惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Know Your Adversary
Know Your Adversary
C
CERT Recently Published Vulnerability Notes
V
Vulnerabilities – Threatpost
N
News | PayPal Newsroom
O
OpenAI News
A
About on SuperTechFans
月光博客
月光博客
Martin Fowler
Martin Fowler
L
LangChain Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V2EX - 技术
V2EX - 技术
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
人人都是产品经理
人人都是产品经理
T
Tor Project blog
D
DataBreaches.Net
Cloudbric
Cloudbric
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
云风的 BLOG
云风的 BLOG
F
Full Disclosure
S
SegmentFault 最新的问题
Vercel News
Vercel News
T
Tailwind CSS Blog
Schneier on Security
Schneier on Security
宝玉的分享
宝玉的分享
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
P
Privacy International News Feed
美团技术团队
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
Scott Helme
Scott Helme
Forbes - Security
Forbes - Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Announcements
Recent Announcements
AWS News Blog
AWS News Blog
Stack Overflow Blog
Stack Overflow Blog
S
Security Affairs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The GitHub Blog
The GitHub Blog
T
Tenable Blog
Cyberwarzone
Cyberwarzone
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
T
Threatpost

Show HN

GitHub - villagesql/villagesql-skills: Agent skills for VillageSQL - gemini-cli-extension; claude-code-plugin GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - rondoflow/rondoflow: RondoFlow is a local-first, open-source platform for visually orchestrating Claude Code AI agents. Use a drag-and-drop canvas to create agents, attach skills, define security policies, and run multi-agent workflows.
arzzen · 2026-06-25 · via Show HN

Build teams of Claude Code agents - visually.

Describe what you need on a drag-and-drop canvas, and RondoFlow assembles a team of specialized AI agents that plan, run, and improve the work together - locally, on your machine, with your files.

License: MIT Node.js TypeScript Status PRs Welcome

obrázok

What is RondoFlow?

Most "AI workflow" tools wire prompts together. RondoFlow orchestrates real Claude Code agents - so the agents on your canvas can actually read and write files, run commands, and use MCP tools and skills, all governed by safety policies you control. You compose them visually, hit Run, and watch the team execute in real time.

Why it's different

  • 🧩 Visual multi-agent canvas - drag agents, skills, safety rules, resources, and MCP connections onto a React Flow board and connect them into a workflow.
  • 🤖 Real agents that do things - agents are Claude Code CLI subprocesses, not just chat completions. They edit code, run tools, and stream their work back live.
  • 🎯 AI that steers the run - a Director evaluates each step mid-run and decides whether to continue, retry, or conclude; a Planner tunes the team before it starts; an Advisor reviews the result afterward.
  • 🔌 Multi-provider - mix Claude Code (local CLI), OpenAI, and Perplexity agents in the same workflow.
  • 🔒 Local-first & policy-governed - runs on your machine, talks to your files, and gates risky actions behind a three-layer safety model. Nothing leaves your box except the model API calls you configure.

Table of Contents

  • Features
  • How It Works
  • Documentation
  • Configuration
  • Development
  • Architecture
  • Contributing
  • Security
  • License
  • Community & Support

Local development

git clone https://github.com/rondoflow/rondoflow.git
cd rondoflow
npm run setup    # installs deps, generates .env, starts Postgres, migrates + seeds
npm run dev      # opens at http://localhost:3000

Full Docker (everything in containers)

git clone https://github.com/rondoflow/rondoflow.git
cd rondoflow
cp .env.example .env   # edit .env (see Configuration below)
docker compose up      # builds and starts all services

This starts five containers:

Container Port Role
rondoflow-postgres 5432 PostgreSQL database
rondoflow-server 3001 Fastify backend + Socket.IO + Claude Code CLI
rondoflow-ui 3000 Next.js frontend
rondoflow-docs 3002 Nextra documentation site (proxied at /docs)
rondoflow-migrate - Runs database migrations once, then exits

Then open http://localhost:3000.

Docker mode needs Docker Desktop only - Node.js is not required on the host.

First run

RondoFlow is invite-only - open self-registration is disabled, and an admin creates all accounts. Set RONDOFLOW_ADMIN_EMAIL and RONDOFLOW_ADMIN_PASSWORD in .env before you run setup; the seed step then bootstraps that first admin (it's skipped if either is blank).

  • Option A (local): npm run setup runs the seed for you, so the admin is created automatically.
  • Option B (Docker): the rondoflow-migrate container runs migrations only - run the seed step yourself (npm run db:seed, with the admin vars set and Postgres reachable) to create the first admin.

Sign in with that account (email/password). On first sign-in a short onboarding wizard walks you through picking a working directory and a work mode (Quick Start - describe a task and let RondoFlow build the team - or Full Control - assemble agents by hand). Admins can then create accounts for teammates from the Users panel. If the Claude Code CLI isn't detected, the app shows install instructions and waits.

Features

Visual canvas

Drag nodes onto an interactive board and connect them to define how work flows. Everything auto-saves.

Node types Assistants (agents), Skills, Safety Rules, Resources, Connections (MCP), Output, Condition (branching), Sticky Notes
Connections Flow edges (execution order), association edges (configuration), and conditional edges (branching from a Condition node)
Interaction Drag-and-drop palette, undo/redo (Ctrl+Z), keyboard shortcuts (?), command palette (Ctrl+K)
Workspaces Multiple project-based workspaces, each tied to a folder on your machine; export/import to share

Assistants & providers

Each Assistant has a provider, model, personality, skills, memory, and MCP connections - all configurable from the side panel.

Provider Models Notes
Claude Code (default) Opus / Sonnet / Haiku tiers Runs the local CLI; full tool, MCP, and skill access
OpenAI GPT / o-series API-based; optional web search
Perplexity Sonar family API-based; web-grounded research

The Workflow Generator picks a sensible model per agent automatically - you can always change it.

Smart execution - Planner, Director & Advisor

Three AI helpers reason about your run at different points:

  • Planner (before) - reviews the team, models, skills, and order; suggests improvements up front.
  • Director (during) - after each step, decides continue / redirect (retry with sharper instructions) / conclude, with a tunable criticism level and learnings it banks for next time.
  • Advisor (after) - compares the result against the objective and offers one-click fixes.

Team Discussions

Multiple Assistants brainstorm, review, or debate a topic while an automated Facilitator manages turn order and synthesizes a conclusion.

Workflow generation

Describe a task in plain English and RondoFlow designs a 2–5 agent workflow with personas, models, and skills, laid out as a DAG. Review and edit it before it hits the canvas - or start from a built-in template (Code Review, Content Team, Research, Brainstorm).

Skills

Skills are reusable instruction sets that give Assistants specialized abilities. RondoFlow ships built-in skills (Code Review, Writing Assistant, Data Analysis, API Designer, Test Writer) and you can install more from any Git repository.

Safety first

Three layers of policies - global, per-agent, and per-session - control what agents may do. The most restrictive policy always wins, risky commands require your approval, and budget limits prevent runaway costs. See SECURITY.md for the full model.

Users & roles

RondoFlow runs as a shared team workspace with three global roles: viewer (read-only), editor (create, edit, delete, and run workflows - Director / Planner / Advisor / Discussions included), and admin (everything an editor can do, plus user management and global settings). Accounts are invite-only - admins create users with a starting role from a Users panel and can change roles or deactivate/remove accounts; there is no open self-registration. Roles are enforced server-side on both the REST API and the realtime socket layer (viewers get a read-only canvas - palette hidden, nodes locked), and the UI mirrors those capabilities to hide affordances a role can't use. Admin user-management actions are written to the audit log.

More

Recurring Schedules (cron), iterative Loops (re-run an agent until a goal is met), an in-app Git panel (status, branches, commit, push), Memory that persists facts across runs, external folder mounts, and an audit log + analytics dashboard for monitoring and cost tracking.

How It Works

  1. Describe what you need in plain English - or pick a template.
  2. Review the AI-generated team of agents with their providers, models, and skills.
  3. Run the workflow on the canvas - watch agents execute in real time, with the Director steering between steps.
  4. Improve with Advisor analysis and one-click suggestions after each run.
flowchart TD
    A["Describe your task<br/>in plain English"] --> B["Workflow Generator builds<br/>a 2-5 agent team"]
    B --> C["Review and edit on the canvas"]
    C --> D["Planner tunes the team<br/>before the run"]
    D --> E["Run on the canvas"]
    E --> F["Agent runs a step"]
    F --> G{"Director evaluates<br/>the output"}
    G -->|continue| F
    G -->|redirect| F
    G -->|conclude| H["Advisor reviews the run"]
    H --> I(["Apply suggestions and<br/>re-run stronger"])
Loading

