This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/agent-team/systemd/agent-team-status.service

53 lines
2.4 KiB
Desktop File

# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam).
#
# A tiny stdlib http.server that renders the agent-team coordinator's queue
# (tasks/phases, who is waiting on the human gate, active/parked counts, recent
# budget spend) as a 10s-auto-refresh HTML page. It opens the SQLite ledger
# READ-ONLY (mode=ro) and never writes; it has no mutating endpoints and no auth.
#
# NETWORK POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on port
# AGENT_TEAM_STATUS_PORT (default 8770). The sh-secrev VM (10.10.60.120, VLAN 60)
# has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 reaches the
# LAN/VPN only. Task descriptions may be sensitive -> keep this LAN/VPN-only,
# never expose to the public internet.
#
# Install (on the VM, as root):
# sudo cp agent-team-status.service /etc/systemd/system/
# sudo systemctl daemon-reload
# sudo systemctl enable --now agent-team-status.service
# systemctl status agent-team-status.service
# journalctl -u agent-team-status.service -e -f
#
# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The
# coordinator owns the ledger (read/write); this unit only reads it. They can run
# side by side: SQLite WAL/RO opens coexist with the coordinator's writer.
[Unit]
Description=Sea Haven agent-team LAN-only read-only status dashboard
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=adam
WorkingDirectory=/home/adam/orchestrator/agent-team
# Optional ('-'): the dashboard reads no secrets, but loading the same env file
# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in
# one place if set there.
EnvironmentFile=-/home/adam/secrev.env
# Use the agent-team venv interpreter (where langgraph + the checkpoint dep are
# installed), NOT the bare system python3 that systemd's PATH would resolve.
ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.status_page import serve; serve()"
Restart=on-failure
RestartSec=5
# Hardening - mirrors agent-team-coordinator.service, but this unit only READS
# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be
# read-only and ProtectSystem full; the RO sqlite open lives under read-only
# home, which is sufficient for mode=ro).
NoNewPrivileges=true
ProtectSystem=full
ProtectHome=read-only
Nice=10
[Install]
WantedBy=multi-user.target