Add deployment: Dockerfile, compose, proxy config, and docs
One container plus a Postgres behind any TLS-terminating proxy. Nothing is specific to a particular host. The app and API are served from a SINGLE origin. This is not tidiness: browser auth sessions live in per-origin storage, so splitting them across two hostnames makes sign-in loop in a way that presents as a server fault. The short alias redirects rather than serving a second origin. Two safety properties verified by running the image, not by reading the code: - With NODE_ENV=production and no SUPABASE_URL, the process refuses to start and says why. Serving the whole CRM unauthenticated is a worse outcome than failing to deploy, so the failure is deliberate and loud. - In production the development auth bypass does not apply: an unauthenticated request to /api/dashboard returns 401 rather than adopting the first user in the table. The Dockerfile typechecks all six packages as a build gate, so a deploy that does not compile fails at build time rather than in front of a user. Runtime runs unprivileged as `node`, and Postgres is not published to the host. Docs cover the ontology and why it is shaped this way, agent connection for Claude Code / Codex / prime-agent / Buzz, and the provenance rules governing seed data about real people — including how to have your record removed. Verified: image builds, container reports healthy, serves the SPA, enforces auth, and the production guard exits non-zero. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
# Connecting an agent
|
||||
|
||||
PIG is a first-class application for agents. The same MCP server serves every
|
||||
client, so nobody is asked to use a different tool than the one they already
|
||||
work in.
|
||||
|
||||
## What connects
|
||||
|
||||
| Client | How |
|
||||
|---|---|
|
||||
| **Claude Code** | `claude mcp add pig -- npx -y @pig/mcp` |
|
||||
| **Codex** | Add PIG as an MCP server in its config, with the same env vars |
|
||||
| **prime-agent** | It is an MCP *client*; add PIG through `/mcp` |
|
||||
| **Buzz** | Agents reach PIG through the ACP bridge's MCP support |
|
||||
|
||||
## Setup
|
||||
|
||||
Create an API key in PIG under **Settings → API keys**, then:
|
||||
|
||||
```bash
|
||||
export PIG_URL=https://primeintellectgrowth.com
|
||||
export PIG_API_KEY=pig_...
|
||||
```
|
||||
|
||||
Scope the key to `read` unless the agent genuinely needs to write. An agent
|
||||
acting for you is a **separate principal** from you: it has its own audit trail
|
||||
and can be revoked without disturbing your session, and it can never reach
|
||||
further than you can.
|
||||
|
||||
## The tools
|
||||
|
||||
| Tool | What it answers |
|
||||
|---|---|
|
||||
| `pig_whoami` | Who am I acting for, and which teams am I on? |
|
||||
| `pig_my_pipeline` | Where are we? What needs attention? |
|
||||
| `pig_capacity_match` | What have we bought that would serve this customer? |
|
||||
| `pig_margin_report` | What is each block earning against what it cost? |
|
||||
| `pig_idle_capacity` | What are we paying for and not selling? |
|
||||
| `pig_inventory_search` | What could we buy to cover demand we cannot serve? |
|
||||
| `pig_search` | Find an account |
|
||||
| `pig_get_account` | Everything about one account |
|
||||
| `pig_log_activity` | Record a call, meeting or note |
|
||||
|
||||
`pig_capacity_match` is the one worth learning. Ask it in plain language:
|
||||
|
||||
> "A customer wants 128 H100s with InfiniBand for three months, ceiling $2.80
|
||||
> per GPU-hour. What have we got?"
|
||||
|
||||
It returns ranked matches, preferring blocks that are sitting idle — those
|
||||
hours are already paid for — and warns explicitly when a match would sell below
|
||||
break-even.
|
||||
|
||||
## Why the surface is small
|
||||
|
||||
Nine tools, each doing one thing. A sprawling tool list measurably degrades
|
||||
model performance, and anything genuinely niche is reachable through
|
||||
`pig_search` or the HTTP API. If you need something that is not here, it is
|
||||
probably better added as a service method than as a tenth tool.
|
||||
|
||||
## What it cannot do
|
||||
|
||||
The MCP server holds an API key and calls the same HTTP API a browser does. It
|
||||
has no database credentials and no privileged path. There is deliberately no
|
||||
tool that provisions infrastructure, spends money, or emails a customer.
|
||||
Reference in New Issue
Block a user