mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 11:33:14 +00:00
Captures the stock-LangGraph deployment of this fork at Sea Haven: - systemd/open-swe.service: langgraph dev (:2024) + store seed ExecStartPost - seed_store.sh: re-seeds team_settings + user_mappings (in-memory store resets on restart); env-parameterized, no secrets - nginx/openswe.conf: dashboard SPA + scoped /dashboard/api proxy (security boundary; agent API not exposed) - aegra/: deferred self-hosted-runtime alternative (not active on stock) - DEPLOYMENT.md: full runbook (models, build, ingress, OAuth callback) Secrets and internal infra identifiers are intentionally excluded (public fork); real values live in private IT docs.
32 lines
1.1 KiB
Text
32 lines
1.1 KiB
Text
# Open SWE dashboard frontend (TanStack Start SPA) + scoped API proxy.
|
|
# nginx is the security boundary: ONLY /dashboard/api/* reaches the backend;
|
|
# the unauthenticated LangGraph agent API (/threads,/runs,/assistants,/store) is NOT proxied.
|
|
server {
|
|
listen 80 default_server;
|
|
listen [::]:80 default_server;
|
|
server_name openswe.seahavenind.com;
|
|
|
|
root /var/www/openswe;
|
|
index _shell.html;
|
|
|
|
# ALB health check
|
|
location = /healthz { default_type text/plain; return 200 "ok\n"; }
|
|
|
|
# Dashboard API + OAuth callback -> backend webapp on :2024 (the ONLY proxied path)
|
|
location /dashboard/api/ {
|
|
proxy_pass http://127.0.0.1:2024;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
proxy_read_timeout 300s;
|
|
}
|
|
|
|
# Static assets + SPA shell fallback (client-side routing)
|
|
location / {
|
|
try_files $uri $uri/ /_shell.html;
|
|
}
|
|
}
|