OpenHuman on Oracle Cloud: headless core with no account, governed Oracle Database through the managed MCP server, all Always Free, all Terraform #6940
fede-kamel
started this conversation in
Show and tell
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
I ran the headless core on Oracle Cloud Infrastructure with three properties the default setup does not have: no TinyHumans account (inference from OCI Generative AI through its OpenAI-compatible endpoint, wired in as a caller-owned
local-openairuntime), governed Oracle Database access (agents reach data only through Oracle's managed Database Tools MCP Server under IAM policy and identity-domain app roles, no wallet or SQL driver in the container), and everything else on OCI's Always Free tier (one Ampere A1 VM, one Autonomous AI Database, one load balancer, Vault, Bastion). It is all Terraform, oneapplybuilds it in about twenty minutes, and the whole thing is public.Repository: https://github.com/kamelhar/openhuman-oci (Apache-2.0)
Architecture reference: https://github.com/kamelhar/openhuman-oci/blob/main/docs/OPENHUMAN-ON-OCI.md
Two recorded sessions: a platform tour (edge checks, headless browser drive through Playwright MCP, research turn, memory read-back) and a clinical research scenario: 4,300 public Alzheimer's trials from ClinicalTrials.gov in the database, three researcher turns in parallel on the live web, a synthesis, a regulator-only deep dive, and the brief recalled from memory.
What runs on the VM
openhuman-corefrom the published aarch64 release tarball on Ubuntu 24.04 (the tarball needs glibc 2.39), plus SearXNG for search, Microsoft's Playwright MCP for headless browsing, and Ollama withbge-m3for embeddings. A small renderer pulls every secret from OCI Vault with the instance principal and pushes model settings, MCP registrations and a custom researcher agent through the core's own RPC, so nothing secret is baked into the image or cloud-init.What I learned about the core along the way, now filed
read_onlycompose root left~/OpenHuman/projectsuncreatable.encrypted_filekeyring master key via env or file.tool_call_idat 64 characters; the harness mints 69.subagents.allowlistoverride never reachesspawn_async_subagent.max_iterationssnapshot that was failing every outside contributor'srust-covlane.servemode, caller-owned local runtimes are not.Two things I would love maintainer input on: an OCI Generative AI provider preset in
tinyinference(it is OpenAI-compatible with a regional endpoint and a bearer API key; embeddings and rerank are native-API only), and whether alocal-openaiprofile could opt into native tool calling for hosted endpoints. Happy to open either as an issue first if that is the preferred order.Thanks for merging the first three so quickly.
All reactions