + row names. You create your API key there in step 2, and Labs 2 and 3 use the |
| 25 | + same login. |
21 | 26 | - You cloned this repository and opened a terminal in it. The terminal runs |
22 | 27 | `bash`: on Windows that is WSL or Git Bash, on every path, because the checks |
23 | 28 | are `bash` commands. |
@@ -67,38 +72,73 @@ PASS jq found |
67 | 72 | All good: you're ready. |
68 | 73 | ``` |
69 | 74 |
|
70 | | -## Step 2: Fill in `.env` from your team card |
| 75 | +## Step 2: Build your team card in `.env` |
| 76 | + |
| 77 | +Your team card is your team's row in the environment sheet, plus an API key |
| 78 | +that you create. `.env` is where you write it down. |
71 | 79 |
|
72 | 80 | Open a second terminal at the repository root and copy the template: |
73 | 81 |
|
74 | 82 | ```bash |
75 | 83 | cp .env.cloud.example .env |
76 | 84 | ``` |
77 | 85 |
|
78 | | -`.env` is git-ignored. It will hold your team's key: do not commit it or paste |
79 | | -it anywhere. Give each of these lines its value from the card: |
| 86 | +`.env` is git-ignored. It will hold your key: do not commit it or paste it |
| 87 | +anywhere. |
| 88 | + |
| 89 | +**From the sheet.** Open the environment sheet on the **Team Environments** tab |
| 90 | +and find the row with your **Team ID**. Six lines of `.env` come from that row: |
80 | 91 |
|
81 | | -| `.env` line | On your card | Write it as | |
| 92 | +| `.env` line | Column in your row | Write it as | |
82 | 93 | |---|---|---| |
83 | | -| `SN_API_KEY` | API key | the raw key, with no `token:` in front | |
84 | | -| `SN_SERVICE_ACCOUNT` | Service account | `<name>@<org>.auth.streamnative.cloud`. If the card has only the name, add the rest, with the organization id from the card (`o-...`) | |
85 | | -| `ORCA_BASE_URL` | Agent workspace endpoint | `https://` and the host, with no `/v1` | |
86 | | -| `KAFKA_BOOTSTRAP_SERVERS` | Broker URL | the host and its port, `:9093` | |
87 | | -| `SCHEMA_REGISTRY_URL` | Schema registry URL | `https://` and the host | |
88 | | -| `SN_MCP_URL` | SQL workspace MCP endpoint | `https://mcp.streamnative.cloud/mcp/x/<org>/sqlworkspace.compute.streamnative.io/<SQL workspace>` | |
89 | | -| `SN_SQL_DATABASE` | SQL database | as given. It is the name of your SQL catalog, not of your SQL workspace | |
90 | | - |
91 | | -If your card already is a list of `NAME=value` lines, paste each one over the |
92 | | -empty line with the same name. |
93 | | - |
94 | | -`SN_SQL_DATABASE` is the database you use in Lab 2 and the agent targets in |
95 | | -Labs 3 and 4. Leave the other lines as they are: the MCP server uses a separate |
96 | | -browser login in Lab 3, so `SN_MCP_AUTH=oauth` stays, and `SN_MCP_OAUTH_ISSUER` |
97 | | -stays empty. |
98 | | - |
99 | | -**Two people share one team card.** Your teammate fills in the same values, and |
100 | | -you both work in the same Kafka cluster and the same SQL database. Your agents |
101 | | -stay apart: each is named after its owner's OS user name, like |
| 94 | +| `SN_SERVICE_ACCOUNT` | **Service Account**, with **StreamNative Cloud Organization** | `<Service Account>@<Organization>.auth.streamnative.cloud`. A cell that already ends in `.auth.streamnative.cloud` goes in as it is | |
| 95 | +| `ORCA_BASE_URL` | **Agent Workspace Endpoint** | `https://` and the host, with no `/v1` | |
| 96 | +| `KAFKA_BOOTSTRAP_SERVERS` | **Broker URL** | as it is: the host and its port, `:9093` | |
| 97 | +| `SCHEMA_REGISTRY_URL` | **Schema Registry URL** | as it is, with `https://` | |
| 98 | +| `SN_MCP_URL` | **SQL Workspace MCP Endpoint** | as it is | |
| 99 | +| `SN_SQL_DATABASE` | **SQL Database** | as it is. It is the database you open in Lab 2, and it is not your SQL workspace's name | |
| 100 | + |
| 101 | +A cell you need is empty? Ask a facilitator. One value you can build yourself: |
