53 lines
2.4 KiB
Desktop File
53 lines
2.4 KiB
Desktop File
# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam).
|
|
#
|
|
# A tiny stdlib http.server that renders the agent-team coordinator's queue
|
|
# (tasks/phases, who is waiting on the human gate, active/parked counts, recent
|
|
# budget spend) as a 10s-auto-refresh HTML page. It opens the SQLite ledger
|
|
# READ-ONLY (mode=ro) and never writes; it has no mutating endpoints and no auth.
|
|
#
|
|
# NETWORK POSTURE: binds AGENT_TEAM_STATUS_HOST (default 0.0.0.0) on port
|
|
# AGENT_TEAM_STATUS_PORT (default 8770). The sh-secrev VM (10.10.60.120, VLAN 60)
|
|
# has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0 reaches the
|
|
# LAN/VPN only. Task descriptions may be sensitive -> keep this LAN/VPN-only,
|
|
# never expose to the public internet.
|
|
#
|
|
# Install (on the VM, as root):
|
|
# sudo cp agent-team-status.service /etc/systemd/system/
|
|
# sudo systemctl daemon-reload
|
|
# sudo systemctl enable --now agent-team-status.service
|
|
# systemctl status agent-team-status.service
|
|
# journalctl -u agent-team-status.service -e -f
|
|
#
|
|
# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The
|
|
# coordinator owns the ledger (read/write); this unit only reads it. They can run
|
|
# side by side: SQLite WAL/RO opens coexist with the coordinator's writer.
|
|
|
|
[Unit]
|
|
Description=Sea Haven agent-team LAN-only read-only status dashboard
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=adam
|
|
WorkingDirectory=/home/adam/orchestrator/agent-team
|
|
# Optional ('-'): the dashboard reads no secrets, but loading the same env file
|
|
# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in
|
|
# one place if set there.
|
|
EnvironmentFile=-/home/adam/secrev.env
|
|
# Use the agent-team venv interpreter (where langgraph + the checkpoint dep are
|
|
# installed), NOT the bare system python3 that systemd's PATH would resolve.
|
|
ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.status_page import serve; serve()"
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
# Hardening - mirrors agent-team-coordinator.service, but this unit only READS
|
|
# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be
|
|
# read-only and ProtectSystem full; the RO sqlite open lives under read-only
|
|
# home, which is sufficient for mode=ro).
|
|
NoNewPrivileges=true
|
|
ProtectSystem=full
|
|
ProtectHome=read-only
|
|
Nice=10
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|