docs(agent-team): install/run notes for the read-only status dashboard

This commit is contained in:
Adam Moussa 2026-06-23 14:16:07 -04:00
parent de215dfb64
commit bd5bec2f9a
2 changed files with 58 additions and 0 deletions

View file

@ -163,6 +163,46 @@ bearer auth) only if you want the `/delegate` Claude Code hook or the
The `/docs` + `/openapi` routes are disabled and it binds loopback by design (do
not change to `0.0.0.0`). See the deploy script's step 6 for how to start it.
### Status dashboard (optional, LAN/VPN-only, READ-ONLY)
`agent_team/status_page.py` serves a tiny self-refreshing HTML page showing the
coordinator queue: each task's short `thread_id`, description, current phase and
status; which tasks have an **open** pending question (blocked on the human gate)
vs. progressing; active/parked counts; and recent `budget_ledger` spend. It opens
the SQLite ledger **READ-ONLY** (`mode=ro`) and has **no mutating endpoints and
no auth**.
It is a **separate, optional process** — `agent-team-status.service` (mirrors the
coordinator unit's hardening; `User=adam`, `EnvironmentFile=-/home/adam/secrev.env`,
venv-python ExecStart, `Restart=on-failure`). Unlike the coordinator it needs **no**
`ReadWritePaths` carve-out (it only reads). It can run side-by-side with the
coordinator (RO SQLite opens coexist with the writer).
```bash
# install the unit
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now agent-team-status.service
systemctl status agent-team-status.service
journalctl -u agent-team-status.service -e -f
# or run it ad hoc from the venv
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
python3 -c "from agent_team.status_page import serve; serve()"
```
Then browse `http://10.10.60.120:8770/` from the LAN/VPN.
**Config (env):** `AGENT_TEAM_DB` (default `state/agent_team.sqlite`),
`AGENT_TEAM_STATUS_HOST` (default `0.0.0.0`), `AGENT_TEAM_STATUS_PORT` (default
`8770`).
**Posture:** the sh-secrev VM (`10.10.60.120`, VLAN 60) has no public NIC and sits
behind the UniFi firewall, so `0.0.0.0` reaches the **LAN/VPN only**. Task
descriptions may be sensitive and the page is unauthenticated — **keep it
LAN/VPN-only, never expose it to the public internet.** A missing/locked DB renders
a friendly "no data" page rather than crashing.
## 5. P1 live exit-criteria demo (§3.3.1)
Demonstrate all four once the service is live. Map each to the operator commands

View file

@ -95,6 +95,24 @@ Then set AGENT_TEAM_API_TOKEN + AGENT_TEAM_API_URL in the Mac Claude Code env
to enable the /delegate hook (sea-haven-claude-plugin).
NOTE
say "6b. (OPTIONAL) READ-ONLY status dashboard — LAN/VPN-only"
cat <<'NOTE'
agent_team/status_page.py serves a self-refreshing HTML view of the queue
(tasks/phases, who is waiting on the human gate, active/parked counts, recent
budget spend). It opens the ledger READ-ONLY (mode=ro), has no mutating
endpoints and NO auth. Separate, optional process from the coordinator.
- install the unit (mirrors the coordinator hardening; reads only, no RW carve-out):
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now agent-team-status.service
- or run ad hoc:
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
python3 -c "from agent_team.status_page import serve; serve()"
- then browse http://10.10.60.120:8770/ from the LAN/VPN.
POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on AGENT_TEAM_STATUS_PORT
(default 8770). The sh-secrev VM has no public NIC + sits behind the UniFi
firewall -> LAN/VPN only. Task descriptions may be sensitive; never expose public.
NOTE
say "7. SMOKE TESTS (manual)"
cat <<'SMOKE'
a) Coordinator up: systemctl is-active agent-team-coordinator.service -> active