Documentation

Full documentation lives at docs.rondoflow.app. It's built with Nextra and the source ships in packages/docs - run it locally with:

npm run dev:docs   # http://localhost:3002/docs

Configuration

npm run setup generates a .env automatically. For Docker mode, copy .env.example and set:

  • BETTER_AUTH_SECRET - a random string, e.g. openssl rand -hex 32.
  • A Claude credential (required for Claude Code agents) - either ANTHROPIC_API_KEY (an Anthropic API key) or CLAUDE_CODE_OAUTH_TOKEN from claude setup-token to use your Claude subscription. If both are set, the setup token wins.
  • Claude Code telemetry - set CLAUDE_CODE_ENABLE_TELEMETRY, OTEL_METRICS_EXPORTER, OTEL_LOGS_EXPORTER, OTEL_EXPORTER_OTLP_PROTOCOL, and either the direct OTEL values (OTEL_EXPORTER_OTLP_ENDPOINT, OTEL_EXPORTER_OTLP_HEADERS, OTEL_RESOURCE_ATTRIBUTES) or the source vars they derive from (OTEL_ENDPOINT, AUTH_TOKEN, USER_EMAIL). The server forwards these into spawned Claude Code processes.
  • RONDOFLOW_ADMIN_EMAIL / RONDOFLOW_ADMIN_PASSWORD - bootstrap the first admin account. Required to get into a fresh instance, since self-registration is disabled (see First run).
Variable Required What it does
DATABASE_URL Auto PostgreSQL connection string
BETTER_AUTH_SECRET Yes Session encryption - random, never commit
BETTER_AUTH_URL Auto Backend URL
RONDOFLOW_ADMIN_EMAIL First run Email for the bootstrap admin, created at seed time (RondoFlow is invite-only)
RONDOFLOW_ADMIN_PASSWORD With email Password for the bootstrap admin - set alongside the email, then rotate after first login
RONDOFLOW_ADMIN_NAME No Display name for the bootstrap admin (default Administrator)
ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN For agents Claude credential (setup token wins if both set)
CLAUDE_CODE_ENABLE_TELEMETRY / OTEL_METRICS_EXPORTER / OTEL_LOGS_EXPORTER / OTEL_EXPORTER_OTLP_PROTOCOL No Enable Claude Code telemetry export when spawning agents
OTEL_ENDPOINT / AUTH_TOKEN / USER_EMAIL No Convenience source vars used to derive OTEL_EXPORTER_OTLP_ENDPOINT, OTEL_EXPORTER_OTLP_HEADERS, and OTEL_RESOURCE_ATTRIBUTES
OTEL_EXPORTER_OTLP_ENDPOINT / OTEL_EXPORTER_OTLP_HEADERS / OTEL_RESOURCE_ATTRIBUTES No Direct telemetry overrides forwarded to Claude Code if you prefer to set OTEL values explicitly
GITHUB_CLIENT_ID / GITHUB_CLIENT_SECRET No Enable GitHub login
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET No Enable Google login

Invite-only. Open self-registration is disabled - an admin creates all accounts. When RONDOFLOW_ADMIN_EMAIL and RONDOFLOW_ADMIN_PASSWORD are both set, the seed step (npm run db:seed, run for you by npm run setup) creates the first admin; leave both blank to skip.

OpenAI and Perplexity API keys are configured in the app's Settings (instance-wide, shared by all agents of that provider).

Email (SMTP)

The Email node sends a workflow's output via SMTP. Configure it with SMTP_* in .env, or at runtime in Settings → Credentials (a DB-stored value overrides .env; SMTP_PASS is stored encrypted). Leave SMTP_HOST blank to disable.

Variable Default What it does
SMTP_HOST - SMTP server hostname (blank disables email)
SMTP_PORT 587 SMTP port
SMTP_SECURE false true for implicit TLS (465), false for STARTTLS (587)
SMTP_USER / SMTP_PASS - SMTP credentials (SMTP_PASS encrypted if set in Settings)
SMTP_FROM - From address, e.g. RondoFlow <noreply@example.com>

Optional tuning

.env.example also documents optional variables not needed for a basic run:

