# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam). # # A tiny stdlib http.server that renders the agent-team coordinator's queue # (tasks/phases, who is waiting on the human gate, active/parked counts, recent # budget spend) as a 10s-auto-refresh HTML page. It opens the SQLite ledger # READ-ONLY (mode=ro) and never writes; it has no mutating endpoints and no auth. # # NETWORK POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on port # AGENT_TEAM_STATUS_PORT (default 8770). The sh-secrev VM (10.10.60.120, VLAN 60) # has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 reaches the # LAN/VPN only. Task descriptions may be sensitive -> keep this LAN/VPN-only, # never expose to the public internet. # # Install (on the VM, as root): # sudo cp agent-team-status.service /etc/systemd/system/ # sudo systemctl daemon-reload # sudo systemctl enable --now agent-team-status.service # systemctl status agent-team-status.service # journalctl -u agent-team-status.service -e -f # # This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The # coordinator owns the ledger (read/write); this unit only reads it. They can run # side by side: SQLite WAL/RO opens coexist with the coordinator's writer. [Unit] Description=Sea Haven agent-team LAN-only read-only status dashboard After=network-online.target Wants=network-online.target [Service] Type=simple User=adam WorkingDirectory=/home/adam/orchestrator/agent-team # Optional ('-'): the dashboard reads no secrets, but loading the same env file # as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in # one place if set there. EnvironmentFile=-/home/adam/secrev.env # Use the agent-team venv interpreter (where langgraph + the checkpoint dep are # installed), NOT the bare system python3 that systemd's PATH would resolve. ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.status_page import serve; serve()" Restart=on-failure RestartSec=5 # Hardening - mirrors agent-team-coordinator.service, but this unit only READS # the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be # read-only and ProtectSystem full; the RO sqlite open lives under read-only # home, which is sufficient for mode=ro). NoNewPrivileges=true ProtectSystem=full ProtectHome=read-only Nice=10 [Install] WantedBy=multi-user.target