mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 11:36:24 +00:00
feat(web): fully web-managed control plane via a DB command queue
Make credentials/hosts, projects, agents, and approvals manageable from the dashboard. The API and control layer are separate containers, so the API can't run control actions directly (no git/tmux/claude, doesn't own the tmux sessions). Instead the API enqueues a command and a worker in the control container executes it and writes the result back. Data model (migration 0003): - `commands` queue/audit table; `forge_hosts` registry; `approvals` gains a nullable approver id + `actor` so operator verdicts are first-class. Control worker: - `control/worker.py` claims commands and dispatches to the existing control functions (spawn/kill/resume/record_approval/write_skills/poller.sweep), plus a periodic CI sweep. New `handler worker` CLI subcommand; it becomes the control image's default command (subsumes `poll-ci --watch`). API: - `require_admin` gate + `ADMIN_TOKEN`; project GET/PATCH/DELETE; agent spawn/kill/delete; resume now enqueues (fixes a cross-container bug where the API tried to send tmux keys to a session in the control container); new approvals/commands/hosts routes; forge-init and poll-ci enqueue endpoints. Credentials/hosts: - host->token-env lookup consults the `forge_hosts` registry first (built-in map is the fallback); `resolve()` refactored to a scheme dispatch reserving `db:` for a future encrypted store. Web input restricts credential_ref to env:/file:/db: (cmd: stays CLI-only — it would run arbitrary commands). Dashboard: - New tabs for projects, agents (spawn/kill with live command-status polling), approvals, hosts, and an activity/audit view; shared context is now writable. Tests: +33 (queue atomicity, worker dispatch, CRUD, hosts, admin gating, cmd: rejection, host-aware credentials, and an API->queue->worker->spawn end-to-end). README gains a Web management section. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CrhrBToauu4L2qG6jdnuFP
This commit is contained in:
@@ -1,8 +1,9 @@
|
||||
"""Answer + resume routes, including the mocked control seam."""
|
||||
"""Answer + resume routes. Resume now enqueues a command for the control worker (the tmux
|
||||
session lives in the control container), so we assert on the queued command, not an
|
||||
in-process seam call."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from handler.control import spawn
|
||||
from handler.db import repository as repo
|
||||
from handler.db.engine import get_engine
|
||||
|
||||
@@ -43,34 +44,29 @@ def test_answer_with_no_open_question_is_404(client, auth, env):
|
||||
assert r.status_code == 404
|
||||
|
||||
|
||||
def test_resume_calls_control_seam(client, auth, env, monkeypatch):
|
||||
def test_resume_enqueues_command_with_the_answer(client, auth, env):
|
||||
_seed_agent_with_question(env)
|
||||
client.post(
|
||||
"/projects/proj/agents/api/answer", json={"answer": "Postgres"}, headers=auth
|
||||
)
|
||||
|
||||
calls = []
|
||||
|
||||
def fake_resume(agent, answer):
|
||||
calls.append((agent["name"], answer))
|
||||
return True, "delivered"
|
||||
|
||||
monkeypatch.setattr(spawn, "resume", fake_resume)
|
||||
|
||||
r = client.post("/projects/proj/agents/api/resume", json={}, headers=auth)
|
||||
assert r.status_code == 200
|
||||
assert r.json()["resumed"] is True
|
||||
assert calls == [("api", "Postgres")]
|
||||
assert r.status_code == 202
|
||||
body = r.json()
|
||||
assert body["type"] == "resume"
|
||||
assert body["agent_name"] == "api"
|
||||
assert body["status"] == "queued"
|
||||
# The API resolves the stored answer and hands it to the worker via the payload.
|
||||
assert body["payload"]["answer"] == "Postgres"
|
||||
|
||||
with get_engine().begin() as conn:
|
||||
a = repo.get_agent_by_name(conn, "proj", "api")
|
||||
assert a["status"] == "working"
|
||||
commands = repo.list_commands(conn, project_id="proj")
|
||||
assert [c["type"] for c in commands] == ["resume"]
|
||||
|
||||
|
||||
def test_resume_without_answer_is_400(client, auth, env, monkeypatch):
|
||||
def test_resume_without_answer_is_400(client, auth, env):
|
||||
with get_engine().begin() as conn:
|
||||
repo.create_project(conn, "proj", "/tmp/proj")
|
||||
repo.create_agent(conn, "proj", "api", "/tmp/proj/api")
|
||||
monkeypatch.setattr(spawn, "resume", lambda a, ans: (True, "x"))
|
||||
r = client.post("/projects/proj/agents/api/resume", json={}, headers=auth)
|
||||
assert r.status_code == 400
|
||||
|
||||
Reference in New Issue
Block a user