Skip to content

aigw: add one-command install script - #2617

Open
missBerg wants to merge 6 commits into
theagentrouter:mainfrom
missBerg:claude/aigw-one-command-installer-nrzk1d
Open

missBerg wants to merge 6 commits into
theagentrouter:mainfrom
missBerg:claude/aigw-one-command-installer-nrzk1d

Conversation

@missBerg

@missBerg missBerg commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Description

This commit adds a one-command installer for the aigw CLI so the standalone
quickstart becomes a single curl | sh:

curl -fsSL https://raw.githubusercontent.com/envoyproxy/ai-gateway/main/install.sh | sh

Today the CLI docs point users at the GitHub releases page to download a
binary by hand, pick the right platform, chmod +x it, and move it onto their
PATH. The install script does that for them and adds checksum verification,
which the manual path never had.

install.sh is POSIX sh with no dependencies beyond curl or wget. It
detects the platform, resolves the latest release (or AIGW_VERSION),
downloads the release binary, verifies its SHA-256, and installs it into
AIGW_INSTALL_DIR (default ~/.local/bin) without ever using sudo.
Checksums come from a checksums.txt asset when the release has one, falling
back to the per-asset digest the GitHub API reports, so verification also
works for every existing release. The script validates the install directory
before downloading, and warns when another aigw earlier on PATH would
shadow the one it just installed. Intel Macs and other unsupported platforms
get a clear error pointing at the Docker image, since Envoy no longer
publishes macOS amd64 builds and aigw downloads Envoy at runtime.

Alongside the script:

  • The release workflow now publishes checksums.txt next to the CLI binaries.
  • netlify.toml redirects https://aigateway.envoyproxy.io/install.sh to the
    raw script on main, giving a stable URL that survives a repository move.
  • The CLI installation docs lead with the one-liner, document the environment
    variables, and add a supported-platforms table.
  • A non-blocking CI job runs shellcheck on the script and smoke-tests it
    against the latest published release on ubuntu-latest and macos-latest,
    so the script cannot silently rot.

AI assistance was used to draft the script and this description. Every
change was reviewed and tested by hand on macOS arm64: default install,
pinned version, replace-existing, unwritable directory, unsupported
platforms, and a nonexistent release tag, followed by aigw run serving
/v1/chat/completions end to end.

Related Issues/PRs (if applicable)

Related PR: #2598

Special notes for reviewers (if applicable)

  • The raw.githubusercontent.com URL and the Netlify redirect only work once
    this lands on main. Until then the script can be tested from a branch URL
    or by running sh install.sh from a checkout.
  • checksums.txt is only produced by releases cut after this merges. For
    older releases, including the current v1.1.0, the script verifies against
    the GitHub API asset digest instead, which I confirmed matches the real
    binary hash.
  • The CI smoke test uses continue-on-error: true on purpose. It depends on
    GitHub Releases being reachable and on the latest release having a binary
    for the runner, so it is advisory rather than a required check.
  • The script does not add a Homebrew formula or a Windows path. Both are out
    of scope here and can follow separately.

missBerg and others added 3 commits September 2, 2026 16:25
Adds install.sh at the repository root so the standalone quickstart is a
single curl | sh. The script is POSIX sh, detects the platform, resolves
the latest release (or AIGW_VERSION), downloads the release binary with a
progress bar, verifies its SHA-256 (checksums.txt, then the GitHub API
asset digest, then a warning for older releases), and installs it to
AIGW_INSTALL_DIR (default ~/.local/bin) without sudo. Intel Macs and
other unsupported platforms get a clear error pointing at the Docker
image. Works with curl or wget.

The release workflow now publishes checksums.txt next to the CLI
binaries, netlify.toml redirects /install.sh on the project domain to
the raw script on main, the CLI installation docs lead with the
one-liner, and a non-blocking CI job smoke-tests the script against the
latest release on ubuntu-latest and macos-latest.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EJhXwqNkhcmPtPjAQrri68
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
…aigw

Check that AIGW_INSTALL_DIR exists and is writable before pulling the ~300 MB
binary so a bad directory fails in milliseconds instead of after the download.

After installing, warn when another aigw earlier on PATH (e.g. a Go build in
~/go/bin) would shadow the freshly installed binary, since "Installed" followed
by "aigw" running the old copy is confusing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
Resolves the conflict in .github/workflows/build_and_test.yaml where the new
test_install_script job and upstream's compute_version job (theagentrouter#2580) were both
inserted after test_e2e_aigw. Both jobs are kept, and the checkout action pin in
test_install_script is aligned with the SHA upstream now uses.

Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
@missBerg
missBerg requested a review from a team as a code owner September 2, 2026 20:32
@codecov-commenter

codecov-commenter commented Sep 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.33%. Comparing base (79770ba) to head (f440504).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2617      +/-   ##
==========================================
- Coverage   86.33%   86.33%   -0.01%     
==========================================
  Files         183      183              
  Lines       24404    24404              
==========================================
- Hits        21070    21068       -2     
- Misses       2160     2161       +1     
- Partials     1174     1175       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@missBerg missBerg added enhancement New feature or request area/operations Deployment, Helm, platform config, k8s limits labels Sep 24, 2026
@missBerg
missBerg requested a review from a team as a code owner October 8, 2026 17:54
@netlify

netlify Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for theagentrouter canceled.

Name Link
🔨 Latest commit beb9d3a
🔍 Latest deploy log https://app.netlify.com/projects/theagentrouter/deploys/6ac8185c9e675a00086c69da

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Resolves conflicts from the Agent Router rebrand and the move of the
repository to theagentrouter/agent-router:

- README: keep upstream's rewritten link list, and put the install
  one-liner into the new Quick start section ahead of `aigw run`.
- CLI installation docs: keep upstream's releases link, keep the
  checksums.txt note, and update the install URLs to the new repository
  and the theagentrouter.ai alias.
- netlify.toml: place the /install.sh rule after upstream's domain-wide
  rule and point it at the new repository.
- install.sh: download from theagentrouter/agent-router directly instead
  of relying on GitHub forwarding the old name.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EJhXwqNkhcmPtPjAQrri68
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
@missBerg
missBerg force-pushed the claude/aigw-one-command-installer-nrzk1d branch from 673832e to 382bd98 Compare October 8, 2026 22:17
Download the binary into the install directory and rename it into place
instead of moving it from /tmp. The rename is atomic on the same
filesystem, so a failure can no longer leave a truncated aigw behind,
and a small tmpfs /tmp is not a problem for a ~300 MB file. mktemp
creates the file as 0600, so set 755 explicitly.

Route INT and TERM through the EXIT trap so Ctrl-C always removes the
partial download and exits with the conventional status, rather than
relying on the download child dying first.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EJhXwqNkhcmPtPjAQrri68
Signed-off-by: Erica Hughberg <erica.sundberg.90@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/operations Deployment, Helm, platform config, k8s limits enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants