Files
OpenFlare/docs/en/deployment/agent.md
T
ryan 454542c1d0 docs(i18n): 恢复并补齐英文版 vitepress,README 默认改为英文
- README 默认英文:README.en.md → README.md(英文为默认),中文移至 README.zh-CN.md,语言切换链接同步
- 恢复被删除的 docs/en/ 英文文档(git 历史 cc5e53c5^),删除 4 篇已废弃文件
- 英文导航 config.ts 对齐中文结构(新增 Deployment/Changelog 侧栏,同步 Guide/Design 条目)
- 翻译 15 篇中文新增文档:guide 5 篇(certificates/pages-usage/proxy-config/uptime-kuma/zone-domain-migration)+ design 10 篇(zone-design/cloudflare-pointing/waf-orchestration/origin-error-page/edge-cache-design/pages-design/logstore/kuma-design/login-captcha/observability 三篇)
- en 首页更新(新增 Pages 特性、tagline 同步);changelog 英文入口指向中文版
- vitepress 构建验证:43 个英文页面全部渲染

注意:29 篇旧英文文档为恢复版,部分内容(如 deployment/server、reference/configuration)可能落后于中文,需后续逐篇同步
2026-08-16 23:18:29 +08:00

6.4 KiB

Access Agent

You will learn: The responsibilities of the Agent, the difference between the two access Tokens, installation script parameters, agent.json settings, and how to verify that the node has successfully connected.

The OpenFlare Agent runs on the proxy node. It does not receive arbitrary remote shell commands; instead, it pulls the configuration version published by the control plane via the Agent API, writes files for OpenResty locally, executes configuration validation, reloads, and attempts to roll back to a working configuration if it fails.

Connection Credentials

Method Applicable Scenario
discovery_token Automatically registers a node for the first time, which the Server exchanges for a node-specific credential
agent_token Node has already been created/allocated in the management console, directly uses this node-specific credential

At least one of agent_token or discovery_token must be configured.

Credential Retrieval Path

  • discovery_token (Auto Registration Token): Log into the management console, navigate to "System Settings" -> "Auto Registration", where you can generate, view, and copy the global auto-registration credential.
  • agent_token (Node Specific Token): Log into the management console, navigate to "Node Management" -> "Add Node", fill in basic node information, save, and copy the node-specific access Token in the node details.

One-Click Installation

Using the discovery_token:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --discovery-token YOUR_DISCOVERY_TOKEN

Using the node-specific agent_token:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --agent-token YOUR_AGENT_TOKEN

The installation script downloads the latest Agent, writes to /opt/openflare-agent by default, generates agent.json, and registers openflare-agent.service on Linux + systemd environments.

Supported arguments:

Argument Description Default Value
--server-url Server address (required)
--discovery-token One-time auto-registration Token
--agent-token Node-specific Token
--install-dir Target installation directory /opt/openflare-agent
--openresty-path Path to the OpenResty binary; automatically detects openresty if unspecified
--repo GitHub repository to download from Rain-kl/OpenFlare
--no-service Do not register systemd service

Configuration File

Default configuration file path:

/opt/openflare-agent/agent.json

Example local configuration:

{
  "server_url": "http://127.0.0.1:3000",
  "agent_token": "replace-with-node-auth-token",
  "data_dir": "./data",
  "openresty_path": "openresty",
  "openresty_observability_port": 18081,
  "observability_replay_minutes": 15,
  "heartbeat_interval": 10000,
  "request_timeout": 10000
}

Example customized OpenResty paths configuration:

{
  "server_url": "http://127.0.0.1:3000",
  "agent_token": "replace-with-node-auth-token",
  "data_dir": "/var/lib/openflare-agent",
  "openresty_path": "/usr/local/openresty/nginx/sbin/openresty",
  "main_config_path": "/var/lib/openflare-agent/etc/nginx/nginx.conf",
  "route_config_path": "/var/lib/openflare-agent/etc/nginx/conf.d/openflare_routes.conf",
  "access_log_path": "/var/lib/openflare-agent/var/log/openflare/access.log",
  "cert_dir": "/var/lib/openflare-agent/etc/nginx/certs",
  "lua_dir": "/var/lib/openflare-agent/etc/nginx/lua",
  "runtime_config_dir": "/var/lib/openflare-agent/etc/openflare",
  "heartbeat_interval": 10000,
  "request_timeout": 10000
}

If openresty_path is not configured, the Agent calls openresty by default. For the full fields, see Configurations Reference.

Running in Docker

For Docker deployments, run the Agent image containing built-in OpenResty directly:

docker pull ghcr.io/rain-kl/openflare-agent:latest
docker rm -f openflare-agent 2>/dev/null || true
docker run -d --name openflare-agent --restart unless-stopped \
  -p 80:80 -p 443:443 \
  -e OPENFLARE_SERVER_URL=http://your-server:3000 \
  -e OPENFLARE_AGENT_TOKEN=YOUR_AGENT_TOKEN \
  ghcr.io/rain-kl/openflare-agent:latest

Start & Validate

In a systemd environment:

systemctl start openflare-agent
systemctl status openflare-agent
journalctl -u openflare-agent -f

Manual execution:

/opt/openflare-agent/openflare-agent -config /opt/openflare-agent/agent.json

Running from source:

cd openflare-agent
export LOG_LEVEL='info'
go run ./cmd/agent -config /path/to/agent.json

Running compiled binary:

cd openflare-agent
go build -o openflare-agent ./cmd/agent
export LOG_LEVEL='info'
./openflare-agent -config /path/to/agent.json

Confirm in the management console:

Position Expected Result
Node List Node status is online
Node Details Heartbeat, current version, and basic resource metrics display correctly
Apply Logs Application result displays after publishing

Uninstall

To completely uninstall the Agent and wipe local data:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash

Supported arguments:

Argument Description Default Value
--install-dir Installation directory /opt/openflare-agent
--service-name systemd service name openflare-agent

The uninstallation script only removes the Agent service, processes, and installation directory; it does not uninstall OpenResty from the host.

Common Questions

Symptom Actions
agent_token and discovery_token cannot both be empty Check if at least one Token is configured in agent.json
Node stays offline Run curl -I http://your-server:3000 on the Agent node to verify that the Server is reachable
OpenResty is not running Review journalctl -u openflare-agent, checking that openresty_path is executable and ports 80/443 are not bound
Repeated application failures after publishing The Agent blocks repeated sync attempts of the same failing version + checksum; fix the configuration and republish, or activate an older version to roll back