Skip to content

Admin panel: observability + settings + on/off (127.0.0.1, separate from receiver) #5

Description

@edgehero

Why

This is the piece of the vision that is entirely missing and that you specifically described: a
main panel to see triggers, see the logs of each previous trigger, manage them, change settings, and
turn pi-dispatch on/off. panel/ does not exist. The design is already written
(DES-PANEL-SEPARATE-FROM-RECEIVER, specs/design.md:358) and carries a load-bearing security
correction — read it before starting.

Non-negotiable architecture (DES-PANEL-SEPARATE-FROM-RECEIVER)

  • The panel is a separate process on a separate port, bound 127.0.0.1 by default. It is the admin
    surface.
  • The receiver must NOT carry the panel. The receiver binds 0.0.0.0 (GitHub must reach it from the
    internet); mounting the admin surface there publishes the ability to change the model and rewrite
    behaviour to the internet
    . The two have opposite reachability requirements and cannot share a port.
    (This is a correction to the original DESIGN.md, which mounted Bull Board on the receiver.)

What to build (panel/)

Scope it as a checklist; the first item is shippable alone:

  • Observability (read-only) — mount Bull Board (.claude/rules/library-first.md — do not
    build a queue dashboard) for waiting/active/failed jobs, plus a "previous triggers" view with
    each run's outcome and logs, reading the run-history read model.
  • On/off switch — "off means stop draining the queue" (specs/design.md:134), i.e.
    queue.pause() / worker pause, not dropping the receiver. Jobs still enqueue while paused; they
    just don't run. (Pairs with the background-service issue for the worker-side mechanism.)
  • Settings — model / provider / concurrency / daily budget cap, editable at runtime.
  • Manage triggers — view configured cron schedules and label→flow mappings; enable/disable.

Explicitly out of scope for the panel (DES-FLOWS-ARE-DATA-PERSONA-IS-CODE): it does not edit
personas, skills, or hard rules — those live in the project's .pi/ and the baked guardrails, in git,
reviewed. The panel changes operational settings, not agent instructions.

Depends on

The run-history / durable logs issue (for "previous triggers + logs"). The on/off switch pairs with
the background-service issue. Observability (Bull Board) can ship as soon as the queue is drainable —
it does not need the receiver.

Acceptance

  • The panel binds 127.0.0.1 only; it is not reachable on the receiver's public port.
  • An operator can see waiting/active/failed jobs and open any past run's log.
  • Toggling "off" stops jobs from running but does not reject new enqueues; toggling "on" resumes draining.
  • Changing the model/budget in the panel affects the next job without a restart.
  • The panel exposes no control that edits a persona, skill, or hard rule.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestpanelAdmin panel / observability

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions