DreamLake

Basic host and run UI

September 15, 2026 update (production): frontend PR #310 supersedes the standalone Hosts layout below with Compute at /:namespace/compute and /:namespace/compute/hosts/:hostId. Old URLs redirect on production. Staging rollout remains separate. Compute uses one pattern-search field and a scrollable inventory assembled from all API pages, with ten-second visible-tab polling. The original pagination/group-control proposal is retained here as design history. Enrollment guidance and tracked-run monitoring carry forward; see the current UI review guide.

Status: In progress. Design for #218; implementation and deployment remain separate. The first slice makes existing hosts and runs inspectable. CLI/Python enrollment and execution remain usable independently of UI delivery.

First slice

Use the application's existing signed-in namespace context, navigation, and API client. Add a Hosts view and a Run detail view; retain server IDs in URLs so reload and sharing recover the same authorized resource. Use /:namespace/hosts and /:namespace/hosts/:hostId, plus /:namespace/tracked-runs for ID lookup and /:namespace/tracked-runs/:runId for detail. Keep the existing workflow /runs surface unchanged. Do not add a second browser-owned job state machine or store account/SSH secrets in local storage.

ViewBasic behaviorExisting API
HostsNamespace list, optional exact namespace/group filter, pagination, host name, Unix user/enrollment, connection status, last heartbeat and verification state. Open a host by its stable ID.GET /namespaces/:ns/hosts?prefix=ns/group&page=1&pageSize=50
Host detailIdentity and per-user enrollment rows; refresh status. Display connection health separately from runner readiness; say “not reported” when capability/readiness data is absent.GET /namespaces/:ns/hosts/:id
EnrollSmall name/prefix and SSH-alias form producing a copyable CLI command, then a refresh/link to the resulting host. No browser SSH, private-key/password input, or fake completion.CLI handoff; the browser does not call grant issuance as a substitute for target bootstrap.
Run detailOpen by namespace/run ID; show target/enrollment, status, timestamps, result and exit code. Poll stdout/stderr and allow cancellation of nonterminal work.GET /namespaces/:ns/runs/:id, GET .../:id/logs, POST .../:id/cancel

Host online means verified connectivity, not proven workload readiness. A lost status request preserves the last known value with a stale/unverified marker. Authentication failures lead to sign-in/access help; unknown resources remain distinct from network failures. Never reveal arbitrary server error payloads or bootstrap credentials.

Poll only the selected resource, with bounded retry/backoff and cleanup on navigation. Retain the server's single opaque nextCursor unchanged (it carries both stream offsets), with separate incremental UTF-8 decoders for stdout/stderr; there is no cross-stream ordering guarantee. On reload, read server state and replay logs from the beginning or a validated cursor without submitting again. Terminal status and fully drained logs stop polling; provide an explicit refresh.

Cancellation is a server request, not a local toggle to “cancelled.” Disable duplicate clicks with “Requesting cancellation” while submitting; show cancel_requested only when confirmed by the server, until terminal confirmation, and retain completed results if completion wins the race. An unreachable worker or a cancellation receipt alone does not prove descendant processes stopped.

Next slice, without blocking the first

  • Run list: add an authenticated, owner-scoped paginated list endpoint before a persistent list UI. The current API only retrieves known run IDs; do not present browser history as a complete server list.
  • Run submission: select an authorized host/enrollment; choose uv-run or uvx; edit an argument list, not an interpolated shell string. Preview explicit files only, with the same relative-path/hash/mode validation and 100-file/1-MiB limit. Send the atomic manifest through POST /namespaces/:ns/runs, preserve the request ID through uncertain responses, and navigate to the returned durable run ID. Never automatically upload a project, .env, or SSH key.
  • Capabilities and linking: expose missing readiness fields through the shared API and handle ambiguous enrollment explicitly. Additional Unix-user linking needs its authorization workflow; host names alone are insufficient.

Vault management/optional saving belongs to #241; provider provisioning/cluster UI belongs to #243. Link those flows without embedding their policies here.

Acceptance and delivery

  • First UI PR: host list/detail, CLI enrollment handoff, run-by-ID detail, log polling, and cancellation using existing authenticated routes.
  • Verify loading/empty/error states, owner denial, stale/offline status, running/success/failure results, cancellation races, and reload with persistent identity/logs.
  • Run UI E2E against real authenticated service fixtures; response fixtures may supplement this but do not establish execution or authorization proof.
  • Include a committed manual script, exact setup/run commands, expected results, and cleanup in each implementation PR. Record merge, deployment, and live-browser verification separately.
  • Follow with server-backed run listing and explicit-file submission once their contracts and tests are complete.

See manual host/run testing for reusable real-service fixtures and current CLI/Python acceptance.