Files
handler/Dockerfile.control
T
Claude 4f05d09c2b feat(web): fully web-managed control plane via a DB command queue
Make credentials/hosts, projects, agents, and approvals manageable from the
dashboard. The API and control layer are separate containers, so the API can't
run control actions directly (no git/tmux/claude, doesn't own the tmux
sessions). Instead the API enqueues a command and a worker in the control
container executes it and writes the result back.

Data model (migration 0003):
- `commands` queue/audit table; `forge_hosts` registry; `approvals` gains a
  nullable approver id + `actor` so operator verdicts are first-class.

Control worker:
- `control/worker.py` claims commands and dispatches to the existing control
  functions (spawn/kill/resume/record_approval/write_skills/poller.sweep),
  plus a periodic CI sweep. New `handler worker` CLI subcommand; it becomes the
  control image's default command (subsumes `poll-ci --watch`).

API:
- `require_admin` gate + `ADMIN_TOKEN`; project GET/PATCH/DELETE; agent
  spawn/kill/delete; resume now enqueues (fixes a cross-container bug where the
  API tried to send tmux keys to a session in the control container); new
  approvals/commands/hosts routes; forge-init and poll-ci enqueue endpoints.

Credentials/hosts:
- host->token-env lookup consults the `forge_hosts` registry first (built-in
  map is the fallback); `resolve()` refactored to a scheme dispatch reserving
  `db:` for a future encrypted store. Web input restricts credential_ref to
  env:/file:/db: (cmd: stays CLI-only — it would run arbitrary commands).

Dashboard:
- New tabs for projects, agents (spawn/kill with live command-status polling),
  approvals, hosts, and an activity/audit view; shared context is now writable.

Tests: +33 (queue atomicity, worker dispatch, CRUD, hosts, admin gating,
cmd: rejection, host-aware credentials, and an API->queue->worker->spawn
end-to-end). README gains a Web management section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrhrBToauu4L2qG6jdnuFP
2026-07-10 16:32:45 +00:00

67 lines
2.7 KiB
Docker

# syntax=docker/dockerfile:1
# Control-layer image: the `handler` CLI (the write side — spawn/list/kill agents,
# approve/reject branches, forge-init, and the CI poller). It shares the package, the
# database, and the /var/lib/handler data volume with the API image (see Dockerfile),
# but runs the control process instead of uvicorn.
# ---- build stage: install the package + deps into an isolated venv ----
FROM python:3.11-slim AS builder
ENV PIP_DISABLE_PIP_VERSION_CHECK=1 \
PIP_NO_CACHE_DIR=1
RUN python -m venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
WORKDIR /build
COPY pyproject.toml README.md ./
COPY src ./src
RUN pip install .
# ---- runtime stage ----
FROM python:3.11-slim
# git + tmux are the live-spawning dependencies the control layer shells out to
# (README "Requirements"); openssh-client covers git-over-ssh remotes. The `claude`
# and `forge` binaries are bring-your-own — layer or mount them in for live agent
# spawning and CI resolution; the poller degrades gracefully when forge is absent.
RUN apt-get update \
&& apt-get install -y --no-install-recommends git tmux openssh-client \
&& rm -rf /var/lib/apt/lists/*
ENV PATH="/opt/venv/bin:$PATH" \
PYTHONUNBUFFERED=1 \
# SQLite fallback lives on the /var/lib/handler volume; point DATABASE_URL at the
# same Postgres the API uses for a shared, real deploy (see docker-compose.yml).
DATABASE_URL="sqlite:////var/lib/handler/handler.db" \
PROJECTS_ROOT="/var/lib/handler/projects"
COPY --from=builder /opt/venv /opt/venv
# Ship alembic alongside the package so the image can migrate standalone if asked
# (RUN_MIGRATIONS=true). In the compose stack the API owns migrations and the control
# service runs with RUN_MIGRATIONS=false to avoid a startup race.
WORKDIR /app
COPY alembic.ini ./
COPY src/handler/migrations ./src/handler/migrations
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
RUN useradd --system --home-dir /var/lib/handler --create-home handler \
&& mkdir -p /var/lib/handler/projects \
&& chown -R handler:handler /var/lib/handler \
&& chmod +x /usr/local/bin/docker-entrypoint.sh
USER handler
VOLUME /var/lib/handler
# Liveness: exercises the CLI end-to-end and confirms the database is reachable.
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
CMD handler list >/dev/null 2>&1 || exit 1
# Default to the worker: it drains the control-command queue the API enqueues
# (spawn/kill/resume/approve/…) and sweeps CI on an interval (subsuming `poll-ci --watch`).
# Override for one-shot control operations, e.g. `docker compose run --rm control handler list`.
ENTRYPOINT ["docker-entrypoint.sh"]
CMD ["handler", "worker"]