feat(agent-team): systemd unit for the read-only status dashboard
This commit is contained in:
parent
3ddd9ca08c
commit
97a4befd24
1 changed files with 53 additions and 0 deletions
53
agent-team/systemd/agent-team-status.service
Normal file
53
agent-team/systemd/agent-team-status.service
Normal file
|
|
@ -0,0 +1,53 @@
|
|||
# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam).
|
||||
#
|
||||
# A tiny stdlib http.server that renders the agent-team coordinator's queue
|
||||
# (tasks/phases, who is waiting on the human gate, active/parked counts, recent
|
||||
# budget spend) as a 10s-auto-refresh HTML page. It opens the SQLite ledger
|
||||
# READ-ONLY (mode=ro) and never writes; it has no mutating endpoints and no auth.
|
||||
#
|
||||
# NETWORK POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on port
|
||||
# AGENT_TEAM_STATUS_PORT (default 8770). The sh-secrev VM (10.10.60.120, VLAN 60)
|
||||
# has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 reaches the
|
||||
# LAN/VPN only. Task descriptions may be sensitive -> keep this LAN/VPN-only,
|
||||
# never expose to the public internet.
|
||||
#
|
||||
# Install (on the VM, as root):
|
||||
# sudo cp agent-team-status.service /etc/systemd/system/
|
||||
# sudo systemctl daemon-reload
|
||||
# sudo systemctl enable --now agent-team-status.service
|
||||
# systemctl status agent-team-status.service
|
||||
# journalctl -u agent-team-status.service -e -f
|
||||
#
|
||||
# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The
|
||||
# coordinator owns the ledger (read/write); this unit only reads it. They can run
|
||||
# side by side: SQLite WAL/RO opens coexist with the coordinator's writer.
|
||||
|
||||
[Unit]
|
||||
Description=Sea Haven agent-team LAN-only read-only status dashboard
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=adam
|
||||
WorkingDirectory=/home/adam/orchestrator/agent-team
|
||||
# Optional ('-'): the dashboard reads no secrets, but loading the same env file
|
||||
# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in
|
||||
# one place if set there.
|
||||
EnvironmentFile=-/home/adam/secrev.env
|
||||
# Use the agent-team venv interpreter (where langgraph + the checkpoint dep are
|
||||
# installed), NOT the bare system python3 that systemd's PATH would resolve.
|
||||
ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.status_page import serve; serve()"
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
# Hardening - mirrors agent-team-coordinator.service, but this unit only READS
|
||||
# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be
|
||||
# read-only and ProtectSystem full; the RO sqlite open lives under read-only
|
||||
# home, which is sufficient for mode=ro).
|
||||
NoNewPrivileges=true
|
||||
ProtectSystem=full
|
||||
ProtectHome=read-only
|
||||
Nice=10
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in a new issue