docs(agent-team): install/run notes for the read-only status dashboard
This commit is contained in:
parent
de215dfb64
commit
bd5bec2f9a
2 changed files with 58 additions and 0 deletions
|
|
@ -163,6 +163,46 @@ bearer auth) only if you want the `/delegate` Claude Code hook or the
|
|||
The `/docs` + `/openapi` routes are disabled and it binds loopback by design (do
|
||||
not change to `0.0.0.0`). See the deploy script's step 6 for how to start it.
|
||||
|
||||
### Status dashboard (optional, LAN/VPN-only, READ-ONLY)
|
||||
|
||||
`agent_team/status_page.py` serves a tiny self-refreshing HTML page showing the
|
||||
coordinator queue: each task's short `thread_id`, description, current phase and
|
||||
status; which tasks have an **open** pending question (blocked on the human gate)
|
||||
vs. progressing; active/parked counts; and recent `budget_ledger` spend. It opens
|
||||
the SQLite ledger **READ-ONLY** (`mode=ro`) and has **no mutating endpoints and
|
||||
no auth**.
|
||||
|
||||
It is a **separate, optional process** — `agent-team-status.service` (mirrors the
|
||||
coordinator unit's hardening; `User=adam`, `EnvironmentFile=-/home/adam/secrev.env`,
|
||||
venv-python ExecStart, `Restart=on-failure`). Unlike the coordinator it needs **no**
|
||||
`ReadWritePaths` carve-out (it only reads). It can run side-by-side with the
|
||||
coordinator (RO SQLite opens coexist with the writer).
|
||||
|
||||
```bash
|
||||
# install the unit
|
||||
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
|
||||
sudo systemctl daemon-reload
|
||||
sudo systemctl enable --now agent-team-status.service
|
||||
systemctl status agent-team-status.service
|
||||
journalctl -u agent-team-status.service -e -f
|
||||
|
||||
# or run it ad hoc from the venv
|
||||
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
|
||||
python3 -c "from agent_team.status_page import serve; serve()"
|
||||
```
|
||||
|
||||
Then browse `http://10.10.60.120:8770/` from the LAN/VPN.
|
||||
|
||||
**Config (env):** `AGENT_TEAM_DB` (default `state/agent_team.sqlite`),
|
||||
`AGENT_TEAM_STATUS_HOST` (default `0.0.0.0`), `AGENT_TEAM_STATUS_PORT` (default
|
||||
`8770`).
|
||||
|
||||
**Posture:** the sh-secrev VM (`10.10.60.120`, VLAN 60) has no public NIC and sits
|
||||
behind the UniFi firewall, so `0.0.0.0` reaches the **LAN/VPN only**. Task
|
||||
descriptions may be sensitive and the page is unauthenticated — **keep it
|
||||
LAN/VPN-only, never expose it to the public internet.** A missing/locked DB renders
|
||||
a friendly "no data" page rather than crashing.
|
||||
|
||||
## 5. P1 live exit-criteria demo (§3.3.1)
|
||||
|
||||
Demonstrate all four once the service is live. Map each to the operator commands
|
||||
|
|
|
|||
|
|
@ -95,6 +95,24 @@ Then set AGENT_TEAM_API_TOKEN + AGENT_TEAM_API_URL in the Mac Claude Code env
|
|||
to enable the /delegate hook (sea-haven-claude-plugin).
|
||||
NOTE
|
||||
|
||||
say "6b. (OPTIONAL) READ-ONLY status dashboard — LAN/VPN-only"
|
||||
cat <<'NOTE'
|
||||
agent_team/status_page.py serves a self-refreshing HTML view of the queue
|
||||
(tasks/phases, who is waiting on the human gate, active/parked counts, recent
|
||||
budget spend). It opens the ledger READ-ONLY (mode=ro), has no mutating
|
||||
endpoints and NO auth. Separate, optional process from the coordinator.
|
||||
- install the unit (mirrors the coordinator hardening; reads only, no RW carve-out):
|
||||
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
|
||||
sudo systemctl daemon-reload && sudo systemctl enable --now agent-team-status.service
|
||||
- or run ad hoc:
|
||||
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
|
||||
python3 -c "from agent_team.status_page import serve; serve()"
|
||||
- then browse http://10.10.60.120:8770/ from the LAN/VPN.
|
||||
POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on AGENT_TEAM_STATUS_PORT
|
||||
(default 8770). The sh-secrev VM has no public NIC + sits behind the UniFi
|
||||
firewall -> LAN/VPN only. Task descriptions may be sensitive; never expose public.
|
||||
NOTE
|
||||
|
||||
say "7. SMOKE TESTS (manual)"
|
||||
cat <<'SMOKE'
|
||||
a) Coordinator up: systemctl is-active agent-team-coordinator.service -> active
|
||||
|
|
|
|||
Reference in a new issue