feat: add command center chat loop widget
This commit is contained in:
@@ -21,8 +21,8 @@
|
||||
> **Track 4 offline partial**:
|
||||
> FinOps/SLO page reads provider usage + business KPI artifacts and budget cap setting
|
||||
> without fabricating missing values.
|
||||
> **Command Center §8.6 built:** `GET /api/v1/command` returns eight evidence-backed
|
||||
> widgets with `{source, artifact_path, commit, run_at, verified}` envelopes; React
|
||||
> **Command Center §8.6 built:** `GET /api/v1/command` returns nine evidence-backed
|
||||
> widgets, including Plan-18 `chat_loop`, with `{source, artifact_path, commit, run_at, verified}` envelopes; React
|
||||
> `/command` page has executive briefing VI/EN, live governance ticker, and evidence drawer.
|
||||
> **Deploy scaffold + local-prod smoke:** `Dockerfile.control-panel-api`,
|
||||
> `Dockerfile.control-panel-ui`, `docker-compose.control-panel.yml`,
|
||||
@@ -30,14 +30,14 @@
|
||||
> `docker compose config`; nginx config passes `nginx -t` with a temp cert/upstream aliases;
|
||||
> `packages/casan-control-panel/scripts/local-prod-smoke.sh` passes
|
||||
> `CP_LOCAL_SMOKE_PASS https_oidc=true actor=oidc-ops role=org-admin` and asserts
|
||||
> `/api/v1/command` returns all 8 widgets with provenance envelopes.
|
||||
> `/api/v1/command` returns all 9 widgets with provenance envelopes.
|
||||
> `prod-readiness-check.sh` validates managed-prod host prerequisites (compose, TLS,
|
||||
> oauth2-proxy OIDC env, nginx) without printing secrets.
|
||||
> `managed-prod-smoke.sh` validates deployed endpoint auth enforcement (unauth blocked,
|
||||
> spoofed identity headers blocked) and, with a real IdP cookie jar, authenticated
|
||||
> `/settings` + `/command` behavior.
|
||||
> Local-prod now runs that managed smoke with the mock-IdP authenticated cookie jar and
|
||||
> emits `CP_MANAGED_SMOKE_PASS actor=oidc-ops role=org-admin widgets=8`.
|
||||
> emits `CP_MANAGED_SMOKE_PASS actor=oidc-ops role=org-admin widgets=9`.
|
||||
> Nginx `auth_request` overwrites identity headers and API maps IdP groups → RBAC roles.
|
||||
> **Còn:** managed host/cert/enterprise IdP env thật (07 T2).
|
||||
>
|
||||
@@ -190,11 +190,11 @@ monitor + manage + settings"] --> API["Control-Plane API (NestJS)"]
|
||||
- [x] Các key settings đang whitelist trong `control-plane-settings.py` quản lý được qua console (compression/cost/model/security/kill-switch/loop); kill-switch UI có.
|
||||
- [x] FinOps/SLO board đọc provider usage + business KPI artifact thật; thiếu budget cap thì báo chưa cấu hình.
|
||||
- [x] Approval inbox + delegation L0-L5 + oversight log có API/UI và test SoD/apply.
|
||||
- [x] Command Center §8.6 có API/UI: 8 widget evidence-backed, provenance envelope, executive briefing VI/EN, live ticker, evidence drawer.
|
||||
- [x] Command Center §8.6 có API/UI: 9 widget evidence-backed (gồm `chat_loop`), provenance envelope, executive briefing VI/EN, live ticker, evidence drawer.
|
||||
- [x] Local production-like deploy có TLS + OIDC + oauth2-proxy + nginx `auth_request`; smoke pass qua HTTPS.
|
||||
- [x] Managed production readiness checker cho cert/host/enterprise IdP env thật.
|
||||
- [x] Managed production endpoint smoke script cho unauth/spoof/authenticated-cookie checks.
