Skip to content

Commit e7d7475

Browse files
committed
Document building the team card from the environment sheet
Teams are given access to the environment sheet that the organizers keep and build their team card themselves, so the team-card Lab 0 now says how. - Step 2 maps six columns of a team row to .env lines, gives the console steps for creating an API key for the team service account, and shows a finished card with placeholders. - The READMEs, .env.cloud.example and docs/before-you-arrive.md describe a team environment and its sheet instead of a card that is handed over. - Troubleshooting: with a team card, a rejected key is replaced by creating a new one. - The tutor asks whether the team has a row in the environment sheet. - What was run: steps 2 and 3 against a test instance with the seven lines filled in. The API key steps follow the labels of the console and were not clicked through.
1 parent d610cac commit e7d7475

9 files changed

Lines changed: 116 additions & 69 deletions

File tree

‎.env.cloud.example‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,8 @@
44
# cp .env.cloud.example .env
55
#
66
# labs/cloud/00-set-up.md, step 2, has the snctl command for each address.
7-
# With a team card, every value comes from the card instead:
7+
# In an environment the organizers created for your team, the values come from
8+
# your row in their environment sheet, and you create the API key yourself:
89
# labs/cloud/00-set-up-team-card.md, step 2.
910
# (The Local course writes its own .env: see labs/local/00-set-up.md.)
1011

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ The same five labs, on two stacks.
2626
| | [Cloud course](labs/cloud/README.md) | [Local course](labs/local/README.md) |
2727
|---|---|---|
2828
| Runs on | StreamNative Cloud: your own instance, with a Kafka cluster, a SQL workspace, and an agent workspace | Your laptop: [Ursa for Kafka](https://openlakestream.org/docs/ursa-for-kafka), [RisingWave](https://risingwave.com), and the Orca Agent Engine (`ork local`) |
29-
| You need | A StreamNative Cloud login from the hackathon organizers, with a team card or an instance of your own | Docker and an Anthropic API key |
29+
| You need | A StreamNative Cloud login from the hackathon organizers, with a team environment they created or an instance of your own | Docker and an Anthropic API key |
3030
| Time | About 40 minutes | About 45 minutes, plus image downloads |
3131
| Start | [Lab 0: Set up](labs/cloud/00-set-up.md), or [from a team card](labs/cloud/00-set-up-team-card.md) | [Lab 0: Set up](labs/local/00-set-up.md) |
3232

‎docs/before-you-arrive.md‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -30,8 +30,8 @@ Everyone also needs:
3030
- [`jq`](https://jqlang.org/download/), for the checks in every lab.
3131
- [`snctl`](https://docs.streamnative.io/tools/cli/snctl/snctl-overview) (the
3232
StreamNative Cloud CLI): `brew install streamnative/streamnative/snctl`. Lab 0
33-
uses it to read your instance's addresses and to create your topic. With a
34-
team card (step 4) you do not need it.
33+
uses it to read your instance's addresses and to create your topic. In an
34+
environment the organizers created for your team (step 4) you do not need it.
3535

3636
## 1. Get the code
3737

@@ -74,12 +74,12 @@ Every line should say `PASS`.
7474

7575
## 4. Set up your instance
7676

77-
**Getting a team card?** If the organizers told you that your team's
78-
environment is created for you, skip this step and create nothing in the
79-
console: your Kafka cluster, SQL workspace, and agent workspace already exist.
80-
Your team card has their addresses and an API key, and
81-
[Lab 0: Set up from a team card](../labs/cloud/00-set-up-team-card.md) starts
82-
from it.
77+
**Did the organizers create your team's environment?** Then skip this step and
78+
create nothing in the console: your Kafka cluster, SQL workspace, and agent
79+
workspace already exist. The organizers share an environment sheet with a row
80+
for your team, and
81+
[Lab 0: Set up from a team card](../labs/cloud/00-set-up-team-card.md) turns
82+
that row into your `.env`.
8383

8484
The organizers add you to the hackathon organization on StreamNative Cloud, give
8585
you an **instance** of your own, and make a **service account** in it. They give

‎docs/tutor.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ last row works in any agent that can read a file.
4949
Started with no request, the tutor asks three things:
5050

