mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
PR#2 of the AWS migration. deploy/ami/: Packer template (Ubuntu 24.04 arm64, uv+py3.12, nginx, awscli v2, CW agent; no swapfile), provisioning-only user-data (userDataCausesReplacement rationale), systemd unit + nginx + CW templates. Incorporates T5 /sh-security-review fixes: langgraph binds 127.0.0.1 (not 0.0.0.0); nginx is the sole ingress proxying only /dashboard/api/ + /webhooks/; ExecStartPre runs fetch-config as root (+) and passes the env arg; the app runs as the unprivileged openswe user reading an openswe-owned 0600 .env. packer validate clean.
54 lines
2.3 KiB
Desktop File
54 lines
2.3 KiB
Desktop File
# Open SWE — stock LangGraph dev server (3+ graphs + FastAPI webapp, :2024).
|
|
# TEMPLATE: tokens (@@...@@) are rendered at first boot by user-data.sh.
|
|
# In-memory runtime (--no-reload) + ExecStartPost reseed; no Aegra/Postgres.
|
|
#
|
|
# Boot contract:
|
|
# ExecStartPre = fetch-config.sh <env> -> runs as root (`+`) ONLY to materialize
|
|
# the SERVICE-USER-owned tmpfs .env (@@ENV_FILE@@) from Secrets
|
|
# Manager + SSM and chown it to @@SERVICE_USER@@, fail-fast (the
|
|
# unit does NOT start if config can't be fetched).
|
|
# ExecStart = langgraph dev (as @@SERVICE_USER@@, bound to 127.0.0.1 — nginx
|
|
# is the sole ingress; never binds 0.0.0.0).
|
|
# ExecStartPost = seed_store.sh <env> -> reseeds team_settings + user_mappings
|
|
# that the in-memory store loses on every restart.
|
|
[Unit]
|
|
Description=Open SWE stock LangGraph dev server (graphs + webapp, :@@PORT@@)
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
RequiresMountsFor=/run/open-swe
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=@@SERVICE_USER@@
|
|
Group=@@SERVICE_USER@@
|
|
WorkingDirectory=@@APP_DIR@@
|
|
|
|
# No EnvironmentFile: the secret-bearing app .env (@@ENV_FILE@@) is loaded by
|
|
# langgraph/dotenv (so the multiline GitHub App PEM never hits systemd's env
|
|
# parser), and seed_store.sh reads the same .env directly (without sourcing it).
|
|
#
|
|
# ExecStartPre runs as root (`+`) so it can chown the tmpfs .env to the service
|
|
# user; the env arg (@@OPENSWE_ENV@@) selects the SSM/Secrets prefix (T5 BOOT-01).
|
|
ExecStartPre=+@@FETCH_CONFIG@@ @@OPENSWE_ENV@@
|
|
# Bind 127.0.0.1 only — nginx proxies dashboard + webhooks; :@@PORT@@ is never
|
|
# directly network-reachable (T5 OSWE-IAC-03).
|
|
ExecStart=@@VENV@@/bin/langgraph dev --host 127.0.0.1 --port @@PORT@@ --no-browser --no-reload
|
|
ExecStartPost=@@SEED_STORE@@ @@OPENSWE_ENV@@
|
|
|
|
# App logs to a file CloudWatch collects (30-day retention set in the CW config).
|
|
StandardOutput=append:/var/log/open-swe/app.log
|
|
StandardError=append:/var/log/open-swe/app.log
|
|
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
TimeoutStartSec=180
|
|
|
|
# Hardening — the box holds no durable state of its own.
|
|
NoNewPrivileges=true
|
|
ProtectSystem=full
|
|
ProtectHome=true
|
|
PrivateTmp=true
|
|
ReadWritePaths=/var/log/open-swe /var/www/open-swe /run/open-swe @@APP_DIR@@
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|