Real web Control Panel over CASAN harness telemetry (Level-3 casan-platform component).
Read-only ("Đọc ≠ Ghi"): no settings writes, no gate bypass. Management/RBAC/approval are
Track 2/3 (future, Plan-14). Additive — harness gate untouched (64/0/3).
packages/casan-control-panel/
- backend/ (NestJS, ESM, /api/v1 + ok() envelope): TelemetryReader (jsonl/json, missing→[],
never fabricates) + TelemetryService (aggregations mirroring generate-agentops-dashboard.py)
+ endpoints overview/runs(+:traceId)/governance/security/incidents/tools/traceability/
drift/cost, and /healthz (stale-aware 200/503, fail-loud like dashboard-server.py). App
root + telemetry paths resolve via casan-paths-style marker walk-up (.specify OR
packages/casan-harness) + honor CASAN_DASHBOARD_* env. Binds 127.0.0.1; refuses
non-loopback under CASAN_PROFILE=prod. @Inject token so DI works under tsc AND tsx.
Tests (node native runner) 7/0: reader parse/missing, app-root, overview shape on real
repo state, freshness/stale fail-loud.
- frontend/ (React+Vite+Tailwind+TanStack, port 5174, proxies to :3010): AppLayout +
Sidebar + Header (LIVE/STALE badge from /healthz) + pages Overview/Runs/Governance/
Security/Incidents/Traceability. axios client unwraps ok() envelope. build green.
Wiring: root workspaces + `console:*` scripts. packaging/levels.json + casan-platform
README: platform preview now lists the Ops Console as an implemented component.
Verified: backend build + test 7/0; frontend tsc + vite build; API serves REAL data
(runs=6, provider_tokens=5556, action_blocks=7); /healthz 503 stale → 200 after touch.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
CASAN Ops Console (Plan-13 Track 1) — read-only Control Panel
Real NestJS API + React UI that surfaces CASAN harness telemetry. This is the Level-3
casan-platform Control Panel component. Read-only ("Đọc ≠ Ghi"): it never writes
settings or bypasses a gate — management (settings/RBAC/approval) is Plan-13 Track 2/3
(future, soft-blocked by Plan-14).
backend/ NestJS read-only API (/api/v1 + /healthz) over .specify telemetry
frontend/ React + Vite + Tailwind + TanStack Query Ops Console
Run (local)
npm install # from repo root (picks up the workspaces)
npm run console:api # NestJS API → http://127.0.0.1:3010/api/v1
npm run console:ui # Vite UI → http://127.0.0.1:5174 (proxies to the API)
Open http://127.0.0.1:5174 — panels show REAL metrics from .specify/logs/**.
API (all read-only, ok()-enveloped except /healthz)
GET /api/v1/overview · runs (+ runs/:traceId) · governance · security ·
incidents · tools · traceability · drift · cost · GET /healthz (200 fresh /
503 stale — fail-loud, mirrors dashboard-server.py).
Data sources + aggregation mirror packages/casan-harness/tests/generate-agentops-dashboard.py.
App root + telemetry paths resolve via the same marker walk-up as casan-paths.sh
(.specify or packages/casan-harness) and honor CASAN_DASHBOARD_* env overrides.
Security posture (MVP)
Binds 127.0.0.1, no auth (read-only local ops). Refuses a non-loopback bind under
CASAN_PROFILE=prod / CASAN_CP_STRICT=1 — off-loopback exposure needs TLS/OIDC (Plan-13
Track 4). Auth/login (reuse OKR JWT) is a follow-up.
Test
npm run console:test # backend telemetry reader/service + healthz logic
Not in this pass
Track 2 settings writes (wrap control-plane-settings.py), Track 3 RBAC + approval inbox
(Plan-14), Track 4 docker/deploy + TLS/OIDC + FinOps/SLO. See
docs/plans/CASAN_PLAN_13_CONTROL_PLANE.md.