Commit Graph
72 Commits
Author SHA1 Message Date
gongzhiyongandOmX bf134dec86 Make Agnet runs submit resource-scoped work safely
Manager now exposes a Resource Grant manifest and the Agnet control-plane response carries runtime state, agent instances, and permission_manifest so frontend runs can submit bounded resource grants without plaintext credentials.

Constraint: Manager remains the user console while NewAPI stays independent and OpenBao is referenced through secret_ref only.

Rejected: platform-side high-risk approval | client approval is the product boundary; Agnet only validates approval evidence.

Confidence: medium

Scope-risk: moderate

Directive: Do not mix child Agnet runtime model selection with NewAPI billing or expose OpenBao as a public route.

Tested: git diff --check; jq empty locale JSON; go vet ./controller ./model ./router; go test -count=1 ./controller ./model ./router

Not-tested: frontend typecheck/build because local node_modules tooling is absent and user requested builds happen on the VM.

Co-authored-by: OmX <omx@oh-my-codex.dev>
2026-05-04 18:55:53 +08:00
gongzhiyong ba02ae5be7 feat: align manager agnet boundaries
- add Manager user_context, NewAPI billing_context, and Agnet agent_runtime deployment fields

- move resource binding/grant scope toward user-owned binding_scope and secret_ref-only paths

- document OpenBao internal access and unified heicode.xinghanlab.com routing boundaries

- fix Manager session user id preservation after external auth login
2026-05-04 09:28:03 +08:00
gongzhiyongandOmX 5fb432f7c8 docs: clarify auth billing and secret boundaries
Document Manager user reuse, NewAPI billing mapping, OpenBao short-lived credential injection, and Agnet-owned model configuration.

Tested: git diff --check

Co-authored-by: OmX <omx@oh-my-codex.dev>
2026-05-04 08:46:05 +08:00
gongzhiyongandOmX d9eb7dcd74 feat: wire resource secrets to OpenBao
Manager needs a platform-owned secret handoff path so resource bindings can keep only vault references while OpenBao stores tenant-scoped credential payloads.

Tested: go test ./controller ./model ./router && go vet ./controller ./model ./router
Co-authored-by: OmX <omx@oh-my-codex.dev>
2026-05-03 23:41:55 +08:00
gongzhiyong a7588e1bc8 chore: remove plaintext postgres retry credentials 2026-05-03 21:49:55 +08:00
gongzhiyong 50bf3de6f0 agnet: add deployment logs metrics readiness endpoints 2026-05-03 21:48:26 +08:00
gongzhiyong fb61f385fb deploy: make azure vm deploy helper executable 2026-05-03 21:17:34 +08:00
gongzhiyong e7b1fd81ec Merge commit 'd39e462ff2de4f82765159a18159f3f00c7f434f' 2026-05-03 20:50:46 +08:00
gongzhiyong f182610793 Merge commit '18a7b316a1da1fb16817387c586ba3db1ca84b1c' 2026-05-03 20:50:45 +08:00
gongzhiyong 36eb0159bc Merge commit '91617b5d64fcf528a34befea1d7a9168efe070c6' 2026-05-03 20:50:44 +08:00
gongzhiyongandOmX 18a7b316a1 Validate focused docs and backend checks
Worker 3 completed the assigned validation pass without source edits, recording backend pass evidence plus environment and contract findings for leader integration.

Tested: go vet ./controller ./model ./router; go test focused resource and Agnet grant cases; go test ./controller ./model ./router; git diff --check; focused docs secret scan.

Not-tested: frontend tsc/eslint require bun or full web dependencies; live Agnet curl checks require credentials and service URL.

