Moves the agent model out of env-only config into an admin-editable Settings
section, and enforces is_admin for the first time — it has been in the schema
since migration 0001, plumbed to the client, and checked nowhere.
Backend:
- Migration 0010: instance_settings, a single-row (CHECK id=1) table — pansy's
first instance-level state. Holds agent_model ('' = inherit env) and
agent_enabled (NULL = inherit env), version-guarded like every mutable row.
SECRETS STAY IN ENV: OLLAMA_CLOUD_API_KEY is never stored here.
- requireAdmin at the service seam (authoritative) plus a cheap middleware
early-403. Non-admin gets 403, not 404 — settings existence isn't masked.
- EffectiveAgent resolves DB-over-env (model, enabled); key always from env.
- The live Runner is hot-swapped, not built once. agentHolder holds it behind
an atomic.Pointer; the chat routes are now registered UNCONDITIONALLY and
nil-check agent.get(), so a settings change turns the assistant on/off/onto a
new model with no restart and no race against in-flight readers. /capabilities
reads the pointer, so it reports what's live, not what booted.
- internal/agentmodel is a new leaf package holding the one place that knows how
to turn a spec into a model. Both agent (to run) and service (to validate a
spec before storing it) import it; it can't live in agent, which imports
service. Settings PATCH validates the spec via Parse, so a typo is a 400 now
rather than a broken assistant on the next turn.
Frontend:
- /settings route (admin guard), a Settings page (model field, tri-state
enabled, live status), nav link shown only to admins.
- useCapabilities drops staleTime:Infinity — the assistant can now change under
a running page — and the settings save invalidates it.
Contract change: chat routes always exist, so "assistant off" is a runtime 503
+ capabilities:false, not a missing route. Updated the test that asserted the
old shape.
Verified live against the built binary: disable flips capabilities to false and
logs it; re-enable with a new model swaps it back; a bad spec is rejected 400;
the setting persists across a restart. Swap is race-clean under `go test -race`.
Docs: README (precedence + key-stays-in-env), DESIGN (decision + routes),
CLAUDE (don't re-add conditional route registration; key never in the DB).
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_01H3zbym8Doka2d7D48maSgZ
58 lines
2.3 KiB
Go
58 lines
2.3 KiB
Go
// Package agentmodel holds the ONE place that knows how pansy turns a model spec
|
|
// into a majordomo model: which provider to register and under which token.
|
|
//
|
|
// It exists as a leaf so both internal/agent (which builds the run loop) and
|
|
// internal/service (which validates a spec before storing it as a setting) can
|
|
// share that knowledge without an import cycle — agent imports service, so the
|
|
// shared bit can live in neither of them.
|
|
package agentmodel
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"strings"
|
|
|
|
"gitea.stevedudenhoeffer.com/steve/majordomo"
|
|
"gitea.stevedudenhoeffer.com/steve/majordomo/llm"
|
|
"gitea.stevedudenhoeffer.com/steve/majordomo/provider/ollama"
|
|
)
|
|
|
|
// registry builds the private majordomo registry pansy uses.
|
|
//
|
|
// Private, not the package-level default: pansy passes the key it was configured
|
|
// with rather than depending on ambient environment, and majordomo's own
|
|
// ollama-cloud preset reads OLLAMA_API_KEY while pansy (like gadfly) is
|
|
// configured with OLLAMA_CLOUD_API_KEY. Registering the provider explicitly
|
|
// makes that bridge visible instead of a mysterious empty token.
|
|
func registry(apiKey string) *majordomo.Registry {
|
|
reg := majordomo.New()
|
|
reg.RegisterProvider(ollama.Cloud(ollama.WithToken(apiKey)))
|
|
return reg
|
|
}
|
|
|
|
// Resolve parses a model spec against pansy's registry into a live model. The
|
|
// spec goes to Parse VERBATIM — the grammar, including comma-separated failover
|
|
// chains, is majordomo's, and re-implementing any of it here would only mean two
|
|
// places to update when it grows.
|
|
func Resolve(apiKey, spec string) (llm.Model, error) {
|
|
if strings.TrimSpace(spec) == "" {
|
|
return nil, errors.New("agentmodel: empty model spec")
|
|
}
|
|
m, err := registry(apiKey).Parse(spec)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("agentmodel: resolve %q: %w", spec, err)
|
|
}
|
|
return m, nil
|
|
}
|
|
|
|
// Validate reports whether a spec resolves, without building anything the caller
|
|
// keeps — the cheap, deterministic check a settings save runs to reject a typo.
|
|
//
|
|
// It does NOT make a live call, so it needs no working key and won't catch a
|
|
// model that is merely absent upstream; that surfaces on first use. Parse
|
|
// resolving (known provider, well-formed spec) is the half worth doing eagerly.
|
|
func Validate(apiKey, spec string) error {
|
|
_, err := Resolve(apiKey, spec)
|
|
return err
|
|
}
|