Skip to content

fix(installer): one-command keyless install with proper flag handling (P0-1) - #122

Open
venkateshsakamuri-lab wants to merge 6 commits into
mainfrom
cursor/p0-1-installer-overhaul-968c
Open

venkateshsakamuri-lab wants to merge 6 commits into
mainfrom
cursor/p0-1-installer-overhaul-968c

Conversation

@venkateshsakamuri-lab

@venkateshsakamuri-lab venkateshsakamuri-lab commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

P0-1 Installer Overhaul — Keyless One-Command Install

This PR addresses the P0-1 launch blocker: a new user runs ONE command (curl -fsSL https://deepsql.ai/install.sh | bash), provides ONLY an LLM key (optional), and lands in a working product. AI agents can do the same non-interactively.

Summary of Changes

1. Environment Variable Naming

  • DEEPSQL_LLM_API_KEY is now the primary documented name (matches spec and evangelist docs)
  • DEEPSQL_CHAT_API_KEY remains as a backend alias for compatibility
  • Similar aliasing for DEEPSQL_LLM_PROVIDER, DEEPSQL_LLM_BASE_URL, DEEPSQL_LLM_MODEL

2. Keyless Start Support

  • Agent container now starts without LLM key in degraded mode
  • Shows clear warning: "WARNING: No LLM key configured. Agent will start in degraded mode."
  • All services come up healthy without a key
  • Backend and Frontend work normally; AI features disabled until key is configured

3. Piped Execution Fixes

  • Fixed stdin protection when script is piped (</dev/null on git commands and install.sh exec)
  • Fixed TTY detection to test actual accessibility, not just existence (works with setsid)
  • Flags properly pass through the pipe (--help, --no-seed-demo, --project-name)

4. Documentation Updates

  • Replaced all "Settings → AI Provider" references with "during onboarding in the web UI"
  • Updated README.md, docs/QUICKSTART.md, docs/llms-full.txt, docs/llms.txt
  • Updated install.sh help text and NEEDS_USER_INPUT line

Acceptance Test Results

Test 1: Piped one-liner, no TTY, defaults

setsid bash -c 'cat /workspace/scripts/self-host/remote-install.sh | bash -s'

Result: PASS

✓ Docker is running
✓ Docker Compose 2.29.2
✓ Docker buildx 0.19.3
Auto-generated SECURITY_JWT_SECRET.
Auto-generated ENCRYPTION_KEY.
...
NEEDS_USER_INPUT: DEEPSQL_LLM_API_KEY (optional, can be set during onboarding at http://localhost:3000)
...
Backend is healthy: http://localhost:8080/api/actuator/health
Frontend is healthy: http://localhost:3000
...
DeepSQL is running!

All services healthy:

NAME                               STATUS
deepsql-selfhost-backend-1         Up (healthy)
deepsql-selfhost-deepsql-agent-1   Up (healthy)
deepsql-selfhost-frontend-1        Up
deepsql-selfhost-postgres-1        Up (healthy)
deepsql-selfhost-valkey-1          Up (healthy)

Test 2: Env-var key path

DEEPSQL_LLM_API_KEY=sk-dummy-test setsid bash -c 'cat remote-install.sh | bash -s'

Result: PASS

  • No NEEDS_USER_INPUT printed when key is provided ✓
  • Key reached backend: DEEPSQL_CHAT_API_KEY=***MASKED*** ✓
  • Agent NOT in keyless mode (placeholder key not used) ✓

Test 3a: --help through pipe

cat remote-install.sh | setsid bash -s -- --help

Result: PASS (exit 0, no install)

DeepSQL Remote Installer

Usage: curl -fsSL https://deepsql.ai/install.sh | bash -s -- [options]

One command installs DeepSQL. The only input is an LLM key (optional—can be
set later during onboarding in the web UI).

Options:
  -h, --help           Show this help message and exit
  ...

Test 3b: Flags honored through pipe

DEEPSQL_INITIAL_ADMIN_EMAIL=test@deepsql.local cat remote-install.sh | \
  setsid bash -s -- --non-interactive --no-seed-demo --project-name deepsql-test

Result: PASS

  • --no-seed-demo honored: Demo data seeding skipped (--no-seed-demo).
  • --project-name deepsql-test honored: Project: deepsql-test
  • Containers named deepsql-test-* ✓

Test 4: Reinstall warning with existing volumes

# Run installer again without --fresh
cat remote-install.sh | setsid bash -s -- --non-interactive --project-name deepsql-test

Result: PASS

Warning: Existing volumes found for project 'deepsql-test'.
  This install will reuse existing data (admin account, connections, etc.).
  For a fresh install, run with --fresh flag.

