@harness-fe/gateway
v4.5.0
Published
Harness-FE gateway: the only front door. Embeds @harness-fe/core in-process and exposes /mcp (agent MCP, RBAC + scoped manifest + audit), /ws (runtime WS, write scope), and /console (data + governance API). Policy: Open (solo loopback) | Governed (team to
Downloads
648
Readme
@harness-fe/gateway
Governance gateway for Harness-FE — token + RBAC + project→agent binding + audit + admin, sitting in front of one or more daemons. Team mode only; solo dev doesn't need it (the agent talks to a loopback daemon directly).
Zero native deps — JSON file store + node:crypto scrypt.
New to harness-fe? Start with the agent setup guide and install the skill first.
What it does
Agents reach a shared daemon only through the gateway, which:
- verifies the caller's token → identity + scope + project grants
- gates by scope (RBAC):
control/read/write - routes by token → target daemon, injecting the verified caller (
x-harness-caller+x-harness-projects) - filters
tools/listby scope (dynamic manifest — areadtoken never seespage.*) - audits every call (append-only)
- serves an HTML admin panel (servers / tokens / audit)
The gateway never implements tools or holds data — that's the daemon.
Run
harness-gateway --port 47950 --data-dir ~/.harness-fe/gateway \
--admin-user admin --admin-pass "$PW" \
--add-server name=team,endpoint=http://127.0.0.1:47900,token="$DAEMON_SECRET" \
--issue-token name=agentA,server=team,scopes=read+control,projects=my-app| Flag | Meaning |
|---|---|
| --port / --host | bind (default 47950 / 127.0.0.1) |
| --data-dir | store dir (default ~/.harness-fe/gateway) |
| --admin-user / --admin-pass | bootstrap the first admin (only if none exists) |
| --add-server name=,endpoint=,token= | register an upstream daemon (idempotent by name) |
| --issue-token name=,server=,scopes=read+control[,projects=a+b] | mint a scoped token, printed once. No projects ⇒ * (all) |
Full guide: docs/gateway-team-mode.md. One-command demo: bash scripts/demo.sh.
Library
import { createGateway, GatewayStore } from '@harness-fe/gateway';
const store = new GatewayStore('/path/to/data');
const gw = createGateway({ store });
await gw.listen(47950);License
MIT
