Six real bugs, three of which would have broken the feature's central promise. The worst was that a failed operation threw away the history for changes that had already committed. WithChangeSet buffers HISTORY, not data — the store writes inside fn commit as they go — so discarding the buffer on error left real mutations with no change set and no way to undo them. That is exactly the situation undo exists for: an agent turn that did half a thing and then failed. Now the buffer is written, the summary says the operation failed partway, and the error is still returned. RevertChangeSet does the same for a revert that fails mid-loop. The partial state is still partial, but it is visible and undoable instead of orphaned. versionGuard falsely conflicted whenever one change set held more than one revision for the same entity — an agent turn that moves a bed and then renames it. Each inverse bumps the row's version, so from the second one on the snapshot's version no longer matched the live row and the revert flagged its own work as somebody else's edit. RevertChangeSet now tracks what it has written and the guard compares against that. ListChangeSets found "was this reverted?" with a LEFT JOIN, which emits one duplicate row per revert once a change set has been reverted more than once (undo, redo, undo again). Now a scalar subquery. Reverting an object creation cascade-deleted anything planted in that bed since, quietly. The plops were snapshotted so it was recoverable, but deleting someone's plants as a side effect of an unrelated undo should be reported. It now conflicts and leaves the bed alone. ClearObject cleared by predicate and snapshotted by a separate read, so a plop created between the two was removed with no revision to undo it by. It now clears exactly the ids it read. It also returned an error when only the post-clear re-read failed, which told the caller a clear had failed after it had already applied — inviting a retry of an applied operation. That path now logs the history gap and reports success, matching how record() treats its own write failures. RestoreObject/RestorePlanting could lose the race between the existence check and the insert and surface a raw constraint error. The revert now re-checks and reports ConflictExists, which is what that condition means. RevertChangeSet takes a source, so an agent undoing its own work is distinguishable from a person clicking undo — the whole point of the badge. Refactoring: the three revert bodies repeated a load/guard/unsnapshot/update skeleton (flagged by 3 of 5 models). They are now one generic revertEntity over a small per-type op table, so the ordering, guards and conflict reporting cannot drift apart. The API's view structs duplicated domain types that already carried every field, against the package's direct-JSON convention — dropped. intQuery moved next to the other request helpers. planRevert's comment said three passes where the code runs five. A revert where every revision is already a no-op now answers 200 rather than 201 with a null change set. Six new tests, one per bug. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
pansy
Self-hostable garden planner: drag beds, bags, and containers onto a real-scale field, click into them to place freeform plops of plants, and zoom out to see what's planted where. Go backend + React frontend, one static binary.
🤖 This is a vibe-coded project
Essentially all of the code in pansy was written by an LLM (Claude), with a human directing the work, reviewing it, and deciding what ships. Every pull request also gets an automated adversarial review before it lands.
That's said up front because you deserve to know it before you trust pansy with anything: it hasn't been through the kind of scrutiny a hand-written, widely-used project has. Read the code before you self-host it. Back up your database. Bugs here are the ordinary kind of bugs, not a scandal — but so is the fact that nobody hand-wrote the thing.
See DESIGN.md for the architecture. Work is tracked in this repo's issues — start from the tracking epic.
Quickstart
Prerequisites: Go 1.26+, Node 20+.
Develop
Run the Go API and the Vite dev server together (Vite proxies /api → the API):
make dev
Then open http://localhost:5173. Or run the two halves in separate terminals for independent restarts:
make dev-api # Go API on :8080
make dev-web # Vite dev server on :5173
Build & run
Produce the single static binary with the web build embedded, then run it:
make build
./pansy
Open http://localhost:8080 — one process serves both the JSON API and the app.
Test
make test
Configuration
All configuration is via environment variables; every value has a default, so ./pansy runs with none set.
| Variable | Default | Description |
|---|---|---|
PANSY_PORT |
8080 |
TCP port the HTTP server listens on. |
PANSY_DB |
./pansy.db |
SQLite database file path (created if absent). |
PANSY_BASE_URL |
(empty) | Externally-visible base URL; used to derive the OIDC redirect URI. |
PANSY_REGISTRATION |
open |
open or closed — gates local self-service signup. |
PANSY_LOCAL_AUTH |
true |
Enable local password auth. Set false for pure-OIDC. |
PANSY_OIDC_ISSUER |
(empty) | OIDC issuer/discovery URL (Authentik). Enables SSO when set. |
PANSY_OIDC_CLIENT_ID |
(empty) | OIDC client ID. |
PANSY_OIDC_CLIENT_SECRET |
(empty) | OIDC client secret. |
PANSY_OIDC_BUTTON_LABEL |
Sign in with Authentik |
Label for the OIDC button on the login page. |
PANSY_TRUSTED_PROXIES |
(none) | Comma-separated proxy CIDRs/IPs to trust for client-IP resolution. |
Local email/password auth is live (POST /api/v1/auth/register, /auth/login, /auth/logout, GET /auth/me, GET /auth/providers); the session is an HttpOnly cookie (Secure when PANSY_BASE_URL is https). The first account registered becomes admin, and it may register even when PANSY_REGISTRATION=closed to bootstrap the instance.
OIDC (Authentik-first) is live too: set PANSY_OIDC_ISSUER, PANSY_OIDC_CLIENT_ID, PANSY_OIDC_CLIENT_SECRET, and PANSY_BASE_URL (needed for the redirect URI). Register PANSY_BASE_URL + /api/v1/auth/oidc/callback as the redirect URI in your IdP. GET /auth/oidc/login starts an authorization-code + PKCE flow; first login provisions a user just-in-time (a matching verified email links to an existing local account instead of duplicating it). Provider discovery is lazy, so a briefly-unreachable IdP never blocks startup or local auth. Set PANSY_LOCAL_AUTH=false for pure-Authentik deployments (local register/login are then rejected and hidden from /auth/providers).
Docker & deployment
CI (.gitea/workflows/build-image.yml) builds the single-binary image and pushes it to the Gitea registry on every branch push:
| Ref | Tag |
|---|---|
main |
gitea.stevedudenhoeffer.com/steve/pansy:latest |
| any other branch | gitea.stevedudenhoeffer.com/steve/pansy:<branch-name> |
| every build | gitea.stevedudenhoeffer.com/steve/pansy:sha-<short> (immutable; use to pin) |
The image runs as a non-root user, serves on :8080, and stores the SQLite database on the /data volume. Run it directly:
docker run -d --name pansy \
-p 8080:8080 \
-v pansy-data:/data \
gitea.stevedudenhoeffer.com/steve/pansy:latest
Or as a Komodo/Compose stack:
services:
pansy:
image: gitea.stevedudenhoeffer.com/steve/pansy:${PANSY_TAG:-latest}
ports:
- "8080:8080"
volumes:
- pansy-data:/data
environment:
PANSY_BASE_URL: https://pansy.example.com
# PANSY_OIDC_ISSUER: ... # once auth (#5) lands
restart: unless-stopped
volumes:
pansy-data:
Pin PANSY_TAG to a sha-<short> tag for reproducible deploys, or leave it at latest to track main.