Skip to main content
Version: Next

The web dashboard

orion web serves a dashboard for everything Orion is doing, and lets you act on it without the terminal: clear gates, answer questions, start work, create and plan projects, and change settings. It runs on your own machine only.

Starting it​

orion web # http://127.0.0.1:7061
orion web --port 0 # let the system pick a free port

It prints the address to open. The server listens on 127.0.0.1 only, and no flag changes that. Ctrl-C stops the server and every job it started.

Restarting orion web invalidates open tabs: each run of the server has its own access token, so an old tab is told to reload. The address / opens the current interface; the previous one is still at /?legacy=1.

Pages​

The menu on the left has these pages. Every address can be shared or bookmarked, and adding ?project=KEY scopes any page to one project (the project selector in the top bar does the same).

PageShows
OverviewCounts (running, queued, landed, failed, spent), a card per running ticket, and a pipeline view with one column per stage
Needs youEvery gate waiting on a person, in tabs: waiting on me, in flight, everything, by batch
Start workThe launcher: work tickets, queue them, or start a watch
HistoryEvery past run, filterable and exportable as CSV
ProjectsEach project, its counts, and its settings; create and plan projects here
SettingsAppearance, agents, limits, connections

From any page, a ticket opens to its own view: queue position, blockers, every run and every answer. A run opens as a full-width graph of what happened.

Search with ⌘K or Ctrl-K (or /) jumps to a page or a ticket. The top bar shows Live with a green dot while the page is current, and Reconnecting with an amber dot when it cannot reach the server; the last good view stays on screen meanwhile.

What you can do from the browser​

Every action shows what it will run and asks you to confirm. The server then runs the same orion command you would type, with arguments it builds itself, and shows its output. You cannot enter a command line.

You want toWhereWhat runs
Approve or reject a mergeNeeds youorion approve KEY (or --reject with a reason)
Confirm or reject a recommendationNeeds youorion confirm-plan PROJECT RECORD (or --reject)
Answer a question an agent askedNeeds you, or the ticketYour answer goes to an inbox; see below
Move a ticket to the front of the queueNeeds youorion prioritise KEY FRONT --project P
Work, queue or watchStart workorion work KEY..., orion queue add KEY... [--reset], or orion watch PROJECT --max-jobs N --interval S
Stop something it startedOverview, "started here"Ctrl-C to that job, then a kill
Create a projectProjectsorion new with the answers you typed
Plan a projectProjectsorion plan KEY --yes [--release vX.Y.Z]
Change an agent's model or effortSettings, Agentsthe same check as orion config agents
Change a limit or a landing switchSettings, Limitsthe same check as orion config limits / collect
Set tracker or Slack credentialsSettings, Connectionsstored like orion config; never shown back

Limits on actions​

  • Approve and confirm work only when the project's orion.json sets collect.allow_local_approval. Rejecting always works.
  • A gate is re-read when you act. If the ticket has moved on since the page loaded, the action is refused.
  • Starting work shows a plan first, and is refused if anything changed in between or the weekly budget is spent. One action covers at most 20 tickets, and only one job per action and target runs at a time.
  • A setting above the threshold where the terminal would ask for confirmation is refused here, and the page names the command to run instead.
  • The Plan button runs orion plan KEY --yes, which answers every pause in the chain itself, including the tree preview. Confirm it only when you would have said yes at each step.

Answering a question​

When a ticket is under NEEDS YOU, the answer box on it sends your answer to an inbox, because the web server holds no tracker credential. The watch delivers it at the start of its next sweep. It posts your answer as a comment on the ticket and, if the ticket is orion-failed, puts it back in the queue.

The box shows "Waiting for the watcher", then "Delivered", or a failure you can resend. If no watch is running, the answer waits until one does. Answers are up to 2000 characters, one pending per ticket. See Construction.

What stays in the terminal​

These are only in the terminal:

  • Budget, approvers (slack.merge_approvers), branch and gate settings, ci.auto_fix, paths, and other configuration that changes what Orion is allowed to do.
  • Answering a planning stage's open questions (orion answer).
  • orion plan --from STEP, and any free-form command.
  • Editing a project's key, working copy, sandbox or remote; the page edits only its tracker address and Slack channel.

How it is kept safe​

  • The server listens on 127.0.0.1 and accepts only local host names.
  • Reading is open to the local page. Every write must carry the run's token in a request header, come from the page's own origin, and pass the host check. The token is never a cookie or part of an address, so another site cannot borrow it.
  • Each action maps to a fixed command, with arguments the server builds and validates.
  • The page reads what the watch publishes and writes answers to an inbox the watch delivers; only the watch talks to the tracker.
  • Connections are write-only: a stored credential is never shown back.

The decisions behind it: 0024 (authentication), 0025 (the front end), 0026 (configuration writes), 0027 (answers), 0028 (gate actions), 0029 (starting work), 0030 (projects), 0038 (credentials).

Preferences​

Settings, Appearance: Light, Dark, Match my device, or High contrast; whether to show run ids and exact times; and browser notifications when something needs you. These are kept in this browser only.

Not documented yet​

  • Which browsers are supported.
  • Reaching the dashboard from another machine. It listens on 127.0.0.1 only, and nothing else is documented.