5151
```text
52-
1. Course: Cloud (on StreamNative Cloud, with a team card from the organizers or with your own instance: say which) or Local (everything on your laptop)?
52+
1. Course: Cloud (on StreamNative Cloud, in a team environment the organizers created or in your own instance: say which) or Local (everything on your laptop)?
5353
2. Path: CLI, Python, or TypeScript?
5454
3. What now: start at Lab 0, resume at a lab, quiz me on a lab, or check my setup?
5555
```
@@ -59,7 +59,7 @@ Started with no request, the tutor asks three things:
5959
| You want to | Say |
6060
|---|---|
6161
| Take a course from the start | `Start the Cloud course on the Python path.` |
62-
| Start from a team card | `Start the Cloud course on the Python path. I have a team card.` |
62+
| Start in a team environment | `Start the Cloud course on the Python path. My team has a row in the organizers' environment sheet.` |
6363
| Pick up where you stopped | `Resume the Local course at Lab 3. I'm on TypeScript.` |
6464
| Be quizzed | `Quiz me on Lab 2.` |
6565
| Find out why something fails | `Check my setup.` Or paste the error. |

‎labs/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ Two courses teach the same five labs on two stacks. Pick one.
55
| | [Cloud course](cloud/README.md) | [Local course](local/README.md) |
66
|---|---|---|
77
| Runs on | StreamNative Cloud: your own instance, with a Kafka cluster, a SQL workspace, and an agent workspace | Your laptop: Ursa for Kafka, RisingWave, and the Orca Agent Engine |
8-
| You need | A StreamNative Cloud login from the hackathon organizers, with a team card or an instance of your own | Docker and an Anthropic API key |
8+
| You need | A StreamNative Cloud login from the hackathon organizers, with a team environment they created or an instance of your own | Docker and an Anthropic API key |
99
| Time | About 40 minutes | About 45 minutes, plus the image downloads |
1010
| Take it when | You are at the event | You have no StreamNative Cloud instance, or you want to see every part run |
1111

‎labs/cloud/00-set-up-team-card.md‎

Lines changed: 80 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,28 @@
11
# Lab 0: Set up from a team card
22

3-
**Cloud course** · 5 minutes, plus 5 on your own · CLI, Python, or TypeScript
3+
**Cloud course** · 8 minutes, plus 5 on your own · CLI, Python, or TypeScript
44

5-
You put your team card in `.env`, load the login stream into your team's Kafka
6-
cluster, and run the doctor. When this lab is done, the Agent Engine, Kafka,
7-
and Schema Registry on your card all answer, and your topic holds 246 logins.
5+
The organizers created an environment for your team on StreamNative Cloud. You
6+
build your **team card** from it, put it in `.env`, load the login stream into
7+
your team's Kafka cluster, and run the doctor. When this lab is done, the Agent
8+
Engine, Kafka, and Schema Registry on your card all answer, and your topic
9+
holds 246 logins.
810

9-
No team card? [Lab 0: Set up](00-set-up.md) starts from an instance of your own
10-
instead. Both end in the same place, and Lab 1 is the same after either.
11+
Your team is not in the organizers' environment sheet?
12+
[Lab 0: Set up](00-set-up.md) starts from an instance of your own instead. Both
13+
end in the same place, and Lab 1 is the same after either.
1114

