Files
handler/docker-compose.yml
T
Claude 4f05d09c2b feat(web): fully web-managed control plane via a DB command queue
Make credentials/hosts, projects, agents, and approvals manageable from the
dashboard. The API and control layer are separate containers, so the API can't
run control actions directly (no git/tmux/claude, doesn't own the tmux
sessions). Instead the API enqueues a command and a worker in the control
container executes it and writes the result back.

Data model (migration 0003):
- `commands` queue/audit table; `forge_hosts` registry; `approvals` gains a
  nullable approver id + `actor` so operator verdicts are first-class.

Control worker:
- `control/worker.py` claims commands and dispatches to the existing control
  functions (spawn/kill/resume/record_approval/write_skills/poller.sweep),
  plus a periodic CI sweep. New `handler worker` CLI subcommand; it becomes the
  control image's default command (subsumes `poll-ci --watch`).

API:
- `require_admin` gate + `ADMIN_TOKEN`; project GET/PATCH/DELETE; agent
  spawn/kill/delete; resume now enqueues (fixes a cross-container bug where the
  API tried to send tmux keys to a session in the control container); new
  approvals/commands/hosts routes; forge-init and poll-ci enqueue endpoints.

Credentials/hosts:
- host->token-env lookup consults the `forge_hosts` registry first (built-in
  map is the fallback); `resolve()` refactored to a scheme dispatch reserving
  `db:` for a future encrypted store. Web input restricts credential_ref to
  env:/file:/db: (cmd: stays CLI-only — it would run arbitrary commands).

Dashboard:
- New tabs for projects, agents (spawn/kill with live command-status polling),
  approvals, hosts, and an activity/audit view; shared context is now writable.

Tests: +33 (queue atomicity, worker dispatch, CRUD, hosts, admin gating,
cmd: rejection, host-aware credentials, and an API->queue->worker->spawn
end-to-end). README gains a Web management section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CrhrBToauu4L2qG6jdnuFP
2026-07-10 16:32:45 +00:00

72 lines
2.5 KiB
YAML

# Local/dev deployment: API + Postgres. For a single-node SQLite deploy, drop the
# `db` service and DATABASE_URL override — the image defaults to SQLite on the
# handler-data volume.
services:
api:
image: ghcr.io/0xwheatyz/handler:latest
build: .
ports:
- "8000:8000"
environment:
DATABASE_URL: postgresql+psycopg://handler:handler@db:5432/handler
# Required — the API refuses to start without it. Set in .env or the shell.
AUTH_TOKEN: ${AUTH_TOKEN:?set AUTH_TOKEN in .env or the environment}
SHARED_CONTEXT_WRITE_TOKEN: ${SHARED_CONTEXT_WRITE_TOKEN:-}
WEBHOOK_URL: ${WEBHOOK_URL:-}
UI_ENABLED: ${UI_ENABLED:-true}
CORS_ORIGINS: ${CORS_ORIGINS:-}
volumes:
- handler-data:/var/lib/handler
depends_on:
db:
condition: service_healthy
restart: unless-stopped
# Control layer: the `handler` worker. Drains the control-command queue the API enqueues
# (spawn/kill/resume/approve/reject/forge-init/poll-ci) and sweeps CI on an interval.
# Shares the database and the handler-data volume with the API. It waits for the API
# (which owns migrations), so RUN_MIGRATIONS is off here to avoid a startup race. Run
# one-shot control commands against the same image with, e.g.,
# `docker compose run --rm control handler list`. Live agent spawning also needs
# `git`/`tmux` (baked in) plus bring-your-own `claude`/`forge` binaries — layer or mount
# those in.
control:
image: ghcr.io/0xwheatyz/handler/control:latest
build:
context: .
dockerfile: Dockerfile.control
environment:
DATABASE_URL: postgresql+psycopg://handler:handler@db:5432/handler
RUN_MIGRATIONS: "false"
PROJECTS_ROOT: /var/lib/handler/projects
# Per-project forge credentials are resolved from credential_ref pointers at spawn;
# export the referenced vars here when spawning agents from this container.
FORGE_VERSION: ${FORGE_VERSION:-}
volumes:
- handler-data:/var/lib/handler
depends_on:
db:
condition: service_healthy
api:
condition: service_healthy
restart: unless-stopped
db:
image: postgres:16-alpine
environment:
POSTGRES_USER: handler
POSTGRES_PASSWORD: handler
POSTGRES_DB: handler
volumes:
- postgres-data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U handler -d handler"]
interval: 5s
timeout: 3s
retries: 10
restart: unless-stopped
volumes:
handler-data:
postgres-data: