Actions
7 actions, callable from the panel, the command palette and the API as
POST /api/v1/a/<id>. Internal actions used between modules are not listed.
| Action | What it does | Risk | Preview |
|---|---|---|---|
terminal.session.open | Open a terminal | medium | No dry run |
terminal.root.open | Open a root terminal | critical | No dry run |
terminal.session.list | List terminal sessions (read) | low | No dry run |
terminal.session.kill | Kill a terminal session | medium | No dry run |
terminal.recording.list | List recordings (read) | low | No dry run |
terminal.recording.get | Read part of a recording (read) | low | No dry run |
terminal.recording.delete | Delete a recording | high | No dry run |
Permissions and limits
Permissions
terminal.useOpen a terminal in an accountterminal.viewSee terminal sessions and recordingsterminal.manageKill sessionsterminal.rootOpen a root terminal on a serverterminal.recording.manageDelete recordings
Plan limits
terminal.sessionsConcurrent terminal sessions
Engineering notes
Generated from modules/terminal/docs.md at build d90e9e2. These are the notes the engineers keep
next to the code: precise, technical, and honest about what is not done yet.
PTY on the account's server as the account Unix user (credential drop, in the account's cgroup slice — the agent
creates a conservative rc-acct-<u>.slice with TasksMax 1024 if the limits module has not made one), env
TERM=xterm-256color, UTF-8. No action runs a command (AC-terminal-21); the only entry is an interactive PTY.
Flow: terminal.session.open (limit terminal.sessions, sweep of dead sessions) -> agent terminal.pty.open ->
single-use ticket (random 32 bytes, only sha256 stored, 30 s) -> gateway redeems with internal
terminal.ticket.redeem (atomic UPDATE ... WHERE used_at IS NULL, caller must be the opener) -> stream on NATS
rc.pty.<node>.<session>.{in,out,ctl} (node-scoped: the bus lets each agent touch only its own sessions) with credit-based flow control (initial 256 KiB, 16 KiB frames), reattach replays the
last 256 KiB, idle warning at -60 s then close, max duration, asciinema v3 recording (output only unless
RecordInput) to /var/lib/respirecloud/recordings/<session>.cast (0600). Closing kills the shell and every
process left in its session (job-control children, fork bombs) but not setsid daemons (tmux).
Root terminal: admin kind, no impersonation, fresh step-up, always recorded, audited with the reason.
Settings (module settings JSON): record_users (default false), idle_minutes 30, session_max_minutes 480.
Next: shadow/live view, snippets, bubblewrap cage, recording encryption + storage upload, retention sweeper,
package/account/sub-user disable hooks, kill on suspension.