Files
agentic-mobile-control/cloud-console

Cloud Console

Vue 3 + Vite single-page app for the Cloud Control Plane (apps/cloud-api). The primary flow is a Cloud user account: username/password login creates an expiring, revocable HttpOnly session cookie, while the frontend sends the separate CSRF cookie value on writes. The browser never stores the session secret in JavaScript.

Prerequisites

  • Node.js 20+
  • A current Cloud API database migration and at least one administrator created with device-cloud-admin users create ...
  • HTTPS for production: CLOUD_SESSION_COOKIE_SECURE=true is required in a production Cloud API. Terminate TLS at the origin serving /console/.

Accounts have fixed roles:

  • viewer: task, device/host, and plugin read views
  • operator: viewer access plus task submission APIs
  • admin: all API scopes

Administrators can use Users & limits to manage accounts, restrict task submission to explicit Host/Device targets, configure Host self-submission and active-task limits, and inspect non-secret Cloud-proxy usage. Daily token budgets are enforced only for Hosts reporting AI_PLANNER_TRANSPORT=cloud; direct-provider Hosts are labelled unmetered rather than budget compliant. The configured proxy reservation ceiling must fit within any daily budget.

Task readers can inspect full per-step LLM interaction history for cloud-transport tasks in the task detail view. This history includes prompts and resolved tool calls, excludes screenshot bytes, and is unavailable by design for direct-provider Hosts. Retention is configured on the Cloud API via CLOUD_PLANNER_DECISION_LOG_RETENTION_DAYS and its prune interval.

Local development

cd cloud-console
cp .env.example .env.local
# Point this to the local Cloud API when it is not http://127.0.0.1:8001
npm install
npm run dev

For a Vite origin such as http://127.0.0.1:5173, configure the API with the exact origin and disable secure cookies only in local/test mode:

export CLOUD_CONSOLE_CORS_ORIGINS="http://127.0.0.1:5173"
export CLOUD_SESSION_COOKIE_SECURE=false

The Console uses credentials: include. 401 returns to the login screen; 403 remains an authorization error so an otherwise valid session is retained.

Production

npm run build type-checks and creates dist/. The repository Dockerfile already builds this bundle into /app/console-static and configures the Cloud API to serve it at the same-origin /console/ route. No CORS configuration is required in that deployment shape. Use device-cloud-admin for account provisioning and recovery.