feat(web): fully web-managed control plane via a DB command queue

Make credentials/hosts, projects, agents, and approvals manageable from the
dashboard. The API and control layer are separate containers, so the API can't
run control actions directly (no git/tmux/claude, doesn't own the tmux
sessions). Instead the API enqueues a command and a worker in the control
container executes it and writes the result back.

Data model (migration 0003):
- `commands` queue/audit table; `forge_hosts` registry; `approvals` gains a
  nullable approver id + `actor` so operator verdicts are first-class.

Control worker:
- `control/worker.py` claims commands and dispatches to the existing control
  functions (spawn/kill/resume/record_approval/write_skills/poller.sweep),
  plus a periodic CI sweep. New `handler worker` CLI subcommand; it becomes the
  control image's default command (subsumes `poll-ci --watch`).

API:
- `require_admin` gate + `ADMIN_TOKEN`; project GET/PATCH/DELETE; agent
  spawn/kill/delete; resume now enqueues (fixes a cross-container bug where the
  API tried to send tmux keys to a session in the control container); new
  approvals/commands/hosts routes; forge-init and poll-ci enqueue endpoints.

Credentials/hosts:
- host->token-env lookup consults the `forge_hosts` registry first (built-in
  map is the fallback); `resolve()` refactored to a scheme dispatch reserving
  `db:` for a future encrypted store. Web input restricts credential_ref to
  env:/file:/db: (cmd: stays CLI-only — it would run arbitrary commands).

Dashboard:
- New tabs for projects, agents (spawn/kill with live command-status polling),
  approvals, hosts, and an activity/audit view; shared context is now writable.

Tests: +33 (queue atomicity, worker dispatch, CRUD, hosts, admin gating,
cmd: rejection, host-aware credentials, and an API->queue->worker->spawn
end-to-end). README gains a Web management section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrhrBToauu4L2qG6jdnuFP
This commit is contained in:
Claude
2026-07-10 16:32:45 +00:00
parent 7b5a5e3c27
commit 4f05d09c2b
31 changed files with 2277 additions and 146 deletions
+53
View File
@@ -0,0 +1,53 @@
"""Host-aware credential resolution: the forge_hosts registry overrides the built-in map
when a connection is supplied, and behaviour is unchanged when it isn't (regression)."""
from __future__ import annotations
from handler.control import credentials
from handler.db import repository as repo
from handler.db.engine import get_engine
def test_registry_host_overrides_builtin_env_var(env):
with get_engine().begin() as conn:
repo.create_host(conn, "github.com", "github", token_env_var="CORP_GH_TOKEN")
e = credentials.credential_env("tok", "https://github.com/me/repo.git", conn)
# Registry wins over the built-in GITHUB_TOKEN mapping.
assert e["CORP_GH_TOKEN"] == "tok"
assert e["FORGE_TOKEN"] == "tok"
assert "GITHUB_TOKEN" not in e
def test_registry_enables_self_hosted_host(env):
with get_engine().begin() as conn:
repo.create_host(conn, "git.corp.internal", "gitea", token_env_var="CORP_TOKEN")
e = credentials.credential_env("tok", "https://git.corp.internal/me/repo.git", conn)
assert e["CORP_TOKEN"] == "tok"
def test_fallback_to_builtin_when_no_row(env):
with get_engine().begin() as conn:
e = credentials.credential_env("tok", "https://github.com/me/repo.git", conn)
# No forge_hosts row -> built-in map still applies.
assert e["GITHUB_TOKEN"] == "tok"
def test_no_conn_behaviour_is_unchanged():
# The 2-arg form (no registry) must match the pre-existing built-in behaviour.
e = credentials.credential_env("tok", "https://github.com/me/repo.git")
assert e == {"FORGE_TOKEN": "tok", "GITHUB_TOKEN": "tok"}
def test_credential_config_uses_registry_base_url(env):
with get_engine().begin() as conn:
repo.create_host(conn, "git.corp", "gitea", base_url="https://git.corp:8443")
key, value = credentials.git_credential_config("https://git.corp/me/repo.git", conn)
assert key == "credential.https://git.corp:8443.helper"
assert "$FORGE_TOKEN" in value
def test_db_scheme_is_reserved_not_yet_resolvable():
import pytest
with pytest.raises(credentials.CredentialError, match="reserved"):
credentials.resolve("db:42")