Rod Hub — Operation Center
Single source-of-truth dashboard for the Rod Hub ecosystem — five CLI coding agents equalized with shared MCP servers, a 63-agent Rod-Agents hub, ~133 Docker containers across rod-server and rod-ml, 25+ public rodhub.ca subdomains, and an 8-account Google Workspace MCP layer. Every tile on this page is sourced from the forensic audit report (2026-04-21).
Critical Issues
2
Codex full-access / n8n JWT plaintext
High Issues
5
gws-mcp unregistered, http/.home drift, more
Medium Issues
5
ComfyUI models, catalog drift, etc.
Low Issues
3
Cosmetic or documentation drift
CLI Agents
5
Claude · Gemini · Qwen · Codex · OpenCode
MCP Servers
29
Core 6 · Docker 7 · Remote 10 · Extras 6
Rod-Agents (live)
63
Docs claim 105 — drift
Docker (rod-server)
96+
10 compose stacks
Docker (rod-ml)
37
GPU + dev stack
Public Domains
25+
All Traefik-routed
GWS Accounts
8
137-tool MCP (gws-mcp)
Hostinger Tools
119
MCP-connected
AI Token Usage
AI token telemetry has not loaded yet.
Claude 60m
--
waiting for snapshot
Codex 60m
--
waiting for snapshot
Today total
--
Claude + Codex local counters
Window total
--
last 7 days by minute
Codex limit
--
latest token_count event
Billing guardrail
--
account toggle is browser-side
Tokens per minute
Claude
Codex
No token events in the selected range.
Agent totals
| Agent | Last minute | 15m | 60m | Today | Window | Requests | Latest | Status |
|---|---|---|---|---|---|---|---|---|
| Loading token telemetry... | ||||||||
Recent token events
| Time | Agent | Tokens | Input / Cache / Output | Model | Scope | Project |
|---|---|---|---|---|---|---|
| Loading token telemetry... | ||||||
Severity Register (15 findings)
Each row links to the remediation line in the 14-point roadmap. Full evidence in the audit report.
| # | Severity | Finding | Section |
|---|---|---|---|
| 1 | CRITICAL | Codex runs approval_policy="never" + sandbox_mode="danger-full-access" with 0 MCPs registered | Agents |
| 2 | CRITICAL | n8n JWT token stored in plaintext across 3 MCP registries | MCPs / Security |
| 3 | HIGH | gws-mcp (137 tools, 8 accounts) NOT registered in any agent config | MCPs |
| 4 | HIGH | /mnt/e/github/ unreachable from sandbox; repos/ and github/ symlinks dead | Workspace |
| 5 | HIGH | WhatsApp + n8n integration documented but no workflow JSON on disk | n8n/RPA |
| 6 | HIGH | Gemini uses http:// for .home URLs; Traefik forces 301→HTTPS, breaks SSE | Agents |
| 7 | HIGH | terminal-scanner.sh documented as load-bearing but file not present | Rod-Agents |
| 8 | MEDIUM | ComfyUI containers healthy but model volume empty (8 KB total) | Infrastructure |
| 9 | MEDIUM | Rod-Agents "105 agents" claim is inflated; live hub has 63 instances | Rod-Agents |
| 10 | MEDIUM | infra-status.sh cannot SSH rod-server from sandbox (missing key) | Infrastructure |
| 11 | MEDIUM | Traefik dynamic.yml remote-only; local repo has 54-line stub | External |
| 12 | MEDIUM | Four near-identical exporter variants; drift risk | Workspace |
| 13 | LOW | CATALOG_REPOS.md header count disagrees with row count | Workspace |
| 14 | LOW | No hostinger-deploy.sh, no FTP creds, no rsync target for Hostinger mirror | External |
| 15 | LOW | Cloudflare MCP live in session but not registered to any agent | External |
CLI Agent Ecosystem
Codex urgent:
approval_policy="never" + sandbox_mode="danger-full-access" + 0 MCPs registered. Change to on-request and register the 6 core MCPs before next use.| Agent | Binary | Version | Instruction | MCPs | Approval | URL scheme | Status |
|---|---|---|---|---|---|---|---|
| Claude Code | claude | Opus 4.6 | CLAUDE.md | 19 | interactive | https:// | OK |
| Gemini CLI | gemini | 0.31.0 | GEMINI.md | 20 | interactive | mixed | HIGH |
| Qwen CLI | qwen | 0.11.1 | QWEN.md | 15 | interactive | https:// | behind |
| Codex CLI | codex | 0.106.0 | CODEX.md | 0 | never | — | CRIT |
| OpenCode | opencode | 1.2.1 | OPENCODE.md | 19 | interactive | https:// | OK |
Skills share .claude/skills/ via symlinks (fragile — single rm -rf breaks all 5). Agent .md mirrors last synced 2026-02-14.
MCP Server Inventory (29)
Core parity set (must be in all 5 agents)
| # | Server | Transport | Target | Claude | Gemini | Qwen | Codex | OpenCode |
|---|---|---|---|---|---|---|---|---|
| 1 | filesystem | stdio | repos + rod_guides | ✅ | ✅ | ✅ | ✅ | ✅ |
| 2 | workspace | stdio (FastMCP) | repos wrapper | ✅ | ✅ | ✅ | ❌ | ✅ |
| 3 | catalog | stdio (FastMCP) | CATALOG_REPOS.md | ✅ | ✅ | ✅ | ❌ | ✅ |
| 4 | web-scraper | stdio | Crawl4AI + Playwright | ✅ | ✅ | ❌ | ❌ | ✅ |
| 5 | canlii | stdio | 35K decisions, 15 tools | ✅ | ✅ | ❌ | ❌ | ✅ |
| 6 | gws-mcp | streamable-http | 137 tools, 8 accounts | ❌ | ❌ | ❌ | ❌ | ❌ |
Docker MCPs on rod-server (_mcp-tools stack)
| Server | URL | Transport | Status |
|---|---|---|---|
| grafana-mcp | https://grafana-mcp.home/sse | SSE | live |
| huggingface-mcp | https://huggingface-mcp.home/mcp | Streamable HTTP | live |
| pubmed-mcp | https://pubmed-mcp.home/sse | SSE | live |
| mermaid-mcp | https://mermaid-mcp.home/sse | SSE | live |
| notebooklm | https://notebooklm-mcp.home/sse | SSE (Patchright) | live |
| transcript-correction | https://transcript-correction.home/mcp | Streamable HTTP | live |
| comfyui | http://10.0.1.3:8189 (stdio wrapper) | stdio | 0 models |
Remote / hosted MCPs
sci-papers
sci-papers.home/mcp
hostinger
119 tools · Empiric account
globalping
Network diagnostics
exa
AI web search
toolbox-db
Google multi-DB MCP
socket
Dep security scanning
pdf-tools
PDF read/merge/split
scholar-gateway
Wiley CONNECT
claude-memory
27K+ vectors · :8100
cloudflare
unregistered
Rod-Agents Hub
Count reality check: docs claim 105 agents, disk inventory shows 63 instance dirs. Dashboard API may report 105 because it counts placeholders. This Operation Center uses 63 as the honest number.
Agent instances (live)
63
in
dev/Rod-Agents/src/rod_agents/LangGraph steps
7
analyze→retrieve→reason→execute→synthesize→critique→update
LLM providers (fallback)
10
Claude→Codex→Gemini→Qwen→vLLM→Ollama + 