mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 10:26:24 +00:00
4f05d09c2b
Make credentials/hosts, projects, agents, and approvals manageable from the dashboard. The API and control layer are separate containers, so the API can't run control actions directly (no git/tmux/claude, doesn't own the tmux sessions). Instead the API enqueues a command and a worker in the control container executes it and writes the result back. Data model (migration 0003): - `commands` queue/audit table; `forge_hosts` registry; `approvals` gains a nullable approver id + `actor` so operator verdicts are first-class. Control worker: - `control/worker.py` claims commands and dispatches to the existing control functions (spawn/kill/resume/record_approval/write_skills/poller.sweep), plus a periodic CI sweep. New `handler worker` CLI subcommand; it becomes the control image's default command (subsumes `poll-ci --watch`). API: - `require_admin` gate + `ADMIN_TOKEN`; project GET/PATCH/DELETE; agent spawn/kill/delete; resume now enqueues (fixes a cross-container bug where the API tried to send tmux keys to a session in the control container); new approvals/commands/hosts routes; forge-init and poll-ci enqueue endpoints. Credentials/hosts: - host->token-env lookup consults the `forge_hosts` registry first (built-in map is the fallback); `resolve()` refactored to a scheme dispatch reserving `db:` for a future encrypted store. Web input restricts credential_ref to env:/file:/db: (cmd: stays CLI-only — it would run arbitrary commands). Dashboard: - New tabs for projects, agents (spawn/kill with live command-status polling), approvals, hosts, and an activity/audit view; shared context is now writable. Tests: +33 (queue atomicity, worker dispatch, CRUD, hosts, admin gating, cmd: rejection, host-aware credentials, and an API->queue->worker->spawn end-to-end). README gains a Web management section. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CrhrBToauu4L2qG6jdnuFP
58 lines
2.7 KiB
Bash
58 lines
2.7 KiB
Bash
# Handler configuration — copy to .env and fill in. Never commit real secrets.
|
|
|
|
# Database. SQLite fallback (single-node) or Postgres (centralized, default for real deploys).
|
|
# SQLite: sqlite:////absolute/path/to/handler.db
|
|
# Postgres: postgresql+psycopg://user:pass@host:5432/handler
|
|
DATABASE_URL=sqlite:////var/lib/handler/handler.db
|
|
|
|
# Single global bearer token gating every API route. Required for the API to start.
|
|
AUTH_TOKEN=change-me-to-a-long-random-string
|
|
|
|
# Optional higher-trust token gating PUT /shared/context/:key.
|
|
# Falls back to AUTH_TOKEN if unset.
|
|
# SHARED_CONTEXT_WRITE_TOKEN=
|
|
|
|
# Optional admin token gating the web control surface: enqueuing control commands
|
|
# (spawn/kill/resume/approve/reject/forge-init/poll-ci), project CRUD, forge-host CRUD,
|
|
# and credential-pointer edits. Falls back to AUTH_TOKEN if unset. Give operators this
|
|
# token in the dashboard to unlock management actions.
|
|
# ADMIN_TOKEN=
|
|
|
|
# Optional generic webhook target for the Notification hook (ntfy, Pushover, Slack, ...).
|
|
# Fully bring-your-own; the Notification hook is a no-op when unset.
|
|
# WEBHOOK_URL=https://ntfy.sh/my-topic
|
|
|
|
# Base directory under which per-project roots and agent worktrees live (isolation).
|
|
PROJECTS_ROOT=/var/lib/handler/projects
|
|
|
|
# Binary overrides (defaults shown). Point at fakes in tests/CI.
|
|
# CLAUDE_BIN=claude
|
|
# MISE_BIN=mise
|
|
# TMUX_BIN=tmux
|
|
# FORGE_BIN=forge
|
|
# GIT_BIN=git
|
|
|
|
# Phase 2 (forge integration). Pin the forge version your base image installs; spawn
|
|
# verifies the injected forge matches and warns on drift. Leave unset to skip the check.
|
|
# FORGE_VERSION=1.2.3
|
|
|
|
# Branches a direct `git push` may not reach without a standing approval (comma-separated).
|
|
# Closes the "merge locally, push to main" path around the forge-merge approval gate.
|
|
# PROTECTED_BRANCHES=main,master
|
|
|
|
# Phase 3 (web UI). Serve the bundled UI from "/" and "/static". Set false for a
|
|
# headless, API-only deployment. Applied at process start (restart to change).
|
|
# UI_ENABLED=true
|
|
|
|
# Extra origins allowed to call the API cross-origin (comma-separated). Only needed if
|
|
# you host the UI on a DIFFERENT origin than the API; the shipped UI is same-origin and
|
|
# needs none. Empty => no CORS middleware.
|
|
# CORS_ORIGINS=https://handler.example.ts.net
|
|
|
|
# Per-project credentials are NOT set here — they live on each project's `credential_ref`
|
|
# as a POINTER (env:VAR / file:/path / cmd:...), resolved and injected only at spawn.
|
|
# The database never stores the raw token. Example, when registering a project:
|
|
# credential_ref = "env:LEEWORKS_TOKEN" (then export LEEWORKS_TOKEN where the control
|
|
# layer runs; it's injected as FORGE_TOKEN +
|
|
# the host-specific var, e.g. GITHUB_TOKEN)
|