0029: A person starts work from the browser through commands the page shows first
- Status: Accepted (Navjyot, 2026-10-06)
- Date: 2026-10-06
- Related: 0024, 0026, 0028 (same child process rules), 0001
Contextβ
Mockup 05 lets a person pick tickets, choose how they run, see the command, and
start it. Unlike every earlier web write, this spends money, and one mode
(orion watch) keeps spending until it is stopped. The page has no tracker
credential and must not become a way to run arbitrary commands.
Decisionβ
- Three modes, three commands, nothing else:
orion work KEY...(in the order given),orion queue add KEY...(leaves it to a watcher), andorion watch PROJECT [--max-jobs N] [--interval S]. The options the page offers are--verbose,--resetand--dry-run. - Plan, then start. A plan request returns the exact argument list, how many tickets, which agents they route to, the per-ticket limits and what has been spent today, and starts nothing. A start request carries only the plan's identifier; the server rebuilds the argument list itself and refuses if it no longer matches (a ticket moved, a limit changed). No part of a command line comes from the client.
- Spend is checked before start. A start is refused when the weekly budget
(
Budget.WeeklyUSD) is already spent. The page shows the figure, not just the refusal. - Children belong to the web server. Each started command runs in its own process group, supervised by the server, and stops when the server stops. Closing a tab does not stop it; stopping the server does, and the page says so on the start button. A standing watcher that outlives the server is still started from a terminal or a service, not from here.
- One start at a time per project, reusing the claim rules so two starts cannot work one ticket. A second start of the same plan is refused.
- A stop button sends the same interrupt
Ctrl-Cdoes, and the page shows what the process printed, scrubbed and capped as in ADR 0028. watchstates its limits on the button (jobs, interval) and that it spends until stopped.--resetis shown as a separate, named option.- Every request carries the token and passes the Origin and Host checks (ADR 0024).
Consequencesβ
- The web can now spend money. The limits already in
orion.json(per-ticket tries, concurrent tickets, the weekly budget) are the ceiling, and a start that would exceed the budget is refused, but a startedwatchcan still spend up to those limits. - Quitting the web server ends the work it started, which is surprising to a person who expects a launcher to detach. It is the safer default, and the alternative is a rejected option below.
- The ticket picker reads the watcher's queue snapshot, so it shows only tickets a watcher has seen; a ticket it has not is typed as a key.
Rejectedβ
- A free-text command box. The page would be a shell.
- Detach the child so it outlives the server. Spending with no supervisor and no stop button on a surface that may no longer be running.
- Call the work code in the web process. It would put a tracker credential and long-running agent sessions inside the process that faces a browser.