| 102 | +the MCP endpoint is |
| 103 | +`https://mcp.streamnative.cloud/mcp/x/<Organization>/sqlworkspace.compute.streamnative.io/<SQL Workspace Name>`, |
| 104 | +from two other cells of your row. |
| 105 | + |
| 106 | +**Your API key.** The sheet holds no keys. You create one in the StreamNative |
| 107 | +Cloud console, for the service account in your row: |
| 108 | + |
| 109 | +1. Log in to the console, in the organization your row names. |
| 110 | +2. Open the organization's **Settings**. Under **Access & Control**, click |
| 111 | + **Service Accounts**, then click your team's service account. |
| 112 | +3. Click **Create API key**. Give the key a **Name** that nobody else in the |
| 113 | + organization uses, in lowercase letters, digits, and dashes: your team and |
| 114 | + your name work, such as `team07-ana`. Leave **Expiration** at 30 days, and |
| 115 | + click **Create**. |
| 116 | +4. The next window shows the key, once. Click **Copy**, paste the key into |
| 117 | + `.env` as `SN_API_KEY` with nothing in front of it, then click **Close**. If |
| 118 | + you lose the key, create another. |
| 119 | + |
| 120 | +If **Create API key** is greyed out, your login may not create keys: ask a |
| 121 | +facilitator. |
| 122 | + |
| 123 | +Leave the other lines as they are: the MCP server uses a separate browser login |
| 124 | +in Lab 3, so `SN_MCP_AUTH=oauth` stays, and `SN_MCP_OAUTH_ISSUER` stays empty. |
| 125 | + |
| 126 | +Your finished card has these seven lines filled in: |
| 127 | + |
| 128 | +```text |
| 129 | +SN_API_KEY=<the key you copied> |
| 130 | +SN_SERVICE_ACCOUNT=<service account>@<organization>.auth.streamnative.cloud |
| 131 | +ORCA_BASE_URL=https://<agent workspace host> |
| 132 | +KAFKA_BOOTSTRAP_SERVERS=<broker host>:9093 |
| 133 | +SCHEMA_REGISTRY_URL=https://<schema registry host> |
| 134 | +SN_MCP_URL=https://mcp.streamnative.cloud/mcp/x/<organization>/sqlworkspace.compute.streamnative.io/<SQL workspace> |
| 135 | +SN_SQL_DATABASE=<SQL database> |
| 136 | +``` |
| 137 | + |
| 138 | +**Two people share one environment.** Your teammate fills in the same six lines |
| 139 | +from the same row, and can create a key of their own for the same service |
| 140 | +account. You both work in the same Kafka cluster and the same SQL database. |
| 141 | +Your agents stay apart: each is named after its owner's OS user name, like |
102 | 142 | `hello-agent-ana`. If the two of you have the same user name, each set |
103 | 143 | `PARTICIPANT` in `.env` to a name of your own. In Lab 2 the view and the table |
104 | 144 | are created once for the team: if your teammate got there first, the `CREATE` |
@@ -190,7 +230,7 @@ Still failing after two tries? Raise your hand, or see |
190 | 230 |
|
191 | 231 | - A. Fix it now: the doctor has to print only `PASS`. |
192 | 232 | - B. Nothing yet: Lab 3 does the browser login this check waits for. |
193 | | -- C. Ask for a new team card. |
| 233 | +- C. Create a new API key. |
194 | 234 |
|
195 | 235 | <details> |
196 | 236 | <summary>Answer</summary> |
@@ -263,8 +303,9 @@ Engine check, tells you the exact value to use, and ends with |
263 | 303 |
|
264 | 304 | ## Recap |
265 | 305 |
|
266 | | -- `.env` holds your team card: the addresses of your team's environment and its |
267 | | - key. It is git-ignored. |
| 306 | +- `.env` holds your team card: six values from your team's row in the |
| 307 | + environment sheet, and an API key you created for your team's service |
| 308 | + account. It is git-ignored. |
268 | 309 | - Your team shares that environment. The login stream is loaded once, and the |
269 | 310 | seeder refuses a second copy. |
270 | 311 | - The doctor checks each service on the card and prints the fix for a failure. |
|
0 commit comments