# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam). # # Serves the React/Vite single-page dashboard (web/dist) + its read-only JSON API # (/api/state, /api/topology, /api/task/{id}) via FastAPI/uvicorn. The map renders # the live pipeline (auto-laid from the real LangGraph), and a task can be clicked # to see its history through each node. It opens the SQLite ledger READ-ONLY # (mode=ro) and never writes; it has no mutating endpoints and no auth. # # NETWORK POSTURE: binds 0.0.0.0 on port 8770. The sh-secrev VM (10.10.60.120, # VLAN 60) has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 # reaches the LAN/VPN only. Task descriptions may be sensitive -> keep this # LAN/VPN-only, never expose to the public internet. # # BUILD: the SPA is built on the Mac (`cd web && npm ci && npm run build`) and the # resulting web/dist is rsynced to the VM (the box Node is too old for a Vite 5+ # build). uvicorn serves whatever web/dist is present; if absent, the JSON API # still works and the SPA 404s until dist is deployed. # # Install (on the VM, as root): # sudo cp agent-team-status.service /etc/systemd/system/ # sudo systemctl daemon-reload # sudo systemctl enable --now agent-team-status.service # systemctl status agent-team-status.service # journalctl -u agent-team-status.service -e -f # # This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The # coordinator owns the ledger (read/write); this unit only reads it. They can run # side by side: SQLite WAL/RO opens coexist with the coordinator's writer. [Unit] Description=Sea Haven agent-team LAN-only read-only status dashboard After=network-online.target Wants=network-online.target [Service] Type=simple User=adam WorkingDirectory=/home/adam/orchestrator/agent-team # Optional ('-'): the dashboard reads no secrets, but loading the same env file # as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in # one place if set there. EnvironmentFile=-/home/adam/secrev.env # Use the agent-team venv interpreter (where langgraph + fastapi/uvicorn + the # checkpoint dep are installed), NOT the bare system python3 that systemd's PATH # would resolve. ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.dashboard import serve; serve()" Restart=on-failure RestartSec=5 # Hardening - mirrors agent-team-coordinator.service, but this unit only READS # the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be # read-only and ProtectSystem full; the RO sqlite open lives under read-only # home, which is sufficient for mode=ro). NoNewPrivileges=true ProtectSystem=full ProtectHome=read-only Nice=10 [Install] WantedBy=multi-user.target