From 97a4befd2495afcea609c0eb7faf6d552dfa613d Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 23 Jun 2026 14:13:58 -0400 Subject: [PATCH] feat(agent-team): systemd unit for the read-only status dashboard --- agent-team/systemd/agent-team-status.service | 53 ++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 agent-team/systemd/agent-team-status.service diff --git a/agent-team/systemd/agent-team-status.service b/agent-team/systemd/agent-team-status.service new file mode 100644 index 0000000..a131972 --- /dev/null +++ b/agent-team/systemd/agent-team-status.service @@ -0,0 +1,53 @@ +# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam). +# +# A tiny stdlib http.server that renders the agent-team coordinator's queue +# (tasks/phases, who is waiting on the human gate, active/parked counts, recent +# budget spend) as a 10s-auto-refresh HTML page. It opens the SQLite ledger +# READ-ONLY (mode=ro) and never writes; it has no mutating endpoints and no auth. +# +# NETWORK POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on port +# AGENT_TEAM_STATUS_PORT (default 8770). The sh-secrev VM (10.10.60.120, VLAN 60) +# has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 reaches the +# LAN/VPN only. Task descriptions may be sensitive -> keep this LAN/VPN-only, +# never expose to the public internet. +# +# Install (on the VM, as root): +# sudo cp agent-team-status.service /etc/systemd/system/ +# sudo systemctl daemon-reload +# sudo systemctl enable --now agent-team-status.service +# systemctl status agent-team-status.service +# journalctl -u agent-team-status.service -e -f +# +# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The +# coordinator owns the ledger (read/write); this unit only reads it. They can run +# side by side: SQLite WAL/RO opens coexist with the coordinator's writer. + +[Unit] +Description=Sea Haven agent-team LAN-only read-only status dashboard +After=network-online.target +Wants=network-online.target + +[Service] +Type=simple +User=adam +WorkingDirectory=/home/adam/orchestrator/agent-team +# Optional ('-'): the dashboard reads no secrets, but loading the same env file +# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in +# one place if set there. +EnvironmentFile=-/home/adam/secrev.env +# Use the agent-team venv interpreter (where langgraph + the checkpoint dep are +# installed), NOT the bare system python3 that systemd's PATH would resolve. +ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.status_page import serve; serve()" +Restart=on-failure +RestartSec=5 +# Hardening - mirrors agent-team-coordinator.service, but this unit only READS +# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be +# read-only and ProtectSystem full; the RO sqlite open lives under read-only +# home, which is sufficient for mode=ro). +NoNewPrivileges=true +ProtectSystem=full +ProtectHome=read-only +Nice=10 + +[Install] +WantedBy=multi-user.target