Skip to content

feat(hosts): remote computers over SSH, placement, privacy tiers and accounts - #65

Closed
BIackFIame wants to merge 3 commits into
howdeploy:mainfrom
BIackFIame:stack/3-remote-hosts
Closed

BIackFIame wants to merge 3 commits into
howdeploy:mainfrom
BIackFIame:stack/3-remote-hosts

Conversation

@BIackFIame

@BIackFIame BIackFIame commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Run terminals and agents on your own servers over SSH, choose a server automatically, and keep data-handling rules and several accounts per provider consistent across computers.

Behavior

  • Remote hosts use the system OpenSSH client in BatchMode, so CanvasTTY never stores passwords. They cover connectivity checks, remote terminals, CLI discovery in one SSH round trip, light load and memory metrics, and mapping local project folders to server folders.
  • Placement: hard filters (reachability, provider rules, workspace mapping, capacity) run before ranking by sessions, load per core and free memory. A probe checks whether each provider's API answers from that server, so providers blocked in a region are not placed there.
  • spawn_agent can request a host, so subagents may run remotely.
  • Privacy tiers D0–D3 are enforced at spawn time, with host confidentiality ceilings and repository path policies.
  • Accounts: several accounts per provider with subscription tiers, each bound to its own computer.
  • Security fixes: lease supersession, an authentication hang, and SSH option injection through host fields (hosts starting with - or containing whitespace are rejected).

Verification

  • npm run typecheck passed. Full suite: 907/907; Even G2 companion tests (npm run test:even): 47/47.
  • Live, on the final state of this series: three fresh Ubuntu servers over SSH. A remote terminal opened in the mapped folder, and Claude launched on a server. Placement skipped an unreachable server and chose the least-loaded one. A server in a region where Anthropic, OpenAI and xAI APIs are blocked was correctly excluded for those providers.

Series

Each part is one commit on top of the previous one. Please merge them in order. Until #64 is merged, GitHub also shows the earlier parts here; review only the top commit 590d79f (Commits tab → last commit).

Part PR Scope Lines
1 #63 Providers: Cursor, MiniMax Code, Devin, Antigravity +579/−90
2 #64 API keys, API profiles, agent delegation (MCP) +4275/−63
3 #65 Remote servers, placement, privacy tiers, accounts +6620/−40
4 #66 Isolation: capsules, worktrees, containers +5508/−839
5 #67 ACP, connection settings, remote containers +6827/−563
6 #68 Project context and learning +6148/−370
7 #69 Routing, reasoning effort, server preparation, sign-in +3122/−467
8 #70 Open issues and safe fixes from open PRs +306/−58

Compatibility with open upstream PRs

integration/stack-with-open-prs is this whole stack with #54–#62 merged on top and every conflict resolved. On that branch both TypeScript checks, 1492/1492 tests, npm run test:even (47/47) and electron-vite build pass.

I will rebase this stack onto whichever of these lands first.

🤖 Generated with Claude Code

BIackFIame and others added 3 commits September 23, 2026 17:16
Provider CLI resolution is driven by declarative command definitions
instead of assuming the executable matches the provider id. MiniMax
Code (`mcode`), Antigravity (`agy`) and Cursor resolve through the same
registry, known install directories, recheck and install links that howdeploy#52
introduced. Cursor prefers `cursor-agent`; a generic `agent` is accepted
only when its real path is verified as Cursor, because Grok also
installs an `agent` executable.

Each new agent gets normal and resume launches where the CLI documents
them, its YOLO flag only where one exists, launcher entries with a
settings migration, its provider mark and session restore. MiniMax Code
has no permission-bypass flag, so its YOLO profile launches the stock
CLI and says so. Antigravity restores as a fresh session because it has
no resumable id that CanvasTTY can persist.

Provider ids, labels and launcher order live in a dependency-free
`providerCatalog.ts` that `contracts.ts` re-exports, so the Even G2
companion bundle stays free of URLs outside its network whitelist; its
phone launcher lists the new agents too.

Lifecycle hooks are prepared only for providers that have a hook adapter, so
the new agents never write Grok's shared hook configuration.

ADR: docs/adr/ADR-20260921-provider-cli-command-definitions.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tion

- Provider API keys are stored in the main process, encrypted with
  Electron safeStorage; the renderer only sees which keys exist.
- API profiles name a model backend (protocol, HTTPS base URL, key
  reference, default model) with built-in presets.
- Sessions carry role and parent metadata; restore drops orphaned
  subagents instead of resurrecting them.
- Per-provider capability descriptors state what CanvasTTY can really do
  with each agent, and agent control (spawn, send, observe, result,
  cancel, children) works over ordinary terminal sessions.
- An orchestration MCP surface rides the existing agent-bridge design:
  authenticated user-local socket, one-use bootstrap capabilities, scoping
  to the caller's own session subtree, and MCP injection for Claude,
  Codex, OpenCode, Kimi and Hermes. Only orchestrator sessions receive it;
  ordinary launches are unchanged.

ADR: docs/adr/ADR-20260921-orchestration-mcp-rides-agent-bridge.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…accounts

- Saved remote hosts use the system OpenSSH client (BatchMode, no stored
  passwords) for connectivity checks, remote terminals, CLI discovery,
  light load/memory metrics and per-host workspace mapping.
- Automatic placement applies hard filters (reachability, provider rules,
  workspace mapping, capacity) before ranking by load and free memory,
  and probes whether each provider's API answers from that host.
- spawn_agent can request a host, so subagents may run remotely.
- Data-handling tiers D0-D3 are enforced at spawn time, with host
  confidentiality ceilings and repository path policies.
- Several accounts per provider with subscription tiers; each account is
  bound to its own computer.
- Security fixes: lease supersession, an authentication hang and SSH
  option injection through host fields.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@BIackFIame

Copy link
Copy Markdown
Contributor Author

Заменено: функции вынесены в плагины canvastty-plugin-* (environments, assistant, accounts, context, acp), точки расширения ядра — в #81–#88. Подробно — в комментарии в #67: #67 (comment)

@BIackFIame BIackFIame closed this Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant