P1c deploy artifacts: DEPLOY-R720.md (snapshot-first, rsync, venv deps, ~/secrev.env tokens incl. AGENT_TEAM_SLACK_OWNER_IDS, init-db, systemd, the 4-criteria live demo, rollback) and the long-running coordinator service unit.
54 lines
2.5 KiB
Desktop File
54 lines
2.5 KiB
Desktop File
# agent-team-coordinator.service - R720 Plane-2 coordinator daemon (sh-secrev VM, user adam).
|
|
#
|
|
# Long-running coordinator for the agent-team SDLC pipeline. Unlike the
|
|
# sea-haven-secrev sweep (a oneshot driven by a timer), this is an always-on
|
|
# service: it serves the LangGraph coordinator, the durable pending_questions
|
|
# ledger, and the Slack Socket Mode inbound listener that answers clarifier
|
|
# questions. ExecStart runs the `serve` subcommand of the operator CLI.
|
|
#
|
|
# Install (on the VM, as root):
|
|
# sudo cp agent-team-coordinator.service /etc/systemd/system/
|
|
# sudo systemctl daemon-reload
|
|
# sudo systemctl enable --now agent-team-coordinator.service
|
|
# systemctl status agent-team-coordinator.service
|
|
# journalctl -u agent-team-coordinator.service -e -f
|
|
#
|
|
# Secrets come from the EnvironmentFile (leading '-' = optional, no failure if
|
|
# absent), ~/secrev.env (mode 600, NOT in git):
|
|
# CLAUDE_CODE_OAUTH_TOKEN -> subscription OAuth (from `claude setup-token`).
|
|
# A raw ANTHROPIC_API_KEY must NOT be set on this
|
|
# box; it would silently win and meter to API
|
|
# rates. The billing seam pops it defensively.
|
|
# SLACK_BOT_TOKEN -> xoxb- bot token (chat:write) - posts questions.
|
|
# SLACK_APP_TOKEN -> xapp- app-level token (connections:write) -
|
|
# REQUIRED for Socket Mode; opens the inbound
|
|
# WebSocket that receives answers. Without it the
|
|
# coordinator can post but never hear replies.
|
|
# SLACK_CHANNEL_ID -> target channel for clarifier questions.
|
|
|
|
[Unit]
|
|
Description=Sea Haven agent-team Plane-2 coordinator daemon
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=adam
|
|
WorkingDirectory=/home/adam/orchestrator/agent-team
|
|
EnvironmentFile=-/home/adam/secrev.env
|
|
ExecStart=/usr/bin/env python3 run-team.py serve
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
# Hardening - matches the level the sea-haven-secrev unit relies on, scoped for a
|
|
# long-running daemon that must READ ~/secrev.env and WRITE the local ledger.
|
|
NoNewPrivileges=true
|
|
ProtectSystem=full
|
|
# ProtectHome cannot be `true`: the daemon reads /home/adam/secrev.env and writes
|
|
# the ledger under the working dir. read-only home + an explicit RW carve-out for
|
|
# the state/ dir keeps the rest of $HOME unreadable/unwritable to the service.
|
|
ProtectHome=read-only
|
|
ReadWritePaths=/home/adam/orchestrator/agent-team/state
|
|
Nice=10
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|