The web dashboard
orion web serves a dashboard for everything Orion is doing, and lets you
act on it without the terminal: clear gates, answer questions, start work,
create and plan projects, and change settings. It runs on your own machine
only.
Starting itβ
orion web # http://127.0.0.1:7061
orion web --port 0 # let the system pick a free port
It prints the address to open. The server listens on 127.0.0.1 only, and no
flag changes that. Ctrl-C stops the server and every job it started.
Restarting orion web invalidates open tabs: each run of the server has its
own access token, so an old tab is told to reload. The address / opens the
current interface; the previous one is still at /?legacy=1.
Pagesβ
The menu on the left has these pages. Every address can be shared or
bookmarked, and adding ?project=KEY scopes any page to one project (the
project selector in the top bar does the same).
| Page | Shows |
|---|---|
| Overview | Counts (running, queued, landed, failed, spent), a card per running ticket, and a pipeline view with one column per stage |
| Needs you | Every gate waiting on a person, in tabs: waiting on me, in flight, everything, by batch |
| Start work | The launcher: work tickets, queue them, or start a watch |
| History | Every past run, filterable and exportable as CSV |
| Projects | Each project, its counts, and its settings; create and plan projects here |
| Settings | Appearance, agents, limits, connections |
From any page, a ticket opens to its own view: queue position, blockers, every run and every answer. A run opens as a full-width graph of what happened.
Search with βK or Ctrl-K (or /) jumps to a page or a ticket. The top bar
shows Live with a green dot while the page is current, and
Reconnecting with an amber dot when it cannot reach the server; the last
good view stays on screen meanwhile.
What you can do from the browserβ
Every action shows what it will run and asks you to confirm. The server then
runs the same orion command you would type, with arguments it builds itself,
and shows its output. You cannot enter a command line.
| You want to | Where | What runs |
|---|---|---|
| Approve or reject a merge | Needs you | orion approve KEY (or --reject with a reason) |
| Confirm or reject a recommendation | Needs you | orion confirm-plan PROJECT RECORD (or --reject) |
| Answer a question an agent asked | Needs you, or the ticket | Your answer goes to an inbox; see below |
| Move a ticket to the front of the queue | Needs you | orion prioritise KEY FRONT --project P |
| Work, queue or watch | Start work | orion work KEY..., orion queue add KEY... [--reset], or orion watch PROJECT --max-jobs N --interval S |
| Stop something it started | Overview, "started here" | Ctrl-C to that job, then a kill |
| Create a project | Projects | orion new with the answers you typed |
| Plan a project | Projects | orion plan KEY --yes [--release vX.Y.Z] |
| Change an agent's model or effort | Settings, Agents | the same check as orion config agents |
| Change a limit or a landing switch | Settings, Limits | the same check as orion config limits / collect |
| Set tracker or Slack credentials | Settings, Connections | stored like orion config; never shown back |
Limits on actionsβ
- Approve and confirm work only when the project's
orion.jsonsetscollect.allow_local_approval. Rejecting always works. - A gate is re-read when you act. If the ticket has moved on since the page loaded, the action is refused.
- Starting work shows a plan first, and is refused if anything changed in between or the weekly budget is spent. One action covers at most 20 tickets, and only one job per action and target runs at a time.
- A setting above the threshold where the terminal would ask for confirmation is refused here, and the page names the command to run instead.
- The Plan button runs
orion plan KEY --yes, which answers every pause in the chain itself, including the tree preview. Confirm it only when you would have said yes at each step.
Answering a questionβ
When a ticket is under NEEDS YOU, the answer box on it sends your answer to
an inbox, because the web server holds no tracker credential. The watch
delivers it at the start of its next sweep. It posts
your answer as a comment on the ticket and, if the ticket is
orion-failed, puts it back in the queue.
The box shows "Waiting for the watcher", then "Delivered", or a failure you can resend. If no watch is running, the answer waits until one does. Answers are up to 2000 characters, one pending per ticket. See Construction.
What stays in the terminalβ
These are only in the terminal:
- Budget, approvers (
slack.merge_approvers), branch and gate settings,ci.auto_fix, paths, and other configuration that changes what Orion is allowed to do. - Answering a planning stage's open questions (
orion answer). orion plan --from STEP, and any free-form command.- Editing a project's key, working copy, sandbox or remote; the page edits only its tracker address and Slack channel.
How it is kept safeβ
- The server listens on
127.0.0.1and accepts only local host names. - Reading is open to the local page. Every write must carry the run's token in a request header, come from the page's own origin, and pass the host check. The token is never a cookie or part of an address, so another site cannot borrow it.
- Each action maps to a fixed command, with arguments the server builds and validates.
- The page reads what the watch publishes and writes answers to an inbox the watch delivers; only the watch talks to the tracker.
- Connections are write-only: a stored credential is never shown back.
The decisions behind it: 0024 (authentication), 0025 (the front end), 0026 (configuration writes), 0027 (answers), 0028 (gate actions), 0029 (starting work), 0030 (projects), 0038 (credentials).
Preferencesβ
Settings, Appearance: Light, Dark, Match my device, or High contrast; whether to show run ids and exact times; and browser notifications when something needs you. These are kept in this browser only.
Not documented yetβ
- Which browsers are supported.
- Reaching the dashboard from another machine. It listens on
127.0.0.1only, and nothing else is documented.