|
||||
- [x] Authenticated managed endpoint smoke pass trên local-prod HTTPS/OIDC endpoint (`CP_MANAGED_SMOKE_PASS actor=oidc-ops role=org-admin widgets=8`).
|
||||
- [x] Authenticated managed endpoint smoke pass trên local-prod HTTPS/OIDC endpoint (`CP_MANAGED_SMOKE_PASS actor=oidc-ops role=org-admin widgets=9`).
|
||||
- [ ] Managed production deploy với cert/host/enterprise IdP thật (nối Plan-07 TIER 2).
|
||||
- [x] Red-team mục 5 targeted xanh: control-plane 9/0 + HITL 9/0 + RBAC 12/0 + C7 15/0; full gate dài đã pass qua adversarial 44/0 nhưng A6 mất thời gian nên không claim full-gate xanh trong lượt này.
|
||||
|
||||
@@ -270,7 +270,7 @@ monitor + manage + settings"] --> API["Control-Plane API (NestJS)"]
|
||||
| Task | Việc | Verify |
|
||||
|---|---|---|
|
||||
| 13V.0 | Chuẩn hóa envelope provenance trong Control API; core `--json` bổ sung sau khi có widget cần gọi CLI live | ✅ `commandCenter()` envelope có `source/artifact_path/commit/run_at/verified/status` |
|
||||
| 13V.1 | API `GET /api/v1/command` gom 8 widget đọc-only, không ghi state | ✅ `console:test` contract 20/0 |
|
||||
| 13V.1 | API `GET /api/v1/command` gom 9 widget đọc-only, không ghi state | ✅ `console:test` contract 26/0 |
|
||||
| 13V.2 | V1 Maturity gauge + radar H1–H7 (click widget → evidence drawer) | ✅ `/command` widget + drawer |
|
||||
| 13V.3 | V2 HITL panel + approvals inbox/oversight | ✅ đọc approval store; thiếu artifact → `no_data` |
|
||||
| 13V.4 | V3 kill-switch + guardrail badges; V7 certified seal | ✅ đọc incidents + audit-head/audit tail |
|
||||
@@ -278,9 +278,10 @@ monitor + manage + settings"] --> API["Control-Plane API (NestJS)"]
|
||||
| 13V.6 | V8 self-improve pipeline | ✅ hiển thị primitive present + proposal nếu có trong inbox; không fabricate queue |
|
||||
| 13V.7 | Executive Briefing mode (song ngữ VI/EN) + Live ticker + Evidence drawer dùng chung | ✅ `/command` page |
|
||||
| 13V.8 | Provenance guard: thiếu source→`no_data`/`missing`, stale vẫn qua freshness | ✅ contract test + UI status badge |
|
||||
| 13V.9 | Widget Loop/Chat chuyên sâu | ✅ `chat_loop` widget + ticker/budget/replay evidence drawer (Plan-18 Track 8.3) |
|
||||
|
||||
> **Hiện trạng:** Command Center baseline đã có. Widget Loop/Chat chuyên sâu và RAI view
|
||||
> nằm ở Plan-17/18/15 follow-up, không còn chặn Plan-13 baseline.
|
||||
> **Hiện trạng:** Command Center baseline và Widget Loop/Chat chuyên sâu đã có. RAI view
|
||||
> nằm ở Plan-15 follow-up, không còn chặn Plan-13 baseline.
|
||||
|
||||
---
|
||||
_Liên quan: `CASAN_PLAN_07_PRODUCTION_HARDENING.md` (D3 dashboard, C4 IdP, C7 kill-switch, TIER 2 deploy) · `CASAN_PLAN_14_RBAC.md` (phân quyền) · `CASAN_PLAN_04_SELFIMPROVE.md` (proposal→approval) · `CASAN_PLAN_08_CONTEXT_COMPRESSION.md` (compression-policy là settings) · `CASAN_PLAN_15_RESPONSIBLE_AI_DATA_GOV.md` (RAI/data view)._
|
||||
|
||||
Reference in New Issue
Block a user