Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
126 lines
7.6 KiB
Markdown
126 lines
7.6 KiB
Markdown
# pansy
|
|
|
|
Self-hostable garden planner: drag beds, bags, and containers onto a real-scale field, click into them to place freeform plops of plants, and zoom out to see what's planted where. Go backend + React frontend, one static binary.
|
|
|
|
> ### 🤖 This is a vibe-coded project
|
|
>
|
|
> **Essentially all of the code in pansy was written by an LLM** (Claude), with a human directing the work, reviewing it, and deciding what ships. Every pull request also gets an automated adversarial review before it lands.
|
|
>
|
|
> That's said up front because you deserve to know it before you trust pansy with anything: it hasn't been through the kind of scrutiny a hand-written, widely-used project has. Read the code before you self-host it. Back up your database. Bugs here are the ordinary kind of bugs, not a scandal — but so is the fact that nobody hand-wrote the thing.
|
|
|
|
See [DESIGN.md](DESIGN.md) for the architecture. Work is tracked in this repo's issues — start from the tracking epic.
|
|
|
|
## Quickstart
|
|
|
|
**Prerequisites:** Go 1.26+, Node 20+.
|
|
|
|
### Develop
|
|
|
|
Run the Go API and the Vite dev server together (Vite proxies `/api` → the API):
|
|
|
|
```sh
|
|
make dev
|
|
```
|
|
|
|
Then open http://localhost:5173. Or run the two halves in separate terminals for independent restarts:
|
|
|
|
```sh
|
|
make dev-api # Go API on :8080
|
|
make dev-web # Vite dev server on :5173
|
|
```
|
|
|
|
### Build & run
|
|
|
|
Produce the single static binary with the web build embedded, then run it:
|
|
|
|
```sh
|
|
make build
|
|
./pansy
|
|
```
|
|
|
|
Open http://localhost:8080 — one process serves both the JSON API and the app.
|
|
|
|
### Test
|
|
|
|
```sh
|
|
make test
|
|
```
|
|
|
|
## Configuration
|
|
|
|
All configuration is via environment variables; every value has a default, so `./pansy` runs with none set.
|
|
|
|
| Variable | Default | Description |
|
|
| ------------------------- | ------------------ | ------------------------------------------------------------------ |
|
|
| `PANSY_PORT` | `8080` | TCP port the HTTP server listens on. |
|
|
| `PANSY_DB` | `./pansy.db` | SQLite database file path (created if absent). |
|
|
| `PANSY_BASE_URL` | *(empty)* | Externally-visible base URL; used to derive the OIDC redirect URI. |
|
|
| `PANSY_REGISTRATION` | `open` | `open` or `closed` — gates local self-service signup. |
|
|
| `PANSY_LOCAL_AUTH` | `true` | Enable local password auth. Set `false` for pure-OIDC. |
|
|
| `PANSY_OIDC_ISSUER` | *(empty)* | OIDC issuer/discovery URL (Authentik). Enables SSO when set. |
|
|
| `PANSY_OIDC_CLIENT_ID` | *(empty)* | OIDC client ID. |
|
|
| `PANSY_OIDC_CLIENT_SECRET`| *(empty)* | OIDC client secret. |
|
|
| `PANSY_OIDC_BUTTON_LABEL` | `Sign in with Authentik` | Label for the OIDC button on the login page. |
|
|
| `PANSY_TRUSTED_PROXIES` | *(none)* | Comma-separated proxy CIDRs/IPs to trust for client-IP resolution. |
|
|
|
|
The garden assistant reads three more. Setting none of them leaves the assistant off; the app runs exactly as it does without it.
|
|
|
|
| Variable | Default | Description |
|
|
| ----------------------- | ------------------------------ | --------------------------------------------------------------------------- |
|
|
| `OLLAMA_CLOUD_API_KEY` | *(empty)* | Ollama Cloud API key. Without it the assistant is off, not broken. This is the one agent value that stays in the environment — it is **never** stored in the database or editable in Settings. |
|
|
| `PANSY_AGENT_MODEL` | `ollama-cloud/glm-5.2:cloud` | Default model spec, passed verbatim to `majordomo.Parse` — a comma-separated list is a failover chain, e.g. `ollama-cloud/glm-5.2:cloud,ollama-cloud/kimi-k2.6:cloud`. An admin can override this per-instance in **Settings** without a redeploy; a blank Settings value inherits this. |
|
|
| `PANSY_AGENT_ENABLED` | on when a key is present | Default on/off for the assistant. Also overridable in Settings (which can inherit this default). |
|
|
|
|
The model and enabled flag can be changed at runtime by an admin under **Settings** (the gear appears in the nav for admins) — the change swaps the live assistant with no restart. The env vars above are the defaults an untouched instance uses, and the API key is intentionally not among the runtime-editable settings: a secret in the database would land in every backup. Precedence for the model and enabled flag is **Settings value, if set → env var → built-in default**.
|
|
|
|
The assistant acts without asking first, which is only reasonable because every turn is one undoable change set — see the History panel in the editor.
|
|
|
|
**If you set the key and the assistant still doesn't appear**, check that the variable reaches the *container*, not just your orchestrator's stack config — Compose needs it listed under the service's `environment:`. pansy logs why the assistant is off at startup, and Settings shows the same status (a key present, the resolved model, and whether it's actually running).
|
|
|
|
Local email/password auth is live (`POST /api/v1/auth/register`, `/auth/login`, `/auth/logout`, `GET /auth/me`, `GET /auth/providers`); the session is an HttpOnly cookie (`Secure` when `PANSY_BASE_URL` is https). The first account registered becomes admin, and it may register even when `PANSY_REGISTRATION=closed` to bootstrap the instance.
|
|
|
|
OIDC (Authentik-first) is live too: set `PANSY_OIDC_ISSUER`, `PANSY_OIDC_CLIENT_ID`, `PANSY_OIDC_CLIENT_SECRET`, and `PANSY_BASE_URL` (needed for the redirect URI). Register `PANSY_BASE_URL` + `/api/v1/auth/oidc/callback` as the redirect URI in your IdP. `GET /auth/oidc/login` starts an authorization-code + PKCE flow; first login provisions a user just-in-time (a matching *verified* email links to an existing local account instead of duplicating it). Provider discovery is lazy, so a briefly-unreachable IdP never blocks startup or local auth. Set `PANSY_LOCAL_AUTH=false` for pure-Authentik deployments (local register/login are then rejected and hidden from `/auth/providers`).
|
|
|
|
## Docker & deployment
|
|
|
|
CI (`.gitea/workflows/build-image.yml`) builds the single-binary image and pushes it to the Gitea registry on every branch push:
|
|
|
|
| Ref | Tag |
|
|
| --- | --- |
|
|
| `main` | `gitea.stevedudenhoeffer.com/steve/pansy:latest` |
|
|
| any other branch | `gitea.stevedudenhoeffer.com/steve/pansy:<branch-name>` |
|
|
| every build | `gitea.stevedudenhoeffer.com/steve/pansy:sha-<short>` (immutable; use to pin) |
|
|
|
|
The image runs as a non-root user, serves on `:8080`, and stores the SQLite database on the `/data` volume. Run it directly:
|
|
|
|
```sh
|
|
docker run -d --name pansy \
|
|
-p 8080:8080 \
|
|
-v pansy-data:/data \
|
|
gitea.stevedudenhoeffer.com/steve/pansy:latest
|
|
```
|
|
|
|
Or as a Komodo/Compose stack:
|
|
|
|
```yaml
|
|
services:
|
|
pansy:
|
|
image: gitea.stevedudenhoeffer.com/steve/pansy:${PANSY_TAG:-latest}
|
|
ports:
|
|
- "8080:8080"
|
|
volumes:
|
|
- pansy-data:/data
|
|
environment:
|
|
PANSY_BASE_URL: https://pansy.example.com
|
|
# PANSY_OIDC_ISSUER: https://auth.example.com/application/o/pansy/
|
|
# PANSY_OIDC_CLIENT_ID: ...
|
|
# PANSY_OIDC_CLIENT_SECRET: ...
|
|
# OLLAMA_CLOUD_API_KEY: ${OLLAMA_CLOUD_API_KEY} # enables the garden assistant
|
|
# PANSY_AGENT_MODEL: ollama-cloud/glm-5.2:cloud
|
|
restart: unless-stopped
|
|
volumes:
|
|
pansy-data:
|
|
```
|
|
|
|
Pin `PANSY_TAG` to a `sha-<short>` tag for reproducible deploys, or leave it at `latest` to track `main`.
|