Variable Default What it does
PORT / UI_ORIGIN 3001 / http://localhost:3000 Backend port and allowed UI origin (CORS)
CLAUDE_CODE_MAX_OUTPUT_TOKENS 128000 Max output tokens per agent response (clamped to each model's true max)
EXTERNAL_FOLDERS_HOST_PATH / EXTERNAL_FOLDERS_CONTAINER_ROOT ./external / /external Host directory bind-mounted into the server container, and the in-container root mounted folders resolve under (backs external-folder mounts)
RONDOFLOW_SPAWN_IDLE_TIMEOUT_MS / RONDOFLOW_SPAWN_MAX_MS 300000 / 0 Kill a run after this many ms with no stream events / absolute wall-clock cap per spawn (0 disables)
RONDOFLOW_TEARDOWN_ON_DISCONNECT / RONDOFLOW_TEARDOWN_GRACE_MS 1 / 60000 Tear down a user's in-flight runs after their last tab disconnects, following a grace window

Development

npm run dev              # start everything (turbo)
npm run dev:ui           # frontend only (port 3000)
npm run dev:server       # backend only (port 3001)
npm run dev:docs         # docs site only (port 3002)
npm run build            # build all packages
npm run lint             # lint all packages
npm run format           # format with Prettier
npm run test             # run all tests (turbo)
npm run test:coverage    # run all tests with coverage
npm run db:migrate       # run database migrations
npm run db:seed          # load sample data (and bootstrap the admin)
npm run db:studio        # visual database browser
npm run docker:up        # start PostgreSQL only (for local dev)
npm run docker:down      # stop containers

Tests: both the server and ui packages use Vitest. npm run test runs the whole suite via the turbo test task; scope to one package with npm test -w @rondoflow/server or npm test -w @rondoflow/ui. The same lint / build / test sequence runs in CI (.github/workflows/ci.yml).

Architecture

A canvas talks to a server over websocket. The server's engine walks your workflow as a DAG, runs each agent through the right provider, and gates risky actions behind the policy layer.

flowchart LR
    User(["You"]) -->|design and run| Canvas["Canvas UI<br/>React Flow"]
    Canvas <-->|Socket.IO live events| Engine

    subgraph Engine["Server: Fastify + Socket.IO"]
        Chain["ChainExecutor<br/>DAG runner"]
        Plan["Planner"]
        Dir["Director"]
        Adv["Advisor"]
        Pol["PolicyResolver<br/>safety rules"]
        Chain --- Plan
        Chain --- Dir
        Chain --- Adv
        Chain --- Pol
    end

    subgraph Runners["Agent runners"]
        CC["Claude Code CLI<br/>subprocess"]
        OAI["OpenAI API"]
        PPX["Perplexity API"]
    end

    Chain --> CC
    Chain --> OAI
    Chain --> PPX
    Engine <-->|Prisma| DB[("PostgreSQL")]
    CC -.->|tools, files, MCP| Host[("Your machine")]
Loading

A run streams back live - here's the flow for a single Claude Code agent step:

sequenceDiagram
    actor User
    participant UI as Browser
    participant Server as Server
    participant Agent as Claude Code CLI
    User->>UI: Run workflow
    UI->>Server: Socket.IO chain:execute
    loop each step in the DAG
        Server->>Agent: spawn (no shell) with stream-json output
        Agent-->>Server: stream events - text, tool_use, usage
        Server-->>UI: live text + tool-use cards
        opt risky command
            Server-->>UI: approval request
            UI-->>Server: approve or reject
            Server->>Agent: stdin response
        end
        Agent-->>Server: step complete
        Note over Server: Director decides continue / redirect / conclude
    end
    Server-->>UI: chain complete + token usage
Loading

Contributing

Contributions are welcome! Please read CONTRIBUTING.md for setup, code conventions, and the PR process. In short:

# Fork, clone, then:
npm run setup
npm run dev

# Before submitting a PR:
npm run build && npm run lint

Bug reports and feature requests go through the issue templates. By contributing, you agree your work is licensed under the project's MIT license.

Security

RondoFlow runs AI agents that can execute code on your machine, so please review the threat model and deployment guidance in SECURITY.md before exposing it beyond localhost. Found a vulnerability? Report it privately via GitHub's security advisories - please don't open a public issue.

License

MIT © RondoFlow contributors. RondoFlow began as a fork of Orchestra (also MIT) and has diverged substantially since, with the original copyright retained in LICENSE. Third-party dependency licenses are summarized in THIRD_PARTY_NOTICES.md.

Community & Support

Questions, ideas, and show-and-tell go in GitHub Discussions. Found a bug or have a feature request? Open one through the issue templates. For security issues, please use private security advisories rather than a public issue.