1215
## Before you start
1316

14-
- You have your **team card** from the organizers: an **API key**, and the
15-
addresses of the environment they created for your team on StreamNative
16-
Cloud. That environment is a Kafka cluster, a SQL workspace that imports it,
17-
an agent workspace, and the service account the key belongs to. Everything on
18-
the card already exists: you create nothing, and you do not need `snctl`.
19-
- You can log in to StreamNative Cloud, and the organizers added your login to
20-
your team's environment. This lab does not use that login; Labs 2 and 3 do.
17+
- The organizers created your team's environment and shared the **environment
18+
sheet** with you. On its **Team Environments** tab, one row is your team's:
19+
the names and addresses of a Kafka cluster, a SQL workspace that imports it,
20+
an agent workspace, and a service account. All of it already exists. In this
21+
lab you create one thing, an API key, and you do not need `snctl`.
22+
- You know your team's number: it is the **Team ID** of your row.
23+
- You can log in to the StreamNative Cloud console, in the organization your
24+
row names. You create your API key there in step 2, and Labs 2 and 3 use the
25+
same login.
2126
- You cloned this repository and opened a terminal in it. The terminal runs
2227
`bash`: on Windows that is WSL or Git Bash, on every path, because the checks
2328
are `bash` commands.
@@ -67,38 +72,73 @@ PASS jq found
6772
All good: you're ready.
6873
```
6974

70-
## Step 2: Fill in `.env` from your team card
75+
## Step 2: Build your team card in `.env`
76+
77+
Your team card is your team's row in the environment sheet, plus an API key
78+
that you create. `.env` is where you write it down.
7179

7280
Open a second terminal at the repository root and copy the template:
7381

7482
```bash
7583
cp .env.cloud.example .env
7684
```
7785

78-
`.env` is git-ignored. It will hold your team's key: do not commit it or paste
79-
it anywhere. Give each of these lines its value from the card:
86+
`.env` is git-ignored. It will hold your key: do not commit it or paste it
87+
anywhere.
88+
89+
**From the sheet.** Open the environment sheet on the **Team Environments** tab
90+
and find the row with your **Team ID**. Six lines of `.env` come from that row:
8091

81-
| `.env` line | On your card | Write it as |
92+
| `.env` line | Column in your row | Write it as |
8293
|---|---|---|
83-
| `SN_API_KEY` | API key | the raw key, with no `token:` in front |
84-
| `SN_SERVICE_ACCOUNT` | Service account | `<name>@<org>.auth.streamnative.cloud`. If the card has only the name, add the rest, with the organization id from the card (`o-...`) |
85-
| `ORCA_BASE_URL` | Agent workspace endpoint | `https://` and the host, with no `/v1` |
86-
| `KAFKA_BOOTSTRAP_SERVERS` | Broker URL | the host and its port, `:9093` |
87-
| `SCHEMA_REGISTRY_URL` | Schema registry URL | `https://` and the host |
88-
| `SN_MCP_URL` | SQL workspace MCP endpoint | `https://mcp.streamnative.cloud/mcp/x/<org>/sqlworkspace.compute.streamnative.io/<SQL workspace>` |
89-
| `SN_SQL_DATABASE` | SQL database | as given. It is the name of your SQL catalog, not of your SQL workspace |
90-
91-
If your card already is a list of `NAME=value` lines, paste each one over the
92-
empty line with the same name.
93-
94-
`SN_SQL_DATABASE` is the database you use in Lab 2 and the agent targets in
95-
Labs 3 and 4. Leave the other lines as they are: the MCP server uses a separate
96-
browser login in Lab 3, so `SN_MCP_AUTH=oauth` stays, and `SN_MCP_OAUTH_ISSUER`
97-
stays empty.
98-
99-
**Two people share one team card.** Your teammate fills in the same values, and
100-
you both work in the same Kafka cluster and the same SQL database. Your agents
101-
stay apart: each is named after its owner's OS user name, like
94+
| `SN_SERVICE_ACCOUNT` | **Service Account**, with **StreamNative Cloud Organization** | `<Service Account>@<Organization>.auth.streamnative.cloud`. A cell that already ends in `.auth.streamnative.cloud` goes in as it is |
95+
| `ORCA_BASE_URL` | **Agent Workspace Endpoint** | `https://` and the host, with no `/v1` |
96+
| `KAFKA_BOOTSTRAP_SERVERS` | **Broker URL** | as it is: the host and its port, `:9093` |
97+
| `SCHEMA_REGISTRY_URL` | **Schema Registry URL** | as it is, with `https://` |
