This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
orchestrator/agent-team/systemd/agent-team-status.service
Adam Moussa 4f4db6ed03 docs(agent-team): point status systemd unit at the SPA dashboard + document WebUI
Switch agent-team-status.service ExecStart from status_page.serve to
dashboard.serve (uvicorn serving web/dist + the JSON API). Document the WebUI in
the README: live auto-laid pipeline map, click-through task history, endpoints,
and the Mac-side npm build + rsync flow.
2026-06-23 17:15:38 -04:00

59 lines
2.7 KiB
Desktop File

# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam).
#
# Serves the React/Vite single-page dashboard (web/dist) + its read-only JSON API
# (/api/state, /api/topology, /api/task/{id}) via FastAPI/uvicorn. The map renders
# the live pipeline (auto-laid from the real LangGraph), and a task can be clicked
# to see its history through each node. It opens the SQLite ledger READ-ONLY
# (mode=ro) and never writes; it has no mutating endpoints and no auth.
#
# NETWORK POSTURE: binds 0.0.0.0 on port 8770. The sh-secrev VM (10.10.60.120,
# VLAN 60) has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0
# reaches the LAN/VPN only. Task descriptions may be sensitive -> keep this
# LAN/VPN-only, never expose to the public internet.
#
# BUILD: the SPA is built on the Mac (`cd web && npm ci && npm run build`) and the
# resulting web/dist is rsynced to the VM (the box Node is too old for a Vite 5+
# build). uvicorn serves whatever web/dist is present; if absent, the JSON API
# still works and the SPA 404s until dist is deployed.
#
# Install (on the VM, as root):
# sudo cp agent-team-status.service /etc/systemd/system/
# sudo systemctl daemon-reload
# sudo systemctl enable --now agent-team-status.service
# systemctl status agent-team-status.service
# journalctl -u agent-team-status.service -e -f
#
# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The
# coordinator owns the ledger (read/write); this unit only reads it. They can run
# side by side: SQLite WAL/RO opens coexist with the coordinator's writer.
[Unit]
Description=Sea Haven agent-team LAN-only read-only status dashboard
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=adam
WorkingDirectory=/home/adam/orchestrator/agent-team
# Optional ('-'): the dashboard reads no secrets, but loading the same env file
# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in
# one place if set there.
EnvironmentFile=-/home/adam/secrev.env
# Use the agent-team venv interpreter (where langgraph + fastapi/uvicorn + the
# checkpoint dep are installed), NOT the bare system python3 that systemd's PATH
# would resolve.
ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.dashboard import serve; serve()"
Restart=on-failure
RestartSec=5
# Hardening - mirrors agent-team-coordinator.service, but this unit only READS
# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be
# read-only and ProtectSystem full; the RO sqlite open lives under read-only
# home, which is sufficient for mode=ro).
NoNewPrivileges=true
ProtectSystem=full
ProtectHome=read-only
Nice=10
[Install]
WantedBy=multi-user.target