Files
CASAN/packages/casan-control-panel
thanhnvandClaude Opus 4.8 63dd44a11b feat(plan-13): read-only Ops Console (NestJS API + React UI) — Track 1
Real web Control Panel over CASAN harness telemetry (Level-3 casan-platform component).
Read-only ("Đọc ≠ Ghi"): no settings writes, no gate bypass. Management/RBAC/approval are
Track 2/3 (future, Plan-14). Additive — harness gate untouched (64/0/3).

packages/casan-control-panel/
- backend/ (NestJS, ESM, /api/v1 + ok() envelope): TelemetryReader (jsonl/json, missing→[],
  never fabricates) + TelemetryService (aggregations mirroring generate-agentops-dashboard.py)
  + endpoints overview/runs(+:traceId)/governance/security/incidents/tools/traceability/
  drift/cost, and /healthz (stale-aware 200/503, fail-loud like dashboard-server.py). App
  root + telemetry paths resolve via casan-paths-style marker walk-up (.specify OR
  packages/casan-harness) + honor CASAN_DASHBOARD_* env. Binds 127.0.0.1; refuses
  non-loopback under CASAN_PROFILE=prod. @Inject token so DI works under tsc AND tsx.
  Tests (node native runner) 7/0: reader parse/missing, app-root, overview shape on real
  repo state, freshness/stale fail-loud.
- frontend/ (React+Vite+Tailwind+TanStack, port 5174, proxies to :3010): AppLayout +
  Sidebar + Header (LIVE/STALE badge from /healthz) + pages Overview/Runs/Governance/
  Security/Incidents/Traceability. axios client unwraps ok() envelope. build green.

Wiring: root workspaces + `console:*` scripts. packaging/levels.json + casan-platform
README: platform preview now lists the Ops Console as an implemented component.

Verified: backend build + test 7/0; frontend tsc + vite build; API serves REAL data
(runs=6, provider_tokens=5556, action_blocks=7); /healthz 503 stale → 200 after touch.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-08 16:59:56 +09:00
..

CASAN Ops Console (Plan-13 Track 1) — read-only Control Panel

Real NestJS API + React UI that surfaces CASAN harness telemetry. This is the Level-3 casan-platform Control Panel component. Read-only ("Đọc ≠ Ghi"): it never writes settings or bypasses a gate — management (settings/RBAC/approval) is Plan-13 Track 2/3 (future, soft-blocked by Plan-14).

backend/   NestJS read-only API (/api/v1 + /healthz) over .specify telemetry
frontend/  React + Vite + Tailwind + TanStack Query Ops Console

Run (local)

npm install                      # from repo root (picks up the workspaces)
npm run console:api              # NestJS API  → http://127.0.0.1:3010/api/v1
npm run console:ui               # Vite UI     → http://127.0.0.1:5174 (proxies to the API)

Open http://127.0.0.1:5174 — panels show REAL metrics from .specify/logs/**.

API (all read-only, ok()-enveloped except /healthz)

GET /api/v1/overview · runs (+ runs/:traceId) · governance · security · incidents · tools · traceability · drift · cost · GET /healthz (200 fresh / 503 stale — fail-loud, mirrors dashboard-server.py).

Data sources + aggregation mirror packages/casan-harness/tests/generate-agentops-dashboard.py. App root + telemetry paths resolve via the same marker walk-up as casan-paths.sh (.specify or packages/casan-harness) and honor CASAN_DASHBOARD_* env overrides.

Security posture (MVP)

Binds 127.0.0.1, no auth (read-only local ops). Refuses a non-loopback bind under CASAN_PROFILE=prod / CASAN_CP_STRICT=1 — off-loopback exposure needs TLS/OIDC (Plan-13 Track 4). Auth/login (reuse OKR JWT) is a follow-up.

Test

npm run console:test             # backend telemetry reader/service + healthz logic

Not in this pass

Track 2 settings writes (wrap control-plane-settings.py), Track 3 RBAC + approval inbox (Plan-14), Track 4 docker/deploy + TLS/OIDC + FinOps/SLO. See docs/plans/CASAN_PLAN_13_CONTROL_PLANE.md.