98+
| `SN_MCP_URL` | **SQL Workspace MCP Endpoint** | as it is |
99+
| `SN_SQL_DATABASE` | **SQL Database** | as it is. It is the database you open in Lab 2, and it is not your SQL workspace's name |
100+
101+
A cell you need is empty? Ask a facilitator. One value you can build yourself:
102+
the MCP endpoint is
103+
`https://mcp.streamnative.cloud/mcp/x/<Organization>/sqlworkspace.compute.streamnative.io/<SQL Workspace Name>`,
104+
from two other cells of your row.
105+
106+
**Your API key.** The sheet holds no keys. You create one in the StreamNative
107+
Cloud console, for the service account in your row:
108+
109+
1. Log in to the console, in the organization your row names.
110+
2. Open the organization's **Settings**. Under **Access & Control**, click
111+
**Service Accounts**, then click your team's service account.
112+
3. Click **Create API key**. Give the key a **Name** that nobody else in the
113+
organization uses, in lowercase letters, digits, and dashes: your team and
114+
your name work, such as `team07-ana`. Leave **Expiration** at 30 days, and
115+
click **Create**.
116+
4. The next window shows the key, once. Click **Copy**, paste the key into
117+
`.env` as `SN_API_KEY` with nothing in front of it, then click **Close**. If
118+
you lose the key, create another.
119+
120+
If **Create API key** is greyed out, your login may not create keys: ask a
121+
facilitator.
122+
123+
Leave the other lines as they are: the MCP server uses a separate browser login
124+
in Lab 3, so `SN_MCP_AUTH=oauth` stays, and `SN_MCP_OAUTH_ISSUER` stays empty.
125+
126+
Your finished card has these seven lines filled in:
127+
128+
```text
129+
SN_API_KEY=<the key you copied>
130+
SN_SERVICE_ACCOUNT=<service account>@<organization>.auth.streamnative.cloud
131+
ORCA_BASE_URL=https://<agent workspace host>
132+
KAFKA_BOOTSTRAP_SERVERS=<broker host>:9093
133+
SCHEMA_REGISTRY_URL=https://<schema registry host>
134+
SN_MCP_URL=https://mcp.streamnative.cloud/mcp/x/<organization>/sqlworkspace.compute.streamnative.io/<SQL workspace>
135+
SN_SQL_DATABASE=<SQL database>
136+
```
137+
138+
**Two people share one environment.** Your teammate fills in the same six lines
139+
from the same row, and can create a key of their own for the same service
140+
account. You both work in the same Kafka cluster and the same SQL database.
141+
Your agents stay apart: each is named after its owner's OS user name, like
102142
`hello-agent-ana`. If the two of you have the same user name, each set
103143
`PARTICIPANT` in `.env` to a name of your own. In Lab 2 the view and the table
104144
are created once for the team: if your teammate got there first, the `CREATE`
@@ -190,7 +230,7 @@ Still failing after two tries? Raise your hand, or see
190230

191231
- A. Fix it now: the doctor has to print only `PASS`.
192232
- B. Nothing yet: Lab 3 does the browser login this check waits for.
193-
- C. Ask for a new team card.
233+
- C. Create a new API key.
194234

195235
<details>
196236
<summary>Answer</summary>
@@ -263,8 +303,9 @@ Engine check, tells you the exact value to use, and ends with
263303

264304
## Recap
265305

266-
- `.env` holds your team card: the addresses of your team's environment and its
267-
key. It is git-ignored.
306+
- `.env` holds your team card: six values from your team's row in the
307+
environment sheet, and an API key you created for your team's service
308+
account. It is git-ignored.
268309
- Your team shares that environment. The login stream is loaded once, and the
269310
seeder refuses a second copy.
270311
- The doctor checks each service on the card and prints the fix for a failure.

‎labs/cloud/README.md‎

Lines changed: 10 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ flowchart LR
2525
| Lab | Time | Where | You | The idea |
2626
|---|---|---|---|---|
2727
| [0. Set up](00-set-up.md) | 10 min | terminal | Fill in `.env` from your instance, load the topic, run the doctor | Check service access before you build on it |
28-
| or [0. Set up from a team card](00-set-up-team-card.md) | 5 min | terminal | Fill in `.env` from your team card, load the topic, run the doctor | The same, when the organizers created your environment |
28+
