# Open SWE — stock LangGraph dev server (3+ graphs + FastAPI webapp, :2024). # TEMPLATE: tokens (@@...@@) are rendered at first boot by user-data.sh. # In-memory runtime (--no-reload) + ExecStartPost reseed; no Aegra/Postgres. # # Boot contract: # ExecStartPre = fetch-config.sh -> runs as root (`+`) ONLY to materialize # the SERVICE-USER-owned tmpfs .env (@@ENV_FILE@@) from Secrets # Manager + SSM and chown it to @@SERVICE_USER@@, fail-fast (the # unit does NOT start if config can't be fetched). # ExecStart = langgraph dev (as @@SERVICE_USER@@, bound to 127.0.0.1 — nginx # is the sole ingress; never binds 0.0.0.0). # ExecStartPost = seed_store.sh -> reseeds team_settings + user_mappings # that the in-memory store loses on every restart. [Unit] Description=Open SWE stock LangGraph dev server (graphs + webapp, :@@PORT@@) After=network-online.target Wants=network-online.target RequiresMountsFor=/run/open-swe [Service] Type=simple User=@@SERVICE_USER@@ Group=@@SERVICE_USER@@ WorkingDirectory=@@APP_DIR@@ # No EnvironmentFile: the secret-bearing app .env (@@ENV_FILE@@) is loaded by # langgraph/dotenv (so the multiline GitHub App PEM never hits systemd's env # parser), and seed_store.sh reads the same .env directly (without sourcing it). # # ExecStartPre runs as root (`+`) so it can chown the tmpfs .env to the service # user; the env arg (@@OPENSWE_ENV@@) selects the SSM/Secrets prefix (T5 BOOT-01). ExecStartPre=+@@FETCH_CONFIG@@ @@OPENSWE_ENV@@ # Bind 127.0.0.1 only — nginx proxies dashboard + webhooks; :@@PORT@@ is never # directly network-reachable (T5 OSWE-IAC-03). ExecStart=@@VENV@@/bin/langgraph dev --host 127.0.0.1 --port @@PORT@@ --no-browser --no-reload ExecStartPost=@@SEED_STORE@@ @@OPENSWE_ENV@@ # App logs to a file CloudWatch collects (30-day retention set in the CW config). StandardOutput=append:/var/log/open-swe/app.log StandardError=append:/var/log/open-swe/app.log Restart=on-failure RestartSec=5 TimeoutStartSec=180 # Hardening — the box holds no durable state of its own. NoNewPrivileges=true ProtectSystem=full ProtectHome=true PrivateTmp=true ReadWritePaths=/var/log/open-swe /var/www/open-swe /run/open-swe @@APP_DIR@@ [Install] WantedBy=multi-user.target