Admin-gated Settings: runtime model selection, enforce is_admin (#79)
Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
// Package agentmodel holds the ONE place that knows how pansy turns a model spec
|
||||
// into a majordomo model: which provider to register and under which token.
|
||||
//
|
||||
// It exists as a leaf so both internal/agent (which builds the run loop) and
|
||||
// internal/service (which validates a spec before storing it as a setting) can
|
||||
// share that knowledge without an import cycle — agent imports service, so the
|
||||
// shared bit can live in neither of them.
|
||||
package agentmodel
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"gitea.stevedudenhoeffer.com/steve/majordomo"
|
||||
"gitea.stevedudenhoeffer.com/steve/majordomo/llm"
|
||||
"gitea.stevedudenhoeffer.com/steve/majordomo/provider/ollama"
|
||||
)
|
||||
|
||||
// registry builds the private majordomo registry pansy uses.
|
||||
//
|
||||
// Private, not the package-level default: pansy passes the key it was configured
|
||||
// with rather than depending on ambient environment, and majordomo's own
|
||||
// ollama-cloud preset reads OLLAMA_API_KEY while pansy (like gadfly) is
|
||||
// configured with OLLAMA_CLOUD_API_KEY. Registering the provider explicitly
|
||||
// makes that bridge visible instead of a mysterious empty token.
|
||||
func registry(apiKey string) *majordomo.Registry {
|
||||
reg := majordomo.New()
|
||||
reg.RegisterProvider(ollama.Cloud(ollama.WithToken(apiKey)))
|
||||
return reg
|
||||
}
|
||||
|
||||
// Resolve parses a model spec against pansy's registry into a live model. The
|
||||
// spec goes to Parse VERBATIM — the grammar, including comma-separated failover
|
||||
// chains, is majordomo's, and re-implementing any of it here would only mean two
|
||||
// places to update when it grows.
|
||||
func Resolve(apiKey, spec string) (llm.Model, error) {
|
||||
if strings.TrimSpace(spec) == "" {
|
||||
return nil, errors.New("agentmodel: empty model spec")
|
||||
}
|
||||
m, err := registry(apiKey).Parse(spec)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("agentmodel: resolve %q: %w", spec, err)
|
||||
}
|
||||
return m, nil
|
||||
}
|
||||
|
||||
// Validate reports whether a spec resolves, without building anything the caller
|
||||
// keeps — the cheap, deterministic check a settings save runs to reject a typo.
|
||||
//
|
||||
// It does NOT make a live call, so it needs no working key and won't catch a
|
||||
// model that is merely absent upstream; that surfaces on first use. Parse
|
||||
// resolving (known provider, well-formed spec) is the half worth doing eagerly.
|
||||
func Validate(apiKey, spec string) error {
|
||||
_, err := Resolve(apiKey, spec)
|
||||
return err
|
||||
}
|
||||
@@ -0,0 +1,35 @@
|
||||
package agentmodel
|
||||
|
||||
import "testing"
|
||||
|
||||
// TestValidate is what the settings PATCH relies on to reject a typo at save
|
||||
// time rather than on the next chat turn.
|
||||
func TestValidate(t *testing.T) {
|
||||
if err := Validate("k", "ollama-cloud/glm-5.2:cloud"); err != nil {
|
||||
t.Errorf("valid spec rejected: %v", err)
|
||||
}
|
||||
// No key needed to validate — Parse resolves the provider, it doesn't call it.
|
||||
if err := Validate("", "ollama-cloud/glm-5.2:cloud"); err != nil {
|
||||
t.Errorf("valid spec rejected without a key: %v", err)
|
||||
}
|
||||
// A comma-separated failover chain is majordomo grammar and must resolve.
|
||||
if err := Validate("k", "ollama-cloud/glm-5.2:cloud,ollama-cloud/kimi-k2.6:cloud"); err != nil {
|
||||
t.Errorf("failover chain rejected: %v", err)
|
||||
}
|
||||
for _, bad := range []string{"", " ", "nonesuch/model"} {
|
||||
if err := Validate("k", bad); err == nil {
|
||||
t.Errorf("Validate accepted %q", bad)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TestResolveReturnsAModel confirms a good spec yields a usable model handle.
|
||||
func TestResolveReturnsAModel(t *testing.T) {
|
||||
m, err := Resolve("k", "ollama-cloud/glm-5.2:cloud")
|
||||
if err != nil {
|
||||
t.Fatalf("resolve: %v", err)
|
||||
}
|
||||
if m == nil {
|
||||
t.Fatal("resolve returned a nil model with no error")
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user