Agent computer: terminal (tmux + drives + tabs), Obsidian vault, UI polish

Terminal app (xterm ⇄ WebSocket ⇄ per-agent themed container):
- zsh + oh-my-zsh + powerlevel10k image (agent-terminal), runs as uid 65532 to
  share read-write ownership of the file-drive volume with the server.
- Interactive PTY in cm-sandbox (bollard exec tty/attach + resize) + a
  TerminalManager; ticket-authed WS bridge routed straight to the backend via a
  Traefik PathRegexp(/ws) rule. MOTD greets the user by name.
- tmux resumable sessions; multi-tab (one tmux session per tab, same container),
  drag-to-reorder, rename, and a Save that persists named tabs to the server
  (terminal_tabs, migration 0014) so they survive logout / a new device.
- Files drives mounted per-agent (subpath) at ~/drives/{documents,received,
  shared}; a reconciler keeps the Files app's index in sync with terminal writes.
  Storage moved to a shared `filedata` volume (CLAWMATES_STORAGE__DATA_DIR).

Obsidian vault (a markdown "second brain" per agent):
- New `vault` FileDrive (migration 0015) mounted into the terminal at ~/obsidian;
  a file-content read route; a purple Obsidian tile + a vault viewer app.

Computer UI:
- Draggable computer-panel width (min = phone preset) keeping the size presets.
- Green Terminal glyph, "Claw Chat" → "Chat", colored gradient-outline app icons.
- Agent page: avatar↔activity-grid spacing + larger, uniform section fonts with
  colored section-tinted tag chips.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
Omar Sobh
2026-06-23 16:52:35 -07:00
co-authored by Claude Opus 4.8
parent 671df7c622
commit e61724ff82
46 changed files with 2247 additions and 95 deletions
+6
View File
@@ -64,6 +64,8 @@ async fn spawn(suffix: &str) -> (K8sDriver, cm_sandbox::SandboxHandle) {
nano_cpus: 1_000_000_000,
pids_limit: 128,
egress: false,
kind: cm_sandbox::SandboxKind::Agent,
mounts: Vec::new(),
};
let handle = driver.provision(&spec).await.expect("pod provisions");
(driver, handle)
@@ -200,6 +202,8 @@ async fn localhost_seccomp_profile_denies_unshare_inside_pods() {
nano_cpus: 1_000_000_000,
pids_limit: 128,
egress: false,
kind: cm_sandbox::SandboxKind::Agent,
mounts: Vec::new(),
};
let handle = driver.provision(&spec).await.expect("pod provisions");
@@ -249,6 +253,8 @@ async fn calico_enforces_the_default_deny_egress() {
nano_cpus: 1_000_000_000,
pids_limit: 128,
egress: false,
kind: cm_sandbox::SandboxKind::Agent,
mounts: Vec::new(),
};
let handle = driver.provision(&spec).await.expect("pod provisions");