# agent-team-coordinator.service - R720 Plane-2 coordinator daemon (sh-secrev VM, user adam). # # Long-running coordinator for the agent-team SDLC pipeline. Unlike the # sea-haven-secrev sweep (a oneshot driven by a timer), this is an always-on # service: it serves the LangGraph coordinator, the durable pending_questions # ledger, and the Slack Socket Mode inbound listener that answers clarifier # questions. ExecStart runs the `serve` subcommand of the operator CLI. # # Install (on the VM, as root): # sudo cp agent-team-coordinator.service /etc/systemd/system/ # sudo systemctl daemon-reload # sudo systemctl enable --now agent-team-coordinator.service # systemctl status agent-team-coordinator.service # journalctl -u agent-team-coordinator.service -e -f # # Secrets come from the EnvironmentFile (leading '-' = optional, no failure if # absent), ~/secrev.env (mode 600, NOT in git): # CLAUDE_CODE_OAUTH_TOKEN -> subscription OAuth (from `claude setup-token`). # A raw ANTHROPIC_API_KEY must NOT be set on this # box; it would silently win and meter to API # rates. The billing seam pops it defensively. # SLACK_BOT_TOKEN -> xoxb- bot token (chat:write) - posts questions. # SLACK_APP_TOKEN -> xapp- app-level token (connections:write) - # REQUIRED for Socket Mode; opens the inbound # WebSocket that receives answers. Without it the # coordinator can post but never hear replies. # SLACK_CHANNEL_ID -> target channel for clarifier questions. [Unit] Description=Sea Haven agent-team Plane-2 coordinator daemon After=network-online.target Wants=network-online.target [Service] Type=simple User=adam WorkingDirectory=/home/adam/orchestrator/agent-team EnvironmentFile=-/home/adam/secrev.env ExecStart=/usr/bin/env python3 run-team.py serve Restart=on-failure RestartSec=5 # Hardening - matches the level the sea-haven-secrev unit relies on, scoped for a # long-running daemon that must READ ~/secrev.env and WRITE the local ledger. NoNewPrivileges=true ProtectSystem=full # ProtectHome cannot be `true`: the daemon reads /home/adam/secrev.env and writes # the ledger under the working dir. read-only home + an explicit RW carve-out for # the state/ dir keeps the rest of $HOME unreadable/unwritable to the service. ProtectHome=read-only ReadWritePaths=/home/adam/orchestrator/agent-team/state Nice=10 [Install] WantedBy=multi-user.target