Operation Center Static snapshot generated 2026-04-21

Rod Hub — Operation Center

Single source-of-truth dashboard for the Rod Hub ecosystem — five CLI coding agents equalized with shared MCP servers, a 63-agent Rod-Agents hub, ~133 Docker containers across rod-server and rod-ml, 25+ public rodhub.ca subdomains, and an 8-account Google Workspace MCP layer. Every tile on this page is sourced from the forensic audit report (2026-04-21).
Critical Issues
2
Codex full-access / n8n JWT plaintext
High Issues
5
gws-mcp unregistered, http/.home drift, more
Medium Issues
5
ComfyUI models, catalog drift, etc.
Low Issues
3
Cosmetic or documentation drift
CLI Agents
5
Claude · Gemini · Qwen · Codex · OpenCode
MCP Servers
29
Core 6 · Docker 7 · Remote 10 · Extras 6
Rod-Agents (live)
63
Docs claim 105 — drift
Docker (rod-server)
96+
10 compose stacks
Docker (rod-ml)
37
GPU + dev stack
Public Domains
25+
All Traefik-routed
GWS Accounts
8
137-tool MCP (gws-mcp)
Hostinger Tools
119
MCP-connected

AI Token Usage

AI token telemetry has not loaded yet.
Minute-level consumption
not loaded
Claude 60m
--
waiting for snapshot
Codex 60m
--
waiting for snapshot
Today total
--
Claude + Codex local counters
Window total
--
last 7 days by minute
Codex limit
--
latest token_count event
Billing guardrail
--
account toggle is browser-side
Tokens per minute Claude Codex

Agent totals

AgentLast minute15m60mTodayWindowRequestsLatestStatus
Loading token telemetry...

Recent token events

TimeAgentTokensInput / Cache / OutputModelScopeProject
Loading token telemetry...

Severity Register (15 findings)

Each row links to the remediation line in the 14-point roadmap. Full evidence in the audit report.

#SeverityFindingSection
1CRITICALCodex runs approval_policy="never" + sandbox_mode="danger-full-access" with 0 MCPs registeredAgents
2CRITICALn8n JWT token stored in plaintext across 3 MCP registriesMCPs / Security
3HIGHgws-mcp (137 tools, 8 accounts) NOT registered in any agent configMCPs
4HIGH/mnt/e/github/ unreachable from sandbox; repos/ and github/ symlinks deadWorkspace
5HIGHWhatsApp + n8n integration documented but no workflow JSON on diskn8n/RPA
6HIGHGemini uses http:// for .home URLs; Traefik forces 301→HTTPS, breaks SSEAgents
7HIGHterminal-scanner.sh documented as load-bearing but file not presentRod-Agents
8MEDIUMComfyUI containers healthy but model volume empty (8 KB total)Infrastructure
9MEDIUMRod-Agents "105 agents" claim is inflated; live hub has 63 instancesRod-Agents
10MEDIUMinfra-status.sh cannot SSH rod-server from sandbox (missing key)Infrastructure
11MEDIUMTraefik dynamic.yml remote-only; local repo has 54-line stubExternal
12MEDIUMFour near-identical exporter variants; drift riskWorkspace
13LOWCATALOG_REPOS.md header count disagrees with row countWorkspace
14LOWNo hostinger-deploy.sh, no FTP creds, no rsync target for Hostinger mirrorExternal
15LOWCloudflare MCP live in session but not registered to any agentExternal

CLI Agent Ecosystem

Codex urgent: approval_policy="never" + sandbox_mode="danger-full-access" + 0 MCPs registered. Change to on-request and register the 6 core MCPs before next use.
AgentBinaryVersionInstructionMCPsApprovalURL schemeStatus
Claude CodeclaudeOpus 4.6CLAUDE.md19interactivehttps://OK
Gemini CLIgemini0.31.0GEMINI.md20interactivemixedHIGH
Qwen CLIqwen0.11.1QWEN.md15interactivehttps://behind
Codex CLIcodex0.106.0CODEX.md0neverCRIT
OpenCodeopencode1.2.1OPENCODE.md19interactivehttps://OK

Skills share .claude/skills/ via symlinks (fragile — single rm -rf breaks all 5). Agent .md mirrors last synced 2026-02-14.

