Files
pansy/README.md
T
steveandClaude Opus 4.8 41c28592a2
Gadfly review (reusable) / review (pull_request) Failing after 30s
Adversarial Review (Gadfly) / review (pull_request) Failing after 30s
Build image / build-and-push (push) Successful in 14s
Admin-gated Settings: runtime model selection, enforce is_admin (#79)
Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.

Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
  first instance-level state. Holds agent_model ('' = inherit env) and
  agent_enabled (NULL = inherit env), version-guarded like every mutable row.
  SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
  early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
  an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
  nil-check agent.get(), so a settings change turns the assistant on/off/onto a
  new model with no restart and no race against in-flight readers. /capabilities
  reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
  to turn a spec into a model. Both agent (to run) and service (to validate a
  spec before storing it) import it; it can't live in agent, which imports
  service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
  rather than a broken assistant on the next turn.

Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
  enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
  a running page — and the settings save invalidates it.

Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.

Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.

Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
2026-07-21 20:27:36 -04:00

7.6 KiB

pansy

Self-hostable garden planner: drag beds, bags, and containers onto a real-scale field, click into them to place freeform plops of plants, and zoom out to see what's planted where. Go backend + React frontend, one static binary.

🤖 This is a vibe-coded project

Essentially all of the code in pansy was written by an LLM (Claude), with a human directing the work, reviewing it, and deciding what ships. Every pull request also gets an automated adversarial review before it lands.

That's said up front because you deserve to know it before you trust pansy with anything: it hasn't been through the kind of scrutiny a hand-written, widely-used project has. Read the code before you self-host it. Back up your database. Bugs here are the ordinary kind of bugs, not a scandal — but so is the fact that nobody hand-wrote the thing.

See DESIGN.md for the architecture. Work is tracked in this repo's issues — start from the tracking epic.

Quickstart

Prerequisites: Go 1.26+, Node 20+.

Develop

Run the Go API and the Vite dev server together (Vite proxies /api → the API):

make dev

Then open http://localhost:5173. Or run the two halves in separate terminals for independent restarts:

make dev-api   # Go API on :8080
make dev-web   # Vite dev server on :5173

Build & run

Produce the single static binary with the web build embedded, then run it:

make build
./pansy

Open http://localhost:8080 — one process serves both the JSON API and the app.

Test

make test

Configuration

All configuration is via environment variables; every value has a default, so ./pansy runs with none set.

Variable Default Description
PANSY_PORT 8080 TCP port the HTTP server listens on.
PANSY_DB ./pansy.db SQLite database file path (created if absent).
PANSY_BASE_URL (empty) Externally-visible base URL; used to derive the OIDC redirect URI.
PANSY_REGISTRATION open open or closed — gates local self-service signup.
PANSY_LOCAL_AUTH true Enable local password auth. Set false for pure-OIDC.
PANSY_OIDC_ISSUER (empty) OIDC issuer/discovery URL (Authentik). Enables SSO when set.
PANSY_OIDC_CLIENT_ID (empty) OIDC client ID.
PANSY_OIDC_CLIENT_SECRET (empty) OIDC client secret.
PANSY_OIDC_BUTTON_LABEL Sign in with Authentik Label for the OIDC button on the login page.
PANSY_TRUSTED_PROXIES (none) Comma-separated proxy CIDRs/IPs to trust for client-IP resolution.

The garden assistant reads three more. Setting none of them leaves the assistant off; the app runs exactly as it does without it.

Variable Default Description
OLLAMA_CLOUD_API_KEY (empty) Ollama Cloud API key. Without it the assistant is off, not broken. This is the one agent value that stays in the environment — it is never stored in the database or editable in Settings.
PANSY_AGENT_MODEL ollama-cloud/glm-5.2:cloud Default model spec, passed verbatim to majordomo.Parse — a comma-separated list is a failover chain, e.g. ollama-cloud/glm-5.2:cloud,ollama-cloud/kimi-k2.6:cloud. An admin can override this per-instance in Settings without a redeploy; a blank Settings value inherits this.
PANSY_AGENT_ENABLED on when a key is present Default on/off for the assistant. Also overridable in Settings (which can inherit this default).

The model and enabled flag can be changed at runtime by an admin under Settings (the gear appears in the nav for admins) — the change swaps the live assistant with no restart. The env vars above are the defaults an untouched instance uses, and the API key is intentionally not among the runtime-editable settings: a secret in the database would land in every backup. Precedence for the model and enabled flag is Settings value, if set → env var → built-in default.

The assistant acts without asking first, which is only reasonable because every turn is one undoable change set — see the History panel in the editor.

If you set the key and the assistant still doesn't appear, check that the variable reaches the container, not just your orchestrator's stack config — Compose needs it listed under the service's environment:. pansy logs why the assistant is off at startup, and Settings shows the same status (a key present, the resolved model, and whether it's actually running).

Local email/password auth is live (POST /api/v1/auth/register, /auth/login, /auth/logout, GET /auth/me, GET /auth/providers); the session is an HttpOnly cookie (Secure when PANSY_BASE_URL is https). The first account registered becomes admin, and it may register even when PANSY_REGISTRATION=closed to bootstrap the instance.

OIDC (Authentik-first) is live too: set PANSY_OIDC_ISSUER, PANSY_OIDC_CLIENT_ID, PANSY_OIDC_CLIENT_SECRET, and PANSY_BASE_URL (needed for the redirect URI). Register PANSY_BASE_URL + /api/v1/auth/oidc/callback as the redirect URI in your IdP. GET /auth/oidc/login starts an authorization-code + PKCE flow; first login provisions a user just-in-time (a matching verified email links to an existing local account instead of duplicating it). Provider discovery is lazy, so a briefly-unreachable IdP never blocks startup or local auth. Set PANSY_LOCAL_AUTH=false for pure-Authentik deployments (local register/login are then rejected and hidden from /auth/providers).

Docker & deployment

CI (.gitea/workflows/build-image.yml) builds the single-binary image and pushes it to the Gitea registry on every branch push:

Ref Tag
main gitea.stevedudenhoeffer.com/steve/pansy:latest
any other branch gitea.stevedudenhoeffer.com/steve/pansy:<branch-name>
every build gitea.stevedudenhoeffer.com/steve/pansy:sha-<short> (immutable; use to pin)

The image runs as a non-root user, serves on :8080, and stores the SQLite database on the /data volume. Run it directly:

docker run -d --name pansy \
  -p 8080:8080 \
  -v pansy-data:/data \
  gitea.stevedudenhoeffer.com/steve/pansy:latest

Or as a Komodo/Compose stack:

services:
  pansy:
    image: gitea.stevedudenhoeffer.com/steve/pansy:${PANSY_TAG:-latest}
    ports:
      - "8080:8080"
    volumes:
      - pansy-data:/data
    environment:
      PANSY_BASE_URL: https://pansy.example.com
      # PANSY_OIDC_ISSUER: https://auth.example.com/application/o/pansy/
      # PANSY_OIDC_CLIENT_ID: ...
      # PANSY_OIDC_CLIENT_SECRET: ...
      # OLLAMA_CLOUD_API_KEY: ${OLLAMA_CLOUD_API_KEY}   # enables the garden assistant
      # PANSY_AGENT_MODEL: ollama-cloud/glm-5.2:cloud
    restart: unless-stopped
volumes:
  pansy-data:

Pin PANSY_TAG to a sha-<short> tag for reproducible deploys, or leave it at latest to track main.