mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 06:53:14 +00:00
Some checks are pending
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Prod went live 2026-06-29 on self-hosted AWS EC2 behind the shared seahaven-com ALB, superseding the on-prem VM model the runbook described. - Rewrite deploy/seahaven/DEPLOYMENT.md as the canonical end-to-end runbook: infra CD (CDK stacks + OIDC roles + prod approval gate), config seeding (put-config.sh, the 13 boot-required prod vars, fetch-config fail-fast), app artifact deploy (S3 + SSM roll + is-active gate), promotion/rollback, live prod facts, and a RETAIN secret-shell troubleshooting entry that cross-references infra/README.md. - Correct retired *.seahavenind.com hosts to *.seahaven.com throughout and document the live GitHub/Slack/Linear webhook + OAuth endpoints. - Add a concise Deployment section to README pointing at the runbook. - Fix the stale host in the retired on-prem nginx/openswe.conf and mark it superseded by the AMI template.
36 lines
1.4 KiB
Text
36 lines
1.4 KiB
Text
# Open SWE dashboard frontend (TanStack Start SPA) + scoped API proxy.
|
|
# RETIRED on-prem VM variant — kept for on-prem-contrast reference only. The LIVE
|
|
# AWS nginx site is the AMI template deploy/ami/templates/open-swe.nginx.conf
|
|
# (rendered from an @@SERVER_NAME@@ token at first boot). See DEPLOYMENT.md.
|
|
#
|
|
# nginx is the security boundary: ONLY /dashboard/api/* reaches the backend;
|
|
# the unauthenticated LangGraph agent API (/threads,/runs,/assistants,/store) is NOT proxied.
|
|
server {
|
|
listen 80 default_server;
|
|
listen [::]:80 default_server;
|
|
server_name openswe.seahaven.com;
|
|
|
|
root /var/www/openswe;
|
|
index _shell.html;
|
|
|
|
# ALB health check
|
|
location = /healthz { default_type text/plain; return 200 "ok\n"; }
|
|
|
|
# Dashboard API + OAuth callback -> backend webapp on :2024 (the ONLY proxied path)
|
|
location /dashboard/api/ {
|
|
proxy_pass http://127.0.0.1:2024;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
proxy_read_timeout 300s;
|
|
}
|
|
|
|
# Static assets + SPA shell fallback (client-side routing)
|
|
location / {
|
|
try_files $uri $uri/ /_shell.html;
|
|
}
|
|
}
|