Switch agent-team-status.service ExecStart from status_page.serve to dashboard.serve (uvicorn serving web/dist + the JSON API). Document the WebUI in the README: live auto-laid pipeline map, click-through task history, endpoints, and the Mac-side npm build + rsync flow.
59 lines
2.7 KiB
Desktop File
59 lines
2.7 KiB
Desktop File
# agent-team-status.service - R720 LAN-only READ-ONLY status dashboard (sh-secrev VM, user adam).
|
|
#
|
|
# Serves the React/Vite single-page dashboard (web/dist) + its read-only JSON API
|
|
# (/api/state, /api/topology, /api/task/{id}) via FastAPI/uvicorn. The map renders
|
|
# the live pipeline (auto-laid from the real LangGraph), and a task can be clicked
|
|
# to see its history through each node. It opens the SQLite ledger READ-ONLY
|
|
# (mode=ro) and never writes; it has no mutating endpoints and no auth.
|
|
#
|
|
# NETWORK POSTURE: binds 0.0.0.0 on port 8770. The sh-secrev VM (10.10.60.120,
|
|
# VLAN 60) has NO public NIC and sits behind the UniFi firewall, so 0.0.0.0
|
|
# reaches the LAN/VPN only. Task descriptions may be sensitive -> keep this
|
|
# LAN/VPN-only, never expose to the public internet.
|
|
#
|
|
# BUILD: the SPA is built on the Mac (`cd web && npm ci && npm run build`) and the
|
|
# resulting web/dist is rsynced to the VM (the box Node is too old for a Vite 5+
|
|
# build). uvicorn serves whatever web/dist is present; if absent, the JSON API
|
|
# still works and the SPA 404s until dist is deployed.
|
|
#
|
|
# Install (on the VM, as root):
|
|
# sudo cp agent-team-status.service /etc/systemd/system/
|
|
# sudo systemctl daemon-reload
|
|
# sudo systemctl enable --now agent-team-status.service
|
|
# systemctl status agent-team-status.service
|
|
# journalctl -u agent-team-status.service -e -f
|
|
#
|
|
# This is a SEPARATE, OPTIONAL process from agent-team-coordinator.service. The
|
|
# coordinator owns the ledger (read/write); this unit only reads it. They can run
|
|
# side by side: SQLite WAL/RO opens coexist with the coordinator's writer.
|
|
|
|
[Unit]
|
|
Description=Sea Haven agent-team LAN-only read-only status dashboard
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=adam
|
|
WorkingDirectory=/home/adam/orchestrator/agent-team
|
|
# Optional ('-'): the dashboard reads no secrets, but loading the same env file
|
|
# as the coordinator lets AGENT_TEAM_DB / AGENT_TEAM_STATUS_* overrides live in
|
|
# one place if set there.
|
|
EnvironmentFile=-/home/adam/secrev.env
|
|
# Use the agent-team venv interpreter (where langgraph + fastapi/uvicorn + the
|
|
# checkpoint dep are installed), NOT the bare system python3 that systemd's PATH
|
|
# would resolve.
|
|
ExecStart=/home/adam/orchestrator/agent-team/.venv/bin/python -c "from agent_team.dashboard import serve; serve()"
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
# Hardening - mirrors agent-team-coordinator.service, but this unit only READS
|
|
# the ledger, so it needs NO ReadWritePaths carve-out at all (ProtectHome can be
|
|
# read-only and ProtectSystem full; the RO sqlite open lives under read-only
|
|
# home, which is sufficient for mode=ro).
|
|
NoNewPrivileges=true
|
|
ProtectSystem=full
|
|
ProtectHome=read-only
|
|
Nice=10
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|