Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
36 lines
1.9 KiB
SQL
36 lines
1.9 KiB
SQL
-- Instance settings (#79): the first configuration that lives in the database
|
|
-- rather than the environment.
|
|
--
|
|
-- Until now every preference hung off a garden or object row; this is pansy's
|
|
-- first INSTANCE-level state. A single-row table (CHECK id = 1) is the least
|
|
-- surprising shape for "there is exactly one of these" — a key/value table would
|
|
-- invite typo'd keys and lose the column types.
|
|
--
|
|
-- Only NON-SECRET agent settings live here. OLLAMA_CLOUD_API_KEY stays in the
|
|
-- environment on purpose: a copy in SQLite would land in every backup and in the
|
|
-- blast radius of the undo history. An admin can change WHICH model runs, not
|
|
-- WHOSE account pays for it.
|
|
--
|
|
-- Both agent columns are "inherit from env unless set":
|
|
-- * agent_model = '' means fall back to PANSY_AGENT_MODEL, then the built-in
|
|
-- default. So an instance that never opens Settings behaves exactly as it
|
|
-- did before this migration, and the documented env var keeps working.
|
|
-- * agent_enabled is NULLABLE: NULL means inherit PANSY_AGENT_ENABLED's
|
|
-- behaviour (on when a key is present), 0/1 is an explicit override. A plain
|
|
-- boolean couldn't tell "admin hasn't touched this" from "admin turned it
|
|
-- off", and those must deploy differently.
|
|
--
|
|
-- version drives the same optimistic-concurrency 409 every other mutable row
|
|
-- uses, so two admins editing at once conflict rather than clobber.
|
|
CREATE TABLE instance_settings (
|
|
id INTEGER PRIMARY KEY CHECK (id = 1),
|
|
agent_model TEXT NOT NULL DEFAULT '',
|
|
agent_enabled INTEGER CHECK (agent_enabled IN (0, 1)),
|
|
version INTEGER NOT NULL DEFAULT 1,
|
|
updated_at TEXT NOT NULL DEFAULT (strftime('%Y-%m-%dT%H:%M:%SZ', 'now'))
|
|
);
|
|
|
|
-- Seed the single row so every read is a plain SELECT with no "does it exist
|
|
-- yet" branch. Inherits everything from the environment out of the box.
|
|
INSERT INTO instance_settings (id, agent_model, agent_enabled) VALUES (1, '', NULL);
|