docs(agent-team): install/run notes for the read-only status dashboard

This commit is contained in:
Adam Moussa 2026-06-23 14:16:07 -04:00
parent de215dfb64
commit bd5bec2f9a
2 changed files with 58 additions and 0 deletions

View file

@ -163,6 +163,46 @@ bearer auth) only if you want the `/delegate` Claude Code hook or the
The `/docs` + `/openapi` routes are disabled and it binds loopback by design (do The `/docs` + `/openapi` routes are disabled and it binds loopback by design (do
not change to `0.0.0.0`). See the deploy script's step 6 for how to start it. not change to `0.0.0.0`). See the deploy script's step 6 for how to start it.
### Status dashboard (optional, LAN/VPN-only, READ-ONLY)
`agent_team/status_page.py` serves a tiny self-refreshing HTML page showing the
coordinator queue: each task's short `thread_id`, description, current phase and
status; which tasks have an **open** pending question (blocked on the human gate)
vs. progressing; active/parked counts; and recent `budget_ledger` spend. It opens
the SQLite ledger **READ-ONLY** (`mode=ro`) and has **no mutating endpoints and
no auth**.
It is a **separate, optional process** — `agent-team-status.service` (mirrors the
coordinator unit's hardening; `User=adam`, `EnvironmentFile=-/home/adam/secrev.env`,
venv-python ExecStart, `Restart=on-failure`). Unlike the coordinator it needs **no**
`ReadWritePaths` carve-out (it only reads). It can run side-by-side with the
coordinator (RO SQLite opens coexist with the writer).
```bash
# install the unit
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable --now agent-team-status.service
systemctl status agent-team-status.service
journalctl -u agent-team-status.service -e -f
# or run it ad hoc from the venv
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
python3 -c "from agent_team.status_page import serve; serve()"
```
Then browse `http://10.10.60.120:8770/` from the LAN/VPN.
**Config (env):** `AGENT_TEAM_DB` (default `state/agent_team.sqlite`),
`AGENT_TEAM_STATUS_HOST` (default `0.0.0.0`), `AGENT_TEAM_STATUS_PORT` (default
`8770`).
**Posture:** the sh-secrev VM (`10.10.60.120`, VLAN 60) has no public NIC and sits
behind the UniFi firewall, so `0.0.0.0` reaches the **LAN/VPN only**. Task
descriptions may be sensitive and the page is unauthenticated — **keep it
LAN/VPN-only, never expose it to the public internet.** A missing/locked DB renders
a friendly "no data" page rather than crashing.
## 5. P1 live exit-criteria demo (§3.3.1) ## 5. P1 live exit-criteria demo (§3.3.1)
Demonstrate all four once the service is live. Map each to the operator commands Demonstrate all four once the service is live. Map each to the operator commands

View file

@ -95,6 +95,24 @@ Then set AGENT_TEAM_API_TOKEN + AGENT_TEAM_API_URL in the Mac Claude Code env
to enable the /delegate hook (sea-haven-claude-plugin). to enable the /delegate hook (sea-haven-claude-plugin).
NOTE NOTE
say "6b. (OPTIONAL) READ-ONLY status dashboard — LAN/VPN-only"
cat <<'NOTE'
agent_team/status_page.py serves a self-refreshing HTML view of the queue
(tasks/phases, who is waiting on the human gate, active/parked counts, recent
budget spend). It opens the ledger READ-ONLY (mode=ro), has no mutating
endpoints and NO auth. Separate, optional process from the coordinator.
- install the unit (mirrors the coordinator hardening; reads only, no RW carve-out):
sudo cp ~/orchestrator/agent-team/systemd/agent-team-status.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now agent-team-status.service
- or run ad hoc:
cd ~/orchestrator/agent-team && . .venv/bin/activate && \
python3 -c "from agent_team.status_page import serve; serve()"
- then browse http://10.10.60.120:8770/ from the LAN/VPN.
POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on AGENT_TEAM_STATUS_PORT
(default 8770). The sh-secrev VM has no public NIC + sits behind the UniFi
firewall -> LAN/VPN only. Task descriptions may be sensitive; never expose public.
NOTE
say "7. SMOKE TESTS (manual)" say "7. SMOKE TESTS (manual)"
cat <<'SMOKE' cat <<'SMOKE'
a) Coordinator up: systemctl is-active agent-team-coordinator.service -> active a) Coordinator up: systemctl is-active agent-team-coordinator.service -> active