Co-authored-by: OmX <omx@oh-my-codex.dev>
2026-05-03 18:11:48 +08:00
gongzhiyong 91617b5d64 docs: tighten Agnet secret placeholders 2026-05-03 18:09:41 +08:00
gongzhiyong 660670d2fc docs: add azure deploy guardrails 2026-05-03 18:09:07 +08:00
gongzhiyong 0d7491c9a1 omx(team): auto-checkpoint worker-5 [unknown] 2026-05-03 18:09:04 +08:00
gongzhiyong b4413cc230 omx(team): merge worker-1 2026-05-03 18:09:01 +08:00
gongzhiyong d39e462ff2 docs: add azure deploy guardrails 2026-05-03 18:08:15 +08:00
gongzhiyong 6a3e918787 docs: complete Agnet platform contract 2026-05-03 18:05:45 +08:00
gongzhiyong aba1ce28df docs: add daily work summary 2026-05-02 23:49:18 +08:00
gongzhiyong ab71d5b72b docs: add agnet platform request contract 2026-05-02 23:42:51 +08:00
gongzhiyong 57a86ce060 Merge commit '8878d4040c9f4c1a94184ed7a9755e9d7f73a745' 2026-05-02 23:42:18 +08:00
gongzhiyong 8878d4040c task: implement P1 manager resource model 2026-05-02 23:36:33 +08:00
gongzhiyong 24405519a9 omx(team): auto-checkpoint worker-1 [1] 2026-05-02 23:32:00 +08:00
gongzhiyong 05182f0277 task: implement manager resource grants 2026-05-02 23:30:23 +08:00
gongzhiyong 5e4648e608 omx(team): auto-checkpoint worker-5 [5] 2026-05-02 23:29:39 +08:00
gongzhiyong 1aa3643278 omx(team): auto-checkpoint worker-3 [3] 2026-05-02 23:29:37 +08:00
gongzhiyong 0a01f36f1b omx(team): auto-checkpoint worker-2 [2] 2026-05-02 23:29:34 +08:00
gongzhiyong 33fa9f20a6 omx(team): auto-checkpoint worker-5 [5] 2026-05-02 23:28:40 +08:00
gongzhiyong a8be398087 omx(team): auto-checkpoint worker-4 [4] 2026-05-02 23:28:37 +08:00
gongzhiyong 30e0b0b4c6 omx(team): auto-checkpoint worker-2 [2] 2026-05-02 23:28:34 +08:00
gongzhiyong bf42bbda8a omx(team): auto-checkpoint worker-4 [4] 2026-05-02 23:26:17 +08:00
gongzhiyong f0cda510a7 omx(team): merge worker-3 2026-05-02 23:24:29 +08:00
gongzhiyong 6fa8dbcb20 omx(team): auto-checkpoint worker-3 [3] 2026-05-02 23:24:29 +08:00
gongzhiyong 912e3155fd docs: converge heicode plan entrypoint 2026-05-02 23:21:16 +08:00
gongzhiyong a19b90c858 docs: split heicode plan documents 2026-05-02 22:26:44 +08:00
gongzhiyong e08a5d4dcc docs: consolidate current heicode plan 2026-05-02 22:15:33 +08:00
gongzhiyong 72d0e095a4 docs: remove obsolete agnet plans 2026-05-02 22:11:19 +08:00
gongzhiyong f585d26fe7 docs: define saas manager agnet architecture 2026-05-02 22:07:02 +08:00
gongzhiyong 63fe529b36 feat(agnet): allow users to bind git sources 2026-05-01 20:55:58 +08:00
gongzhiyong 75bc93b47a docs(agnet): capture user deployment flow 2026-05-01 20:36:30 +08:00
xiaohei be0d102553 fix(manager): load env file in compose override 2026-05-01 11:50:13 +00:00
Ubuntu 2f0bf2563e feat(manager): login auto relay token hidden from UI; available models page
- Add hide_from_user_ui on tokens; EnsureUserRelayToken on login and Agnet session

- List/search tokens: end-users see only visible keys; admins see all

- Add /available-models and sidebar entry; i18n en/zh + locales

- desktop download / router hooks if present under heicode/
2026-05-01 10:00:11 +00:00
Ubuntu b0acfd44c1 feat(agnet): SK repo_ref validation, create deployment UI, docs touch-ups
Extend agnet SK sources with repo_ref and snapshot display; add authenticated
deployment sheet + API types; cockpit toolbar entry; locale strings; minor docs.

Made-with: Cursor
2026-05-01 09:12:00 +00:00
Ubuntu 356592e294 fix(ui): reorder cockpit nav to bind Git sources before deployments
Made-with: Cursor
2026-05-01 08:18:35 +00:00
Ubuntu 4e8b4a66c6 feat(agnet): persist runtime_execution and sk_access_policy with validation
Go control plane: extend agent plan structs, validate bindings and SK policy
codes. Web: surface bindings on Agents page with i18n.

