The conversational surface, in the editor rather than on its own page. The reason is the feedback loop: watching the canvas change as the agent works IS the confirmation, which is exactly what makes "act freely without asking first" tolerable. It also means the agent never has to guess which garden you mean. Tool calls surface as they happen, in the app's own vocabulary — "Clearing a bed", "Looking up a plant" — not raw tool names or JSON. That is the difference between the panel feeling like it's doing something and feeling like it's hung, which matters because a replant makes a dozen calls over tens of seconds. An unknown tool degrades to readable words rather than showing snake_case at the user, so the client can lag the server by a tool without looking broken. The canvas refreshes as each step lands, not just at the end. Refreshing only on completion would put the whole point of siting the chat here — watching it work — behind the same wait that streaming exists to remove. Undo sits on the turn itself, so the common case never involves opening the History panel. It uses #49's useUndo, not a second implementation, which meant giving that hook an UndoTarget: the chat knows a turn's change set id but not its tally, and fabricating counts to satisfy the type would have produced a confidently wrong "1 of 1 changes undone". describeUndo now says "Partly undone" when it has no denominator rather than inventing one. The panel is only offered when the instance actually has the assistant configured, via a new /capabilities read. The routes 404 without a key, so without this the client would have to probe for a 404 to find out — and a tab that opens onto an apology is worse than no tab. Streaming is hand-rolled over fetch rather than EventSource, which can only issue GETs and this needs a POST body. The wire format is still SSE, so a proxy that understands it doesn't buffer and the server wouldn't change if EventSource became viable. Partial frames are buffered across chunks and a malformed frame is skipped rather than killing a working stream. Errors read as sentences, and as different sentences: a permission refusal, a timeout and a model failure want different reactions. Every failure path refreshes, because something may have landed before it failed — and says where to look for it. Closes #57 Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
pansy
Self-hostable garden planner: drag beds, bags, and containers onto a real-scale field, click into them to place freeform plops of plants, and zoom out to see what's planted where. Go backend + React frontend, one static binary.
🤖 This is a vibe-coded project
Essentially all of the code in pansy was written by an LLM (Claude), with a human directing the work, reviewing it, and deciding what ships. Every pull request also gets an automated adversarial review before it lands.
That's said up front because you deserve to know it before you trust pansy with anything: it hasn't been through the kind of scrutiny a hand-written, widely-used project has. Read the code before you self-host it. Back up your database. Bugs here are the ordinary kind of bugs, not a scandal — but so is the fact that nobody hand-wrote the thing.
See DESIGN.md for the architecture. Work is tracked in this repo's issues — start from the tracking epic.
Quickstart
Prerequisites: Go 1.26+, Node 20+.
Develop
Run the Go API and the Vite dev server together (Vite proxies /api → the API):
make dev
Then open http://localhost:5173. Or run the two halves in separate terminals for independent restarts:
make dev-api # Go API on :8080
make dev-web # Vite dev server on :5173
Build & run
Produce the single static binary with the web build embedded, then run it:
make build
./pansy
Open http://localhost:8080 — one process serves both the JSON API and the app.
Test
make test
Configuration
All configuration is via environment variables; every value has a default, so ./pansy runs with none set.
| Variable | Default | Description |
|---|---|---|
PANSY_PORT |
8080 |
TCP port the HTTP server listens on. |
PANSY_DB |
./pansy.db |
SQLite database file path (created if absent). |
PANSY_BASE_URL |
(empty) | Externally-visible base URL; used to derive the OIDC redirect URI. |
PANSY_REGISTRATION |
open |
open or closed — gates local self-service signup. |
PANSY_LOCAL_AUTH |
true |
Enable local password auth. Set false for pure-OIDC. |
PANSY_OIDC_ISSUER |
(empty) | OIDC issuer/discovery URL (Authentik). Enables SSO when set. |
PANSY_OIDC_CLIENT_ID |
(empty) | OIDC client ID. |
PANSY_OIDC_CLIENT_SECRET |
(empty) | OIDC client secret. |
PANSY_OIDC_BUTTON_LABEL |
Sign in with Authentik |
Label for the OIDC button on the login page. |
PANSY_TRUSTED_PROXIES |
(none) | Comma-separated proxy CIDRs/IPs to trust for client-IP resolution. |
The garden assistant reads three more. Setting none of them leaves the assistant off; the app runs exactly as it does without it.
| Variable | Default | Description |
|---|---|---|
OLLAMA_CLOUD_API_KEY |
(empty) | Ollama Cloud API key. Without it the assistant is disabled, not broken — the chat routes simply aren't registered. |
PANSY_AGENT_MODEL |
ollama-cloud/glm-5.2:cloud |
Model spec, passed verbatim to majordomo.Parse — a comma-separated list is a failover chain, e.g. ollama-cloud/glm-5.2:cloud,ollama-cloud/kimi-k2.6:cloud. |
PANSY_AGENT_ENABLED |
on when a key is present | Turns the assistant off without removing the key. |
The assistant acts without asking first, which is only reasonable because every turn is one undoable change set — see the History panel in the editor.
Local email/password auth is live (POST /api/v1/auth/register, /auth/login, /auth/logout, GET /auth/me, GET /auth/providers); the session is an HttpOnly cookie (Secure when PANSY_BASE_URL is https). The first account registered becomes admin, and it may register even when PANSY_REGISTRATION=closed to bootstrap the instance.
OIDC (Authentik-first) is live too: set PANSY_OIDC_ISSUER, PANSY_OIDC_CLIENT_ID, PANSY_OIDC_CLIENT_SECRET, and PANSY_BASE_URL (needed for the redirect URI). Register PANSY_BASE_URL + /api/v1/auth/oidc/callback as the redirect URI in your IdP. GET /auth/oidc/login starts an authorization-code + PKCE flow; first login provisions a user just-in-time (a matching verified email links to an existing local account instead of duplicating it). Provider discovery is lazy, so a briefly-unreachable IdP never blocks startup or local auth. Set PANSY_LOCAL_AUTH=false for pure-Authentik deployments (local register/login are then rejected and hidden from /auth/providers).
Docker & deployment
CI (.gitea/workflows/build-image.yml) builds the single-binary image and pushes it to the Gitea registry on every branch push:
| Ref | Tag |
|---|---|
main |
gitea.stevedudenhoeffer.com/steve/pansy:latest |
| any other branch | gitea.stevedudenhoeffer.com/steve/pansy:<branch-name> |
| every build | gitea.stevedudenhoeffer.com/steve/pansy:sha-<short> (immutable; use to pin) |
The image runs as a non-root user, serves on :8080, and stores the SQLite database on the /data volume. Run it directly:
docker run -d --name pansy \
-p 8080:8080 \
-v pansy-data:/data \
gitea.stevedudenhoeffer.com/steve/pansy:latest
Or as a Komodo/Compose stack:
services:
pansy:
image: gitea.stevedudenhoeffer.com/steve/pansy:${PANSY_TAG:-latest}
ports:
- "8080:8080"
volumes:
- pansy-data:/data
environment:
PANSY_BASE_URL: https://pansy.example.com
# PANSY_OIDC_ISSUER: https://auth.example.com/application/o/pansy/
# PANSY_OIDC_CLIENT_ID: ...
# PANSY_OIDC_CLIENT_SECRET: ...
# OLLAMA_CLOUD_API_KEY: ... # enables the garden assistant
restart: unless-stopped
volumes:
pansy-data:
Pin PANSY_TAG to a sha-<short> tag for reproducible deploys, or leave it at latest to track main.