MCP Server Inventory (29)

Core parity set (must be in all 5 agents)

#ServerTransportTargetClaudeGeminiQwenCodexOpenCode
1filesystemstdiorepos + rod_guides
2workspacestdio (FastMCP)repos wrapper
3catalogstdio (FastMCP)CATALOG_REPOS.md
4web-scraperstdioCrawl4AI + Playwright
5canliistdio35K decisions, 15 tools
6gws-mcpstreamable-http137 tools, 8 accounts

Docker MCPs on rod-server (_mcp-tools stack)

ServerURLTransportStatus
grafana-mcphttps://grafana-mcp.home/sseSSElive
huggingface-mcphttps://huggingface-mcp.home/mcpStreamable HTTPlive
pubmed-mcphttps://pubmed-mcp.home/sseSSElive
mermaid-mcphttps://mermaid-mcp.home/sseSSElive
notebooklmhttps://notebooklm-mcp.home/sseSSE (Patchright)live
transcript-correctionhttps://transcript-correction.home/mcpStreamable HTTPlive
comfyuihttp://10.0.1.3:8189 (stdio wrapper)stdio0 models

Remote / hosted MCPs

sci-papers
sci-papers.home/mcp
hostinger
119 tools · Empiric account
globalping
Network diagnostics
exa
AI web search
toolbox-db
Google multi-DB MCP
socket
Dep security scanning
pdf-tools
PDF read/merge/split
scholar-gateway
Wiley CONNECT
claude-memory
27K+ vectors · :8100
cloudflare
unregistered

Rod-Agents Hub

Count reality check: docs claim 105 agents, disk inventory shows 63 instance dirs. Dashboard API may report 105 because it counts placeholders. This Operation Center uses 63 as the honest number.
Agent instances (live)
63
in dev/Rod-Agents/src/rod_agents/
LangGraph steps
7
analyze→retrieve→reason→execute→synthesize→critique→update
LLM providers (fallback)
10
Claude→Codex→Gemini→Qwen→vLLM→Ollama + 4
Synthesis modes
7
CROSS_DOMAIN · CAUSAL · EMERGENT · CONTRASTIVE + 3

Running services

ContainerHostHealth
rod-agents-dashboardWSL :8080Healthy
rod-agents-qdrantWSLHealthy
rod-agents-redisWSLHealthy
rod-agents-watcherWSLUnhealthy
agent-chat-v3WSLUp
agent-chatrod-serverUp

Coordination layer (chat.rodhub.ca)

chat.*
Message bus — !battle !debate !research
agents.*
Dashboard — web UI :8080
agents-mcp.*
MCP gateway :9100
mem.*
Shared memory :37777

Drift: terminal-scanner.sh is referenced across multiple docs as the systemd-timer that populates /api/terminals/*, but the script is not in the repo tree. Either commit it or mark the terminal-broadcast feature aspirational.

Infrastructure

rod-server (10.0.1.6) — primary host

StackCompose projectContainersRole
Hostinghosting38Traefik, Portainer, Dockge, Nextcloud, Forgejo, n8n, HA, Ollama, Grafana, Pihole, Frigate, Redis, MariaDB, RustDesk, qBittorrent, SFTP, RomM, GWS-MCP, GWS-Portal
LibroSynth v3librosynth11API Gateway, Orchestrator, 4 engines, dashboard, Postgres :5433, RabbitMQ, MinIO, MCP
MCP Toolsmcp-tools4grafana-mcp, huggingface-mcp, pubmed-mcp, mermaid-mcp
Genomegenome-platform-stack6Orchestrator + 4 workers + nginx relay
Deep Researchdeep-research2API :8010 + Qdrant
Farmingfarming_innovation2Postgres :5434 + Adminer
Cryptocrypto-predictor2Predictor + Prometheus
Transcript Correctiontranscript-correction-mcp1FastAPI + FastMCP
Home Dashboardhome-dashboard1Nginx
Host servicesAudiobookshelf :13378, Plex :32400, Claude CLI Proxy :3300, LAN DNS

rod-ml / WSL (10.0.1.3) — development + GPU

StackContainersNotes
HRTO Litigation7case-binder, case-navigator, chatbot, evidence-api, filing-viewer, hrlsc-portal, nginx
Genomics (GPU)4portal-gpu, qdrant, redis, gene-iobio-ui
Deep Research2local mirror of rod-server
Ignition SCADA3gateway, postgres, redis
Debts App3api, package-worker, qdrant
Rod-Agents4dashboard, qdrant, redis, watcher
Agent chat1agent-chat-v3
Infrastructure7portainer/+agent, dockge, homepage, ollama, ml-service, ocr-rpa
Apps2postgres-fast, sanchez-budget-dashboard
ComfyUI2comfyui (RTX 4090), comfyui-api · 0 models
Telemetry note: this dashboard loads a static snapshot. To refresh with live container/domain status, run ./tools/cli/operation-center-refresh.sh on rod-ml (which SSH-es rod-server) — updated JSON lands at web/data/op-center.json.

n8n Workflows · RPA · CLI Proxies

AssetDocumentedOn diskStatus
n8n workflow JSONs5+1 (rod_agents_task_sync.json)gap
WhatsApp integrationdesign docabsentgap
Claude CLI proxy /v1/messagesyesmissingmissing endpoint
Claude CLI proxy /health, /chatyespresentOK
Agent proxies (Qwen/Gemini/Codex)3 systemd units3 presentOK
RPA agent YAMLs55OK
RPA scripts4343OK
Transcript-correction LLM chain6 providers6 providersOK

