Upgrading to v0.5.9
This is a checklist for moving a server from v0.5.6 or older to v0.5.9. Work through each section that matches how you run OpenJevX. Every setting is also listed on Configuration.
1. Decisions need an API key off loopback
Section titled “1. Decisions need an API key off loopback”- The key is
api_keyinopenjevx.json, or theOPENJEVX_API_KEYenvironment variable. 1 - It guards
POST /v1/systemone, sent asAuthorization: Bearer <key>, and must be 16+ characters. 2 - An API key shorter than 16 characters is an error that asks you to use at least 16. 3 4
- The key is on whenever
listenis not loopback; it is off on127.0.0.1,::1andlocalhostunless you set one. 2 - The environment wins over
openjevx.json. 5 - Left unset on a public listen address, the server generates one into
openjevx.api-keybesideopenjevx.json. 2 - A request without the right key gets 401 with the body
{"error":"missing or wrong API key"}. 6 allow_no_api_key(OPENJEVX_ALLOW_NO_API_KEY=1) turns the key off even when public, e.g. behind a proxy that checks it. 7
Clients send the key as Authorization: Bearer <key>, the header jevx and the jev-cloud gate send. 8
curl -H "Authorization: Bearer $(cat openjevx.api-key)" http://<host>:21118/v1/systemone -d @body.jsonWith an API key (any server not on loopback), let jevx read it from the environment. 9
jevx profile add openjevx http://<host>:21118/v1/systemone --model openjevx --header 'Authorization: Bearer $OPENJEVX_API_KEY'Request and response shapes are on the API page.
2. The dashboard password
Section titled “2. The dashboard password”- There is no default password. 10
- The password guards the dashboard
/,/stats,/metricsand/recipeswith HTTP Basic, and any user name works. 11 - Set
"password"inopenjevx.jsonorOPENJEVX_PASSWORD; unset, the server generates one on its first start and keeps it inopenjevx.password. 12 - The npx install keeps it in
~/.local/share/openjevx/. 13 adminadminshipped inopenjevx.jsonup to v0.5.6; it is public, so the server counts it as no password. 14- An old
adminadminis ignored and replaced by a generated password. 15 - A generated value is shown once, and only on a terminal. 16
- Logs (Docker, systemd, ECS) get the file and a fingerprint, never the secret. 17
3. The npx installer keeps your config
Section titled “3. The npx installer keeps your config”- Archives up to v0.5.6 carried an
openjevx.json(with the password “adminadmin”) that replaced the user’s on every upgrade. 18 - Releases no longer ship one; the user’s file is still put back after unpacking, whatever the archive holds. 18
- On install and upgrade the user’s values always win; only keys the user does not have yet are added. 19
- The keys it adds are
listen(127.0.0.1:21118) anddevice(auto). 20 - Release archives carry no
openjevx.json, so unpacking a new release over an old one never replaces yours. 21
4. Docker
Section titled “4. Docker”- The image refuses to start without
OPENJEVX_PASSWORDandOPENJEVX_API_KEY, or your ownopenjevx.jsonmounted at/data/openjevx.json. 22 - The Docker image refuses to start without
OPENJEVX_PASSWORD(12+ characters) andOPENJEVX_API_KEY(16+). 23 - The image runs as uid 10001, not root, and
/datais its writable working folder. 24 /dataholds the generatedopenjevx.json, any generated credential files and the model cache;/appis read-only to it. 25- Make a key with
openssl rand -hex 24. 26
docker run -d -p 127.0.0.1:21118:21118 \ -e OPENJEVX_PASSWORD=YOUR_PASSWORD -e OPENJEVX_API_KEY=YOUR_API_KEY \ ghcr.io/deemwar-products/openjevx:v0.5.9Marketplace image on 0.5.6
Section titled “Marketplace image on 0.5.6”- The jev-cloud image pins
OPENJEVX_TAG=v0.5.6. 27 - The container product is built in the jev-cloud repo, not from the openjevx Dockerfile. 28
- Its gate checks
Authorization: Bearer <JEV_API_KEY>and runs openjevx on127.0.0.1:21119, where openjevx’s own key is off. 29 - Because the gate runs openjevx on 127.0.0.1:21119 and checks the key in front, the API-key change needs no action; verify the loopback bind in the startup log. 30
5. Clear the jevx answer cache
Section titled “5. Clear the jevx answer cache”- jevx caches answers by model name, so run
jevx cache clearafter upgrading, or give the profile a versioned model name such as--model openjevx-v0.5.2. 31 - A stored answer is used for
cache_ttl_days(default 7). 32
6. Platforms
Section titled “6. Platforms”- Server archives are released for macOS on Apple Silicon, Linux amd64 and arm64 (glibc 2.28+), and Windows amd64. 33
- The linux-arm64 archive is packed with the aarch64 ONNX Runtime library. 34
- On an Intel Mac the installer stops with an error: ONNX Runtime 1.29 has no Intel macOS build, so OpenJevX runs on Apple Silicon only (or use Docker). 35
If a step fails, see Troubleshooting.
Sources
Section titled “Sources”Footnotes
Section titled “Footnotes”-
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL29–31 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL33 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL75–78 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL36 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL181–186 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL33 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL22 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL182 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL202 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL32 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL202–204 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL203–204 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL34–35 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL42–43 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL38–39 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
cmd/openjevx/auth.goL28–29 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
bin/config.jsL1 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
bin/config.jsL2 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL40–41 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL169–170 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
docs/DEPLOY.mdL21–22 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL170–171 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
DockerfileL21–22 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL169–171 ↩ -
jev-cloud @ origin/main (10a744c) ·
image/DockerfileL4 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
docs/DEPLOY.mdL85 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
docs/DEPLOY.mdL86–87 ↩ -
jev-cloud @ origin/main (10a744c) ·
docs/upgrade-openjevx-0.5.7-plan.mdL10 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
README.mdL188 ↩ -
jevx @ 4a4722d (4a4722d) ·
site/src/content/docs/reference/privacy.mdL34 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
bin/platform.jsL1–2 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
scripts/package.shL43 ↩ -
openjevx @ v0.5.9 (ee2a1f4) ·
bin/platform.jsL8–11 ↩