INFRA.md: in-browser approvals, sign-in flow
This commit is contained in:
@@ -7,8 +7,9 @@
|
|||||||
- WARP: Per-node identities in /etc/netvm/
|
- WARP: Per-node identities in /etc/netvm/
|
||||||
- Browsers: Headless Chromium via chrome-box
|
- Browsers: Headless Chromium via chrome-box
|
||||||
- API: muse-chat-api.py via netvm-exec (CDP)
|
- API: muse-chat-api.py via netvm-exec (CDP)
|
||||||
|
- Sign-in: muse-signin.py --email <addr> [--otp <code>]
|
||||||
- Hygiene: netvm-reaper.sh
|
- Hygiene: netvm-reaper.sh
|
||||||
- Approvals: /etc/netvm/approvals/ + netvm-approve.sh
|
- Approvals: In-browser via chat (see below)
|
||||||
|
|
||||||
## VM (34.139.37.135) — Gateway + Vault
|
## VM (34.139.37.135) — Gateway + Vault
|
||||||
- E2 micro (2 vCPU, 1GB RAM)
|
- E2 micro (2 vCPU, 1GB RAM)
|
||||||
@@ -24,3 +25,26 @@
|
|||||||
- Meta accounts: /etc/netvm/meta-credentials/store.age (VM)
|
- Meta accounts: /etc/netvm/meta-credentials/store.age (VM)
|
||||||
- WARP identities: /etc/netvm/node.conf (per-machine, root 600)
|
- WARP identities: /etc/netvm/node.conf (per-machine, root 600)
|
||||||
- Operators handle transiently; never log values.
|
- Operators handle transiently; never log values.
|
||||||
|
|
||||||
|
## In-Browser Approvals
|
||||||
|
When automation needs human input (OTP, confirmation):
|
||||||
|
1. Script exits with code 2 and prints "APPROVAL_NEEDED: <details>"
|
||||||
|
2. Operator sees this and asks user via chat
|
||||||
|
3. User provides input (e.g., OTP code)
|
||||||
|
4. Operator re-runs script with --otp <code>
|
||||||
|
5. Script completes the flow
|
||||||
|
|
||||||
|
No file-based queue needed — the chat IS the approval interface.
|
||||||
|
The human is already in the chat; the automation just needs to
|
||||||
|
signal when it's stuck.
|
||||||
|
|
||||||
|
## Sign-In Flow (muse-signin.py)
|
||||||
|
Automated login for muse.ai accounts:
|
||||||
|
- Step 1: Check if already logged in (skip if yes)
|
||||||
|
- Step 2: Click "Log in"
|
||||||
|
- Step 3: Enter email
|
||||||
|
- Step 4: Click "Continue"
|
||||||
|
- Step 5: Detect OTP prompt
|
||||||
|
- If --otp provided: enter it, click Next, verify
|
||||||
|
- If not: exit 2 with APPROVAL_NEEDED
|
||||||
|
- Credentials never stored; OTP is transient.
|
||||||
|
|||||||
Reference in New Issue
Block a user