Proxy ports

Claude CLI Proxy
:3300
OAuth, no API key · rod-server host service
Qwen Proxy
:3301
coder-model · WSL systemd
Gemini Proxy
:3302
gemini-2.5-pro · WSL systemd
Codex Proxy
:3303
gpt-5.3-codex · WSL systemd

Hostinger · Cloudflare · External

AreaStatusNotes
Hostinger MCP registrations3/5 agentsClaude, Gemini, OpenCode · Qwen and Codex missing
Hostinger active accountEmpiricSSH 82.25.83.254:65002, user u765222744
hostinger-2 placeholderemptyNo real API token
Hostinger deploy scriptmissingNo hostinger-deploy.sh, no rsync target, no FTP creds, no GH Action
Operation Center Hostinger mirrornot set upSee deploy plan
Cloudflare domain registraractiverodhub.ca
Cloudflare DNSmanagedVia Cloudflare
Cloudflare credentialsenv varsrod_infrastructure/.env — no plaintext leak
Cloudflare MCPunregisteredLive in session · not in any Rod Hub agent config
Cloudflare Workers / KV / D1 / R2audit pendingNeeds Cloudflare MCP sweep

Security

CheckStatusEvidence
Hardcoded secrets in dev/ and services/cleangrep + file audit found none
n8n JWT in plaintext across 3 MCP registriesCRITconfig/claude.json, .gemini/settings.json, opencode.json
Codex approval_policy="never"CRIT.codex/config.toml
Codex sandbox_mode="danger-full-access"CRIT.codex/config.toml
env_files/ (51 files) secret auditnot runRecommend trufflehog filesystem env_files/
Cloudflare credentials scopescopedenv vars in rod_infrastructure/.env
GWS credentials locationisolatedDocker volume gws_creds, not on host FS
NotebookLM Patchright authisolatedDocker volume, not repo
Forgejo SSH :2224 public reachabilityunknownUFW config not inspected
Audiobookshelf :13378 / Plex :32400 exposureunknownHost services; LAN-only intended

14-Point Roadmap

Ordered by impact × urgency. Time-to-green (all HIGH+ closed): ~2 days. Time-to-excellent: 2–3 weeks.

#GapSeverityEffortOwnerOrder
1Codex: flip approval_policy to on-request, register 6 core MCPsCRIT30 minhumanDay 0
2Move n8n JWT + all plaintext tokens to env vars in all 4 registriesCRIT1 hhumanDay 0
3Register gws-mcp (137 tools) as streamable-http across all 5 agentsHIGH30 minhumanDay 0
4Fix Gemini http://https:// for all .home MCP URLsHIGH10 minhumanDay 0
5Commit or decommission terminal-scanner.shHIGH2 hhumanDay 1
6Build Operation Center dashboard (this pass produces v1)HIGH4 hClaudedone
7Set up SSH key from sandbox to rod-server for live telemetryHIGH15 minhumanDay 1
8Provision ComfyUI models (SDXL + FLUX.1 Schnell + T5-XXL + CLIP-L)MED45 min + transferhumanDay 2
9Implement 4 WhatsApp-n8n workflow JSONs per design docMED2–3 daysClaude+humanWeek 1
10Add /v1/messages to services/claude_proxy/main.pyMED1 hClaudeDay 1
11Clean CATALOG_REPOS.md — regenerate row count, add last_verified columnMED2 hClaudeDay 2
12Register Cloudflare MCP to all 5 agents; full Cloudflare account auditMED1 hClaudeDay 2
13Consolidate 4 exporter variants into single unified_exporter/MED1 dayClaudeWeek 1
14Plan + execute Hostinger mirror deploy (rsync + subdomain)LOW1 dayhumanWeek 2

Live Domain Grid

All public subdomains below route through rod-server Traefik (dual-access: .home local CA + .rodhub.ca Let's Encrypt).

Today's Deliverables

Dashboard
this page
web/operation-center.html
Wiring Scripts
5 scripts
tools/cli/operation-center-*.sh
Sub-audits (parallel)
8
Workspace · Agents · MCPs · Rod-Agents · Infra · n8n · dev/+services/ · External
Telemetry snapshot
static
web/data/op-center.json (refresh via script)

Wiring script summary

ScriptPurpose
operation-center-refresh.shRegenerate web/data/op-center.json by running infra-status --json on rod-ml and SSH-ing rod-server
operation-center-deploy-local.shCopy dashboard to ~/www/operation-center/ for local file-URL access
operation-center-deploy-rod-server.shrsync to rod-server + generate Traefik route stub for operation-center.home/.rodhub.ca
operation-center-deploy-hostinger.shHostinger rsync stub (SSH :65002); requires one-time FTP/SSH credentials
operation-center-verify.shcurl health check across all public domains + HTML render verification