Slices 1-3 of the local agent IPC surface: - Read model (local_status.go, loop wired): update counts, scanner status, check-in state, token receipt counts — no token material exposed - Local IPC (localapi/): Unix socket (group=redflag-local, 0660) + Windows named pipe (SDDL: LocalSystem/Admins/RedFlagLocal); five read-only endpoints - `redflag-agent -local-status` CLI probe of the local API surface - Screenshot capture handler (screenshot.go, dispatch wired) - Tauri desktop spine (desktop/): tray icon, left-click window, local IPC reader - Desktop React entry (web/src/desktop/LocalAgentApp.tsx, index.desktop.html, vite.desktop.config.ts) - Installer group provisioning: linux.sh creates redflag-local, sets SupplementaryGroups; windows.ps1 creates RedFlagLocal security group - Server-side: screenshot receipt handler on agents, updates handler additions - web/package.json: @tauri-apps/api + tauri CLI dev dep added
507 B
507 B
RedFlag Desktop
Tauri shell for the same RedFlag app in local-agent context.
The desktop shell does not read protected config or state files. Its Rust backend talks to the existing agent local IPC surface:
- Linux:
/var/lib/redflag/agent/localapi/redflag-agent.sock - Windows:
\\.\pipe\RedFlagAgentLocal
The frontend entry is web/index.desktop.html and web/src/desktop/main.tsx.
Fleet-server context should be added to this same app later rather than creating a second
local-only application.