Stack: native Cloud VM (Postgres 16 + Redis + Spring Boot :8080 + Vite :3000 + Hermes :8787 + provisioner :8788). main at 7833f31 (post security PR #49). Redeployed backend from packaged dba-agent-backend-1.0.0.jar.
| Check | Result | Notes |
|---|---|---|
GET /api/actuator/health |
PASS | 200 |
| Anonymous Prometheus | PASS | 401 (not exposed) |
Login admin@localhost |
PASS | auth_token cookie |
| Connections list | PASS | 3 connections incl. demo_shop |
| Brain init status | PASS | COMPLETED / 100% |
/onboarding |
PASS | 200, title DeepSQL |
Agent session mcpAuthOk |
PASS | true after provisioner restart |
Agent Q&A (e2e-agent-check.py) |
PASS | execute_sql → demo_shop |
| Dashboard generate | PASS | HTML + deepsql.query |
| Kill malicious PID | PASS | 400 Invalid session id |
| Logout | PASS | subsequent /auth/me → 401 |
| MCP JS syntax | PASS | node --check clean |
| Hermes bind | PASS | 127.0.0.1:8787 |
- Provisioner must run current tree — an Aug-12
local-agent-provisioner.pyprocess lackedDEEPSQL_TOKEN_FILEwrites; restarting fromscripts/local-agent-provisioner.pyfixed profile token files. - Hermes webui caches MCP env — after rotating tokens / updating
~/.hermes/config.yaml, restarthermes-webuior Agent tab MCP calls 401 with stale env (USER_ID=deepsql-agent, noDEEPSQL_AUTH_TOKEN). Dashboard generate stayed green because it uses the channel-token path. - Syncing default
~/.hermes/config.yamlmcp_servers.deepsql.envfrom the activeu-adminprofile after provision keeps native/dev Agent tab healthy.
Functional smoke + agent/dashboard E2E are green for the v1.0.0 artifact cut. Remaining security Highs in OSS_SECURITY_REVIEW.md are documented, not blockers for this tagged OSS release.