| or [0. Set up from a team card](00-set-up-team-card.md) | 8 min | terminal | Build your team card from the organizers' environment sheet, load the topic, run the doctor | The same, when the organizers created your environment |
2929
| [1. Hello, agent](01-hello-agent.md) | 5 min | CLI / Python / TS | Create an agent and chat | Agent, environment, session, events |
3030
| [2. Hello, streaming SQL](02-streaming-sql.md) | 8 min | SQL Workspace | Build a materialized view over the topic | Context that keeps itself fresh |
3131
| [3. Agent + live context](03-live-context.md) | 9 min | CLI / Python / TS | Give the agent SQL tools, inject new data | The answer changes with the data |
@@ -44,8 +44,9 @@ your own.
4444
- One path installed, plus `ork`, `jq`, and `snctl`. All of this is in
4545
[Before you arrive](../../docs/before-you-arrive.md).
4646

47-
**Have a team card?** Then the organizers created all of this for your team,
48-
and the card has its addresses and an API key. You need only your login, one
47+
**Is your team in the organizers' environment sheet?** Then they created all
48+
of this for your team. Your team's row has the addresses, and you create an API
49+
key yourself: together they are your team card. You need only your login, one
4950
path, `ork`, and `jq`, and you start with
5051
[Lab 0: Set up from a team card](00-set-up-team-card.md).
5152

@@ -67,14 +68,15 @@ cluster was Serverless; the SQL workspace ran RisingWave 3.1.0-alpha.
6768
Python path. On the TypeScript path, the doctor, and the seeder against the
6869
topic once it was loaded.
6970
- **Lab 0 from a team card**: added on 6 October 2026 and run that day against
70-
the same test instance, from a card of ready-made `NAME=value` lines. On the
71+
the same test instance, with the seven lines of step 2 filled in. On the
7172
Python path: every step and check, and the failing doctor run its solution
7273
shows. On the TypeScript path, and with the CLI column's commands: the doctor
7374
and the seeder. The topic was loaded already (274 events, after earlier Lab 3
74-
runs), so the seeder printed its "already holds" line each time. The card had
75-
no `SN_SQL_DATABASE` line; nothing in Lab 0 reads that value. Not run from
76-
this page: the seeder on an empty topic, a card of labeled values, and an
77-
environment the organizers created.
75+
runs), so the seeder printed its "already holds" line each time. Nothing in
76+
Lab 0 reads `SN_SQL_DATABASE`. Not run from this page: reading the values
77+
from an environment sheet, creating the API key (its steps follow the
78+
console's labels as of 3 October 2026; the key used was an existing one), the
79+
seeder on an empty topic, and an environment the organizers created.
7880
- **Lab 2**: every statement and check, through `psql`. The console was not
7981
used.
8082
- **Labs 1, 3 and 4**: every step and check, on all three paths, with the model

‎labs/cloud/troubleshooting.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ Still stuck after two tries? Raise your hand.
1414
| Symptom | Fix |
1515
|---|---|
1616
| `pip install -r requirements.txt`: `No matching distribution found for runorca==0.3.0` | The `python3` that made your virtual environment is older than the course needs: on macOS, Apple's own is 3.9. Install Python 3.11 or newer, then make the environment again with it. In `python/`: `rm -rf .venv`, then the install commands from Lab 0 with that Python's name in place of `python3`, for example `python3.13 -m venv .venv`. |
17-
| Doctor: `Agent Engine HTTP 401/403` | The key was rejected. A key created before its permissions must be re-created: ask a facilitator. |
17+
| Doctor: `Agent Engine HTTP 401/403` | The key was rejected. A key created before its permissions must be re-created. With a team card, create a new key yourself (Lab 0, step 2) and put it in `SN_API_KEY`; otherwise ask a facilitator. |
1818
| Doctor: `Kafka ... authentication` | `SN_SERVICE_ACCOUNT` must be the full principal, `<name>@<org>.auth.streamnative.cloud`; `SN_API_KEY` is the raw key. |
1919
| Doctor: `Kafka security.login_events: not found` | The topic is not there yet. Create it and load it: Lab 0, step 3. |
2020
| Doctor: `Schema Registry ... not found` | The schema is registered when you load the topic: Lab 0, step 3. |

0 commit comments

Comments
 (0)