From bd5bec2f9a5615e97a41dde5dad9a7a5a97f4583 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Tue, 23 Jun 2026 14:16:07 -0400 Subject: [PATCH] docs(agent-team): install/run notes for the read-only status dashboard --- agent-team/DEPLOY-R720.md | 40 ++++++++++++++++++++ agent-team/scripts/deploy-r720-ws-rollout.sh | 18 +++++++++ 2 files changed, 58 insertions(+) diff --git a/agent-team/DEPLOY-R720.md b/agent-team/DEPLOY-R720.md index 71f9a8f..4cf2128 100644 --- a/agent-team/DEPLOY-R720.md +++ b/agent-team/DEPLOY-R720.md @@ -163,6 +163,46 @@ bearer auth) only if you want the `/delegate` Claude Code hook or the The `/docs` + `/openapi` routes are disabled and it binds loopback by design (do not change to `0.0.0.0`). See the deploy script's step 6 for how to start it. +### Status dashboard (optional, LAN/VPN-only, READ-ONLY) + +`agent_team/status_page.py` serves a tiny self-refreshing HTML page showing the +coordinator queue: each task's short `thread_id`, description, current phase and +status; which tasks have an **open** pending question (blocked on the human gate) +vs. progressing; active/parked counts; and recent `budget_ledger` spend. It opens +the SQLite ledger **READ-ONLY** (`mode=ro`) and has **no mutating endpoints and +no auth**. + +It is a **separate, optional process** โ€” `agent-team-status.service` (mirrors the +coordinator unit's hardening; `User=adam`, `EnvironmentFile=-/home/adam/secrev.env`, +venv-python ExecStart, `Restart=on-failure`). Unlike the coordinator it needs **no** +`ReadWritePaths` carve-out (it only reads). It can run side-by-side with the +coordinator (RO SQLite opens coexist with the writer). + +```bash +# install the unit +sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/ +sudo systemctl daemon-reload +sudo systemctl enable --now agent-team-status.service +systemctl status agent-team-status.service +journalctl -u agent-team-status.service -e -f + +# or run it ad hoc from the venv +cd ~/orchestrator/agent-team && . .venv/bin/activate && \ + python3 -c "from agent_team.status_page import serve; serve()" +``` + +Then browse `http://10.10.60.120:8770/` from the LAN/VPN. + +**Config (env):** `AGENT_TEAM_DB` (default `state/agent_team.sqlite`), +`AGENT_TEAM_STATUS_HOST` (default `0.0.0.0`), `AGENT_TEAM_STATUS_PORT` (default +`8770`). + +**Posture:** the sh-secrev VM (`10.10.60.120`, VLAN 60) has no public NIC and sits +behind the UniFi firewall, so `0.0.0.0` reaches the **LAN/VPN only**. Task +descriptions may be sensitive and the page is unauthenticated โ€” **keep it +LAN/VPN-only, never expose it to the public internet.** A missing/locked DB renders +a friendly "no data" page rather than crashing. + ## 5. P1 live exit-criteria demo (ยง3.3.1) Demonstrate all four once the service is live. Map each to the operator commands diff --git a/agent-team/scripts/deploy-r720-ws-rollout.sh b/agent-team/scripts/deploy-r720-ws-rollout.sh index aab77a6..2b1858c 100755 --- a/agent-team/scripts/deploy-r720-ws-rollout.sh +++ b/agent-team/scripts/deploy-r720-ws-rollout.sh @@ -95,6 +95,24 @@ Then set AGENT_TEAM_API_TOKEN + AGENT_TEAM_API_URL in the Mac Claude Code env to enable the /delegate hook (sea-haven-claude-plugin). NOTE +say "6b. (OPTIONAL) READ-ONLY status dashboard โ€” LAN/VPN-only" +cat <<'NOTE' +agent_team/status_page.py serves a self-refreshing HTML view of the queue +(tasks/phases, who is waiting on the human gate, active/parked counts, recent +budget spend). It opens the ledger READ-ONLY (mode=ro), has no mutating +endpoints and NO auth. Separate, optional process from the coordinator. + - install the unit (mirrors the coordinator hardening; reads only, no RW carve-out): + sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/ + sudo systemctl daemon-reload && sudo systemctl enable --now agent-team-status.service + - or run ad hoc: + cd ~/orchestrator/agent-team && . .venv/bin/activate && \ + python3 -c "from agent_team.status_page import serve; serve()" + - then browse http://10.10.60.120:8770/ from the LAN/VPN. +POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on AGENT_TEAM_STATUS_PORT +(default 8770). The sh-secrev VM has no public NIC + sits behind the UniFi +firewall -> LAN/VPN only. Task descriptions may be sensitive; never expose public. +NOTE + say "7. SMOKE TESTS (manual)" cat <<'SMOKE' a) Coordinator up: systemctl is-active agent-team-coordinator.service -> active