Files Changed

  • scripts/self-host/install.sh — Env var aliasing, keyless start, TTY detection fix
  • scripts/self-host/remote-install.sh — Stdin protection for piped execution
  • agent/docker-entrypoint.sh — Allow keyless start with placeholder key
  • README.md — Updated "For AI agents" section
  • docs/QUICKSTART.md — Updated keyless start docs
  • docs/llms-full.txt / docs/llms.txt — Updated AI agent runbook
  • scripts/self-host/bootstrap-server.sh — Updated env var guidance

Acceptance Criteria

  • Piped one-liner works with no TTY and no key
  • Env var key path works (DEEPSQL_LLM_API_KEY)
  • Flags pass through pipe correctly (--help, --no-seed-demo, --project-name)
  • Reinstall warning shows when volumes exist
  • All services come up healthy without LLM key
  • Agent container starts in degraded mode without key
  • DEEPSQL_LLM_API_KEY is primary documented name
  • No "Settings → AI Provider" references (P0-2 feature)
  • NEEDS_USER_INPUT line uses correct env var name
Open in Web Open in Cursor 

cursoragent and others added 6 commits September 26, 2026 08:30
Major changes to install.sh:
- Allow keyless start: stack runs without LLM key, configurable later in Settings
- Env vars override .env placeholders (fixes the precedence bug)
- Add --help, --version, --non-interactive, --seed-demo, --no-seed-demo, --fresh, --project-name flags
- TTY-aware prompts: prompt via /dev/tty if available, never block without TTY
- Print NEEDS_USER_INPUT for missing optional inputs in non-interactive mode
- Auto-generate admin password if not provided
- Fix: print login email instead of 'username: admin'
- Detect Docker permission error and print exact fix
- Warn on reinstall with existing volumes (offer --fresh)
- Demo seeding now defaults to ON

Major changes to remote-install.sh:
- Now runs install end-to-end by default (was just clone + print instructions)
- Latest release detection retries, then falls back to git ls-remote
- Fails loudly if release detection fails (no silent fallback to main)
- Pass through all flags to install.sh
- Renamed --branch to --ref for clarity

Fixes P0-1: the one-liner now performs the full install.

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
- README.md: add 'For AI agents' section with exact non-interactive command
- docs/llms-full.txt: create AI agent runbook with correct health URL
  (/api/actuator/health not /actuator/health)
- docs/llms.txt: create short version for quick reference
- docs/QUICKSTART.md: rewrite for current install flow (was stale: Java 17,
  start-backend.sh, NEXT_PUBLIC_API_URL)

Fixes P1 item: llms-full.txt health URL 404s.

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
- Add shellcheck job to lint installer scripts
- Add installer-args job to smoke test --help, --version, unknown arg handling
- Fix shellcheck SC1090 warnings in status.sh and smoke-test.sh
  (move directive immediately before source command)

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
…ss start

P0-1 installer fixes:
- Use DEEPSQL_LLM_API_KEY as the primary documented env var name (DEEPSQL_CHAT_API_KEY remains as backend alias)
- Allow agent container to start without LLM key in degraded mode
- Replace 'Settings → AI Provider' references with 'during onboarding in the web UI'
- Update NEEDS_USER_INPUT line to use DEEPSQL_LLM_API_KEY

Files updated:
- scripts/self-host/install.sh: Env var aliasing, keyless start messages
- scripts/self-host/remote-install.sh: Updated env var names in docs/examples
- agent/docker-entrypoint.sh: Allow keyless start in degraded mode
- README.md, docs/QUICKSTART.md, docs/llms*.txt: Updated env var names
- scripts/self-host/bootstrap-server.sh: Updated env var guidance

Tested: Full Docker e2e with keyless start - all services healthy.

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
When remote-install.sh is piped to bash, child commands (git clone/fetch,
install.sh) could consume stdin and swallow the rest of the script.

Fixes:
- Add </dev/null to git clone/fetch/checkout commands
- Redirect install.sh stdin from /dev/null when not running in a TTY

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
- can_prompt() now checks if /dev/tty is actually accessible, not just exists
- Print NEEDS_USER_INPUT when no TTY available (piped via setsid)

Co-authored-by: Venkat SF <venkatesh.sakamuri@stayflexi.com>
@venkateshsakamuri-lab
venkateshsakamuri-lab marked this pull request as ready for review September 26, 2026 09:10
@venkateshsakamuri-lab
venkateshsakamuri-lab requested a review from a team as a code owner September 26, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants