swarm: show subagent terminals in the swarm UI
An agent's subagent daemon publishes each subagent's output as terminal
rows on `$SWARM.term.<agent>.sub.<subagent>`, as the agent, into a
per-agent stream it creates itself; swarm-controller lists an agent's
subagents from that stream's subjects and relays one subagent's rows as
SSE; the swarm UI lists them under the agent's terminal preview and
reuses AgentTermPreview, full-screen tab included, with no input.
- swarm-nats.nix: the agent token may also publish
`$SWARM.term.{agent}.sub.>` and `$JS.API.STREAM.CREATE|INFO` on
`term-sub-{agent}`, and nothing else of JetStream. A module-eval arm
pins the agent-token grant as an exact list.
- mcp.nix: hive-subagent-daemon loads the agent's store identity
(`hive-agent-bao-cert/-key/-server-ca`, the ones hive-agent loads)
whenever the agent has a store, not only on the opencode preset. The
agent's own queue secret lives in the store, so this is the credential
the harness connects with.
- hive-subagent-mcp: `swarm_term` reads the agent's queue secret under
that identity, connects with the agent token, opens or creates
`term-sub-<agent>` (max_age 24h), and publishes classified rows from
the sink every subagent line already passes through. The sink only
queues (bounded, drop-and-count); a missing store, refused credential,
failed stream create or failed publish is a log line.
- The stream-json classifier (`stream_enrich`) and the `TermMsg` row
types plus `fit` move from the hive-agent binary into hive-sh4re, so
the subagent daemon publishes the rows AgentTermPreview already
renders. hive-agent keeps its LiveEvent classifier on top.
- swarm-controller: `GET /api/agents/{name}/subagents` and
`GET /api/agents/{name}/subagents/{subagent}/term/stream`.
- docs/swarm: what the UI shows and what the queue carries.
Closes #4827
This commit is contained in:
parent
b90be9e65e
commit
d6f94e5247
35 changed files with 1529 additions and 340 deletions
|
|
@ -361,12 +361,18 @@ mod tests {
|
|||
"$SWARM.agent-state.{agent}",
|
||||
"--agent-token-publish-subject",
|
||||
"$KV.agent-icons.{agent}",
|
||||
"--agent-token-publish-subject",
|
||||
"$SWARM.term.{agent}.sub.>",
|
||||
"--agent-token-publish-subject",
|
||||
"$JS.API.STREAM.CREATE.term-sub-{agent}",
|
||||
"--agent-token-publish-subject",
|
||||
"$JS.API.STREAM.INFO.term-sub-{agent}",
|
||||
"--store-cert-role",
|
||||
"swarm-nats-auth",
|
||||
])
|
||||
.expect("the unit's own argument vector must parse");
|
||||
assert_eq!(args.agent_client_suffix, "-agent");
|
||||
assert_eq!(args.agent_token_publish_subjects.len(), 3);
|
||||
assert_eq!(args.agent_token_publish_subjects.len(), 6);
|
||||
}
|
||||
|
||||
/// The control for the case above: an ordinary value parses through the
|
||||
|
|
|
|||
|
|
@ -1219,6 +1219,37 @@ mod tests {
|
|||
);
|
||||
}
|
||||
|
||||
/// The subagent templates as `swarm-nats.nix` spells them expand to the
|
||||
/// subjects and stream name the subagent daemon uses, and to `CREATE` and
|
||||
/// `INFO` on that one stream only.
|
||||
#[test]
|
||||
fn an_agents_subagent_grant_is_its_own_stream_and_nothing_wider() {
|
||||
use swarm_queue_client::subagent_term::{stream_name, stream_subjects, subject};
|
||||
|
||||
let p = policy_with_agent_subject()
|
||||
.with_agent_token_subjects(vec![
|
||||
"$SWARM.term.{agent}.sub.>".to_owned(),
|
||||
"$JS.API.STREAM.CREATE.term-sub-{agent}".to_owned(),
|
||||
"$JS.API.STREAM.INFO.term-sub-{agent}".to_owned(),
|
||||
])
|
||||
.expect("per-agent templates are valid");
|
||||
let g = p.agent_token_permissions("atlas").expect("configured");
|
||||
assert_eq!(
|
||||
g.publish,
|
||||
vec![
|
||||
stream_subjects("atlas"),
|
||||
format!("$JS.API.STREAM.CREATE.{}", stream_name("atlas")),
|
||||
format!("$JS.API.STREAM.INFO.{}", stream_name("atlas")),
|
||||
]
|
||||
);
|
||||
assert!(subject("atlas", "scout").starts_with(g.publish[0].trim_end_matches('>')));
|
||||
let argus = p.agent_token_permissions("argus").expect("configured");
|
||||
assert!(
|
||||
g.publish.iter().all(|s| !argus.publish.contains(s)),
|
||||
"atlas and argus share a subject: {g:?} {argus:?}"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_agent_token_subject_without_the_placeholder_is_refused() {
|
||||
let err = policy()
|
||||
|
|
|
|||
Loading…
Reference in a new issue