The best catch was one I'd have missed: the store already has resetTransient(), a single list of ephemeral editor state, and the new railTab didn't join it — so the public garden page cleared everything except the rail. Rather than adding railTab in two places, the editor page now calls resetTransient() instead of maintaining its own parallel list, which is what let them drift in the first place. The rail auto-switch keyed off a "something is selected" boolean, so it fired on the transition into having a selection and never again. Select a bed, switch to History, select a different bed — the boolean never changed, so the inspector never came forward, breaking the constraint the whole design was built around. Now keyed off the selected ids. Closing the rail cleared the canvas selection regardless of which tab you were on, so dismissing History deselected your bed. Only the inspector is about the selection, so only closing it deselects. describeUndo said "Undone." when the server reported a complete no-op (200 with a null change set, reachable by undoing a creation whose object is already gone). That reports work that didn't happen; it now says so. relativeTime rounded, so 18 hours ago read as "yesterday" and 90 minutes as "2h ago" — rounding up into the next unit reads as a bigger gap than actually elapsed. Floors throughout. Clock skew that puts a just-written entry slightly in the future now reads "just now" rather than falling through the negative. A failed "Load older" was swallowed entirely: the button simply stopped working. It now reports the error, while the top-level alert only takes over when there is nothing on screen at all. changeCountSchema took any number. Counts come from COUNT(*) and can only be non-negative integers, so constraining them makes bad data fail loudly instead of quietly hiding an Undo button (totalChanges gates it) or rendering "1.5 beds changed". Dropped useUndo's unused isPending — the per-change-set outcome already carries it, and per-row is right anyway. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
pansy
Self-hostable garden planner: drag beds, bags, and containers onto a real-scale field, click into them to place freeform plops of plants, and zoom out to see what's planted where. Go backend + React frontend, one static binary.
🤖 This is a vibe-coded project
Essentially all of the code in pansy was written by an LLM (Claude), with a human directing the work, reviewing it, and deciding what ships. Every pull request also gets an automated adversarial review before it lands.
That's said up front because you deserve to know it before you trust pansy with anything: it hasn't been through the kind of scrutiny a hand-written, widely-used project has. Read the code before you self-host it. Back up your database. Bugs here are the ordinary kind of bugs, not a scandal — but so is the fact that nobody hand-wrote the thing.
See DESIGN.md for the architecture. Work is tracked in this repo's issues — start from the tracking epic.
Quickstart
Prerequisites: Go 1.26+, Node 20+.
Develop
Run the Go API and the Vite dev server together (Vite proxies /api → the API):
make dev
Then open http://localhost:5173. Or run the two halves in separate terminals for independent restarts:
make dev-api # Go API on :8080
make dev-web # Vite dev server on :5173
Build & run
Produce the single static binary with the web build embedded, then run it:
make build
./pansy
Open http://localhost:8080 — one process serves both the JSON API and the app.
Test
make test
Configuration
All configuration is via environment variables; every value has a default, so ./pansy runs with none set.
| Variable | Default | Description |
|---|---|---|
PANSY_PORT |
8080 |
TCP port the HTTP server listens on. |
PANSY_DB |
./pansy.db |
SQLite database file path (created if absent). |
PANSY_BASE_URL |
(empty) | Externally-visible base URL; used to derive the OIDC redirect URI. |
PANSY_REGISTRATION |
open |
open or closed — gates local self-service signup. |
PANSY_LOCAL_AUTH |
true |
Enable local password auth. Set false for pure-OIDC. |
PANSY_OIDC_ISSUER |
(empty) | OIDC issuer/discovery URL (Authentik). Enables SSO when set. |
PANSY_OIDC_CLIENT_ID |
(empty) | OIDC client ID. |
PANSY_OIDC_CLIENT_SECRET |
(empty) | OIDC client secret. |
PANSY_OIDC_BUTTON_LABEL |
Sign in with Authentik |
Label for the OIDC button on the login page. |
PANSY_TRUSTED_PROXIES |
(none) | Comma-separated proxy CIDRs/IPs to trust for client-IP resolution. |
The garden assistant reads two more. Both are read only once the assistant lands (#56); setting them earlier is harmless and setting neither leaves the assistant off.
| Variable | Default | Description |
|---|---|---|
OLLAMA_CLOUD_API_KEY |
(empty) | Ollama Cloud API key. Without it the assistant is disabled, not broken. |
PANSY_AGENT_MODEL |
ollama-cloud/glm-5.2:cloud |
Model spec, passed verbatim to majordomo.Parse — a comma-separated list is a failover chain. |
Local email/password auth is live (POST /api/v1/auth/register, /auth/login, /auth/logout, GET /auth/me, GET /auth/providers); the session is an HttpOnly cookie (Secure when PANSY_BASE_URL is https). The first account registered becomes admin, and it may register even when PANSY_REGISTRATION=closed to bootstrap the instance.
OIDC (Authentik-first) is live too: set PANSY_OIDC_ISSUER, PANSY_OIDC_CLIENT_ID, PANSY_OIDC_CLIENT_SECRET, and PANSY_BASE_URL (needed for the redirect URI). Register PANSY_BASE_URL + /api/v1/auth/oidc/callback as the redirect URI in your IdP. GET /auth/oidc/login starts an authorization-code + PKCE flow; first login provisions a user just-in-time (a matching verified email links to an existing local account instead of duplicating it). Provider discovery is lazy, so a briefly-unreachable IdP never blocks startup or local auth. Set PANSY_LOCAL_AUTH=false for pure-Authentik deployments (local register/login are then rejected and hidden from /auth/providers).
Docker & deployment
CI (.gitea/workflows/build-image.yml) builds the single-binary image and pushes it to the Gitea registry on every branch push:
| Ref | Tag |
|---|---|
main |
gitea.stevedudenhoeffer.com/steve/pansy:latest |
| any other branch | gitea.stevedudenhoeffer.com/steve/pansy:<branch-name> |
| every build | gitea.stevedudenhoeffer.com/steve/pansy:sha-<short> (immutable; use to pin) |
The image runs as a non-root user, serves on :8080, and stores the SQLite database on the /data volume. Run it directly:
docker run -d --name pansy \
-p 8080:8080 \
-v pansy-data:/data \
gitea.stevedudenhoeffer.com/steve/pansy:latest
Or as a Komodo/Compose stack:
services:
pansy:
image: gitea.stevedudenhoeffer.com/steve/pansy:${PANSY_TAG:-latest}
ports:
- "8080:8080"
volumes:
- pansy-data:/data
environment:
PANSY_BASE_URL: https://pansy.example.com
# PANSY_OIDC_ISSUER: https://auth.example.com/application/o/pansy/
# PANSY_OIDC_CLIENT_ID: ...
# PANSY_OIDC_CLIENT_SECRET: ...
# OLLAMA_CLOUD_API_KEY: ... # enables the garden assistant
restart: unless-stopped
volumes:
pansy-data:
Pin PANSY_TAG to a sha-<short> tag for reproducible deploys, or leave it at latest to track main.