Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,22 @@ AGENTS_API_PROXY_TOKEN_FILE=~/.parsar/agents-api/web-token
# together with AGENTS_API_PROXY_TOKEN_FILE.
# AGENTS_API_PROXY_TOKEN=

# Public, non-secret opt-in for the reviewed Codex self_hosted Session profile.
# Leave unset unless Core execution, its executor registry, and executor origin
# are configured. This flag is presentation policy, not capability discovery.
# AGENTS_CORE_WEB_SELF_HOSTED_SESSIONS=1

# Optional local-only Docker connection recipe. This renders a copyable command;
# it never gives the browser Docker access or reads the credential file. Every
# value below is compiled into the browser bundle, so values must be non-secret.
# Enable only for the matching operator-controlled local stack.
# AGENTS_CORE_WEB_DOCKER_GUIDE=1
# AGENTS_CORE_WEB_DOCKER_IMAGE=agents-core-web-executor:2b34ea46-codex-0.153.4
# AGENTS_CORE_WEB_DOCKER_API_CONTAINER=agents-core-web-api
# AGENTS_CORE_WEB_DOCKER_USER=501:20
# AGENTS_CORE_WEB_DOCKER_CREDENTIALS_HOME_PATH=.parsar/agents-api-web-smoke/executor-key.json
# AGENTS_CORE_WEB_DOCKER_RUNTIME_HOME_PATH=.parsar/agents-api-web-smoke/executors

# Public, non-secret suggestions shown by the Create Agent model picker. The
# first entry is the default unless VITE_AGENT_DEFAULT_MODEL overrides it. These
# do not claim live availability; the connected runtime remains authoritative.
Expand Down
48 changes: 42 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ persistence, scheduling, and execution; this project does not embed or reimpleme

- Create, view, edit, and delete reusable Agent configurations.
- Start durable Sessions and inspect their saved Items.
- Optionally create a Codex `self_hosted` Session and follow the connection state
of an operator-managed Linux executor.
- Follow live progress over SSE and recover persisted output after reconnecting.
- Cancel active work and return function results or errors.
- Use the same Web client with Parsar Core or another proven-compatible Core.
Expand Down Expand Up @@ -67,12 +69,25 @@ AGENTS_API_PROXY_TARGET=http://127.0.0.1:8091
AGENTS_API_PROXY_TOKEN_FILE=/absolute/private/path/to/web-token
```

Restart `pnpm dev` after changing them. Keep credentials server-side. A direct
Core URL in the connection dialog is only for a compatible Core that explicitly
allows the Web origin, methods, and headers through CORS.
Self-hosted Session creation is a public, non-secret operator opt-in and is hidden
by default. Enable it only for a reviewed Codex Core deployment whose executor
registry and externally reachable executor origin are configured:

```dotenv
AGENTS_CORE_WEB_SELF_HOSTED_SESSIONS=1
```

This flag is read when Vite starts or builds the Web. It exposes the supported
Session creation form; it does not probe Core capabilities or prove that an
executor, native runtime, model, or provider is ready. Restart `pnpm dev` after
changing it. Never place an executor key or any other credential in this variable.

Keep credentials server-side. A direct Core URL in the connection dialog is only
for a compatible Core that explicitly allows the Web origin, methods, and headers
through CORS.

Do not have a Core running yet? Use the immutable
[current Parsar setup guide](https://github.com/MiniMax-AI-Dev/parsar/blob/d91ba48ac6c49cfdf6f08d7687b9be76ba6d53ee/services/agents-api/README.md#standalone-http-service).
[current Parsar setup guide](https://github.com/MiniMax-AI-Dev/parsar/blob/2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e/services/agents-api/README.md#standalone-http-service).
The repository's [legacy Web connection runbook](docs/core-connection.md) is pinned
to the older revision stated at its top; revalidate its PostgreSQL, caller-key,
device, daemon, native-harness, `CODEX_HOME`, verification, and shutdown steps before
Expand All @@ -81,10 +96,27 @@ applying them to a newer Core.
## First use

1. Open **Agents** and create an Agent with a name, instructions, and model ID.
2. Review, edit, or delete the saved Agent, or start a Session from it.
2. Review, edit, or delete the saved Agent, or start a Session from it. The default
uses no Environment.
3. Open **Sessions**, select the Session, and send a message.
4. Follow live Items, cancel active work, or return a requested function result.

When the operator opt-in is enabled, **Start Session** also offers **Self-hosted**.
Its absolute Workspace path is on the executor host, not in the browser, Web server,
or `parsar-daemon` container. After Core creates the idle Session, Web can show a
launcher template built from that Session's Environment ID and executor origin. The
operator-issued executor credential file stays outside Web, and the launcher itself
runs on caller-managed Linux executor compute. See
[Connecting Agent Core](docs/core-connection.md#optional-self-hosted-session-creation)
for the exact boundary.

For the reviewed local loopback stack, an operator can additionally enable the
default-off `AGENTS_CORE_WEB_DOCKER_GUIDE=1` profile and its required non-secret
`AGENTS_CORE_WEB_DOCKER_*` settings from `.env.example`. The connection panel then
offers a copyable Docker command alongside the native launcher. Web still never
reads the credential file or talks to Docker, and running the command can release
already queued paid input.

The model ID must be supported by the connected execution runtime. Core currently
has no model-catalog endpoint, so Web suggestions are editable hints rather than
availability guarantees. Successfully saving an Agent proves configuration storage,
Expand All @@ -104,6 +136,9 @@ flowchart LR
Core, `parsar-daemon`, and native Codex/Claude execution adapters. This repository
owns only the open Web experience and `@agents-core-web/agents-client`. The browser
connects to the Core protocol; it never uses the daemon WebSocket as its API URL.
For `self_hosted`, a separate operator-managed Linux executor connects to Core with
its own credential and runs commands in its own Workspace; neither Web nor the daemon
container becomes that Environment.

See [Architecture](docs/architecture.md) for the full component and trust boundaries.

Expand All @@ -115,6 +150,7 @@ See [Architecture](docs/architecture.md) for the full component and trust bounda
| `401 invalid_api_key` | The plaintext caller bearer must match the current Core key binding |
| `503 execution_unavailable` / `Execution is not enabled` | Core rejected execution; inspect its safe error plus runtime and ownership state. A worker, executor, or daemon may be unconfigured or disconnected, or an execution lease may have been lost |
| Agent saves but its model fails | Use a model ID and provider credential supported by the connected runtime |
| Self-hosted option is hidden | Set the non-secret `AGENTS_CORE_WEB_SELF_HOSTED_SESSIONS=1` operator flag and restart/rebuild Web only after the connected Codex Core and executor path have been reviewed |

`/healthz` proves HTTP liveness only, not chat readiness. Check durable Core state and
the current pinned Parsar guide before retrying an uncertain request; the
Expand All @@ -123,7 +159,7 @@ historical context only.

## Documentation

- [Current Parsar Core setup](https://github.com/MiniMax-AI-Dev/parsar/blob/d91ba48ac6c49cfdf6f08d7687b9be76ba6d53ee/services/agents-api/README.md#standalone-http-service) — immutable current upstream guide
- [Current Parsar Core setup](https://github.com/MiniMax-AI-Dev/parsar/blob/2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e/services/agents-api/README.md#standalone-http-service) — immutable current upstream guide
- [Legacy Web connection runbook](docs/core-connection.md) — historical `0438880` snapshot; revalidate before use
- [Protocol coverage](docs/protocol-coverage.md) — exact supported API surface
- [Architecture](docs/architecture.md) — ownership, runtime, and trust boundaries
Expand Down
27 changes: 25 additions & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ TypeScript 客户端。鉴权、持久化、调度和执行仍由 Core 负责;

- 创建、查看、编辑和删除可复用的 Agent 配置。
- 启动持久化 Session,并查看其中保存的 Item。
- 可选创建 Codex `self_hosted` Session,并查看运维方管理的 Linux executor 连接状态。
- 通过 SSE 查看实时进度,并在重连后恢复已持久化的输出。
- 取消正在执行的任务,并回传函数执行结果或错误。
- 使用同一个 Web 客户端连接 Parsar Core 或其他经验证兼容的 Core。
Expand Down Expand Up @@ -67,11 +68,21 @@ AGENTS_API_PROXY_TARGET=http://127.0.0.1:8091
AGENTS_API_PROXY_TOKEN_FILE=/absolute/private/path/to/web-token
```

Self-hosted Session 创建是默认隐藏的非秘密运维开关。只有已经核对 Codex Core、
executor registry 和 executor origin 的部署才应启用:

```dotenv
AGENTS_CORE_WEB_SELF_HOSTED_SESSIONS=1
```

该开关只暴露已支持的表单,不会探测 Core 能力,也不能证明 executor、原生运行时、
模型或提供商已就绪。不得在其中放入 executor key 或其他凭据。

修改后重启 `pnpm dev`。凭据应保留在服务端。只有兼容 Core 通过 CORS
明确允许 Web 的源、方法和请求头时,才能在连接对话框中使用 Core 直连 URL。

还没有运行中的 Core?请使用不可变的
[当前 Parsar 配置指南](https://github.com/MiniMax-AI-Dev/parsar/blob/d91ba48ac6c49cfdf6f08d7687b9be76ba6d53ee/services/agents-api/README.md#standalone-http-service)。
[当前 Parsar 配置指南](https://github.com/MiniMax-AI-Dev/parsar/blob/2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e/services/agents-api/README.md#standalone-http-service)。
仓库内的[旧版 Web 连接手册](docs/core-connection.md)固定在文首标注的旧 revision;
将其中 PostgreSQL、调用方凭据、执行设备、daemon、原生执行适配层(harness)、
`CODEX_HOME`、验证和停止流程用于更新版 Core 前必须重新核对。
Expand All @@ -83,6 +94,17 @@ AGENTS_API_PROXY_TOKEN_FILE=/absolute/private/path/to/web-token
3. 打开 **Sessions**,选择 Session 并发送消息。
4. 查看实时 Item、取消正在执行的任务,或回传请求的函数结果。

启用运维开关后,**Start Session** 还会提供 **Self-hosted**。Workspace 是 executor
主机或容器中的绝对路径,不是浏览器、Web 服务或 daemon 容器的目录。Web 只展示
Core 返回的 Environment ID、executor origin、连接状态和安全 launcher 模板;
运维方签发的 executor credential 文件始终留在 Web 之外。完整边界见
[连接 Agent Core](docs/core-connection.md#optional-self-hosted-session-creation)。

对于已核对的本地 loopback 栈,还可以配置 `.env.example` 中默认关闭的
`AGENTS_CORE_WEB_DOCKER_GUIDE=1` 以及完整的非秘密 `AGENTS_CORE_WEB_DOCKER_*`
参数。连接面板会在原生 launcher 之外提供可复制的 Docker 命令;Web 仍不会读取
credential 文件或访问 Docker。若 Session 已有排队输入,运行命令可能立即触发付费调用。

model ID 必须由已连接的执行运行时支持。Core 当前没有模型目录接口,
因此 Web 建议项只是可编辑提示,不代表模型一定可用。成功保存 Agent 只能证明
配置已持久化,不能证明 daemon、模型或提供商凭据能够实际执行它。
Expand Down Expand Up @@ -112,14 +134,15 @@ WebSocket 当作 API URL。
| `401 invalid_api_key` | 明文调用方 Bearer 凭据必须与 Core 当前的密钥绑定匹配 |
| `503 execution_unavailable` / `Execution is not enabled` | Core 拒绝执行;请检查其安全错误、运行时和 ownership 状态。worker、executor 或 daemon 可能未配置或已断连,也可能丢失了执行 lease |
| Agent 保存成功但模型运行失败 | 使用已连接运行时支持的 model ID 和提供商凭据 |
| Self-hosted 选项未显示 | 只有核对兼容 Codex Core 与 executor 链路后,设置非秘密 `AGENTS_CORE_WEB_SELF_HOSTED_SESSIONS=1` 并重启或重建 Web |

`/healthz` 只能证明 HTTP 存活,不能证明聊天已就绪。重试结果不确定的请求前,
请先核对 Core 持久状态和当前固定版本的 Parsar 指南;
[旧版 043 故障排查快照](docs/core-connection.md#troubleshooting)仅供历史参考。

## 文档入口

- [当前 Parsar Core 配置](https://github.com/MiniMax-AI-Dev/parsar/blob/d91ba48ac6c49cfdf6f08d7687b9be76ba6d53ee/services/agents-api/README.md#standalone-http-service) — 不可变的当前上游指南
- [当前 Parsar Core 配置](https://github.com/MiniMax-AI-Dev/parsar/blob/2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e/services/agents-api/README.md#standalone-http-service) — 不可变的当前上游指南
- [旧版 Web 连接手册](docs/core-connection.md) — 历史 `0438880` 快照,使用前必须重新核对
- [协议覆盖范围](docs/protocol-coverage.md) — 准确的已支持 API 范围
- [架构说明](docs/architecture.md) — 所有权、运行时和信任边界
Expand Down
Loading
Loading