Files
handler/.env.example
T
Claude a3a5c272a2 Add the pi harness: lightweight local-model agents with full gate parity
Model backend rows gain a harness column (claude | pi). A pi-harness row runs
the agent through the pi coding agent instead of the claude binary — pi speaks
the OpenAI Completions API natively, so a bare vLLM/llama.cpp/Ollama endpoint
needs no LiteLLM/claude-code-router translation proxy, and the loop is far
lighter for slow local token throughput. The Claude subscription and existing
claude-harness backends are untouched.

Parity comes from generated per-agent artifacts under ~/.handler-pi (outside
the repo tree, so the clean-tree gate never trips): models.json + settings.json
render the row as a pi provider pinned as the default model; a bundled bridge
extension (pi_bridge.ts) adapts pi's events to the exact stdin/stdout contract
of `python -m handler.hooks` — the Stop/completion gate re-prompts pi with
blockers via a follow-up message, git push runs the test/build/approval gates
and denies on failure, questions defer through an ask_operator tool into the
normal answer/resume flow, and memory recall is injected at session start. The
memory tools are registered natively (pi has no MCP), shelling to a new
`python -m handler.mcpserver --call <tool>` seam that reuses the MCP server's
implementations. Skills reuse the same ~/.claude/skills sync (pi implements the
same SKILL.md standard) plus the repo's committed .claude/skills.

Sessions are single JSONL files pre-assigned via --session, so cross-worker
resume archives/materializes exactly like claude's; the prompt travels on stdin
(pi has no -- separator). The supervisor normalizes pi's event stream on the
fly: assistant message_end feeds last_output, the final agent_end becomes the
run result. The whole chain was validated live against pi 0.84.1 with a stub
OpenAI endpoint: memory injection, push-gate denial (including the protected-
branch approval gate), stop-gate block loop, and ask_operator pause all ran
end to end through the real hooks and DB.

Also: harness selector in the dashboard Models form, pi baked into the control
image (NodeSource 22 for pi's node >= 22.19 floor), PI_BIN override, docs in
docs/local-models.md, fake_pi fixture + 12 tests (361 total green).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KdGv3u3DfTsP1S188KDhVH
2026-08-12 18:21:35 +00:00

66 lines
3.2 KiB
Bash

# Handler configuration — copy to .env and fill in. Never commit real secrets.
# Database. SQLite fallback (single-node) or Postgres (centralized, default for real deploys).
# SQLite: sqlite:////absolute/path/to/handler.db
# Postgres: postgresql+psycopg://user:pass@host:5432/handler
DATABASE_URL=sqlite:////var/lib/handler/handler.db
# Single global bearer token gating every API route. Required for the API to start.
AUTH_TOKEN=change-me-to-a-long-random-string
# Optional higher-trust token gating PUT /shared/context/:key.
# Falls back to AUTH_TOKEN if unset.
# SHARED_CONTEXT_WRITE_TOKEN=
# Optional admin token gating the web control surface: enqueuing control commands
# (spawn/kill/resume/approve/reject/forge-init/poll-ci), project CRUD, forge-host CRUD,
# and credential-pointer edits. Falls back to AUTH_TOKEN if unset. Give operators this
# token in the dashboard to unlock management actions.
# ADMIN_TOKEN=
# Optional generic webhook target for the Notification hook (ntfy, Pushover, Slack, ...).
# Fully bring-your-own; the Notification hook is a no-op when unset.
# WEBHOOK_URL=https://ntfy.sh/my-topic
# Symmetric key for the encrypted secret store: git-server tokens and SSH private keys
# are Fernet-encrypted with it before they reach the database. Set the SAME value on the
# API (encrypts on write) and the control container (decrypts at clone/spawn). Generate:
# python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
# Unset => storing tokens/SSH keys on git servers is refused with a clear error.
# HANDLER_SECRET_KEY=
# Base directory under which per-project roots and agent worktrees live (isolation).
PROJECTS_ROOT=/var/lib/handler/projects
# Binary overrides (defaults shown). Point at fakes in tests/CI.
# CLAUDE_BIN=claude
# PI_BIN=pi
# MISE_BIN=mise
# TMUX_BIN=tmux
# FORGE_BIN=forge
# GIT_BIN=git
# Phase 2 (forge integration). Pin the forge version your base image installs; spawn
# verifies the injected forge matches and warns on drift. Leave unset to skip the check.
# FORGE_VERSION=1.2.3
# Branches a direct `git push` may not reach without a standing approval (comma-separated).
# Closes the "merge locally, push to main" path around the forge-merge approval gate.
# PROTECTED_BRANCHES=main,master
# Phase 3 (web UI). Serve the bundled UI from "/" and "/static". Set false for a
# headless, API-only deployment. Applied at process start (restart to change).
# UI_ENABLED=true
# Extra origins allowed to call the API cross-origin (comma-separated). Only needed if
# you host the UI on a DIFFERENT origin than the API; the shipped UI is same-origin and
# needs none. Empty => no CORS middleware.
# CORS_ORIGINS=https://handler.example.ts.net
# Per-project credentials are NOT set here — they live on each project's `credential_ref`
# as a POINTER (env:VAR / file:/path / cmd:...), resolved and injected only at spawn.
# The database never stores the raw token. Example, when registering a project:
# credential_ref = "env:LEEWORKS_TOKEN" (then export LEEWORKS_TOKEN where the control
# layer runs; it's injected as FORGE_TOKEN +
# the host-specific var, e.g. GITHUB_TOKEN)