Made-with: Cursor
2026-05-01 08:13:21 +00:00
Ubuntu b42e5b2dd0 feat(heicode): SK workflow UI, Agnet contract docs, usage-log schema
Manager web: Git sources workflow steps and copy; typecheck fixes for auth
and home sections; UsageLog type in usage-log-schema.ts (outside ignored data/).

docs: Agnet platform contract adds runtime_execution and sk_access_policy,
orchestration-plan and acceptance matrix aligned.

Made-with: Cursor
2026-05-01 07:38:17 +00:00
Ubuntu a8f64bce68 feat(ui): reframe SK area as Git-backed sources and snapshot anchors
SK 正文以 Git 为准:侧栏/首页/登录支柱改为「Git 来源」叙事;
/sk-sources 页增加 Git 绑定说明 +「已解析快照锚点」列表标题;
驾驶舱快捷入口与 i18n(中英及同步 locale)对齐。

Made-with: Cursor
2026-05-01 07:21:02 +00:00
Ubuntu a0e69bf076 i18n(zh): complete localization of cockpit/agnet-console/sign-in
- 补齐 109 个 t() key 的中英对照(涵盖 Code 交付驾驶舱、agnet-console
  四张面板、登录页、侧栏/顶部导航/页脚、usage-logs/about/lib/api 等)
- BRAND_TAGLINE 在 auth-layout 改走 t(),新增「智能体研发控制面」
- password-input 的眼睛按钮 aria-label 走 t(),新增「切换密码可见性」
- fr/ja/ru/vi 同步 key(暂用英文兜底,等后续按 i18n 报告补译)

Made-with: Cursor
2026-05-01 06:37:25 +00:00
Ubuntu 8cd82caf72 feat(ui): hide developer console for management backend users
平台定位为管理后台,登录后不再向普通用户暴露 Playground / API Keys / Models
等开发者控制台入口;Usage logs 作为交付链路一环并入 Code delivery 分组。
路由本身保留,仅侧栏不再展示。

Made-with: Cursor
2026-05-01 04:33:15 +00:00
Ubuntu a668e1fca1 feat(auth,ui): hardened Agnet auth, admin workspace and role whitelist
Backend (controller/heicode_agnet_session.go):
- Add HEICODE_ROOT_EMAILS / HEICODE_ADMIN_EMAILS whitelists for JIT role
  assignment. Manager no longer trusts Agnet's role claim — admin / root
  is granted only by local config.
- Default JIT-synced users to RoleCommonUser.
- Promote-only role sync on every login (never demote).

Frontend auth fixes:
- login() no longer hard-codes id=1; preserves the real manager user id
  returned by /api/user/session/from-agnet so the New-Api-User header
  matches the cookie session.
- After login, prefer local /api/user/self over Agnet /me so role /
  status reflect actual manager state (e.g. whitelist promotion).
- lib/api.ts: scope 401 -> "Session expired" handling to identity
  endpoints only; admin-only 401 no longer resets the session.

UI restructuring:
- Default sidebar shows only Code delivery + Console + Personal, plus a
  single "System settings" entry for ROLE.ADMIN+.
- system-settings workspace now hosts the full Tenant administration
  tree (Channels / Models / Subscriptions / Redemption codes / Tenants /
  Templates / Agents / Vendors / All usage logs) for ROLE.ADMIN+, with
  System Administration sub-tree gated to ROLE.SUPER_ADMIN.
- Workspace switch triggers on admin paths (channels, users, templates,
  agents, subscriptions, models, redemption-codes) — not only
  /system-settings.
- system-settings route now allows ROLE.ADMIN+ instead of root-only.

Branding cleanup:
- Drop orphan "NewAPI" i18n keys from web/default locales.
- Rename web/default workspace package newapi-web -> heicode-web.

Config:
- docker-compose.azure-vm.yml exposes HEICODE_ROOT_EMAILS /
  HEICODE_ADMIN_EMAILS.

VERSION: 1.1.0-default-user-role
Made-with: Cursor
2026-04-30 21:03:08 +00:00
Ubuntu aae8dd329a chore(release): bump VERSION to 1.0.2-agnet-jit after Agnet JIT session bridge
Made-with: Cursor
2026-04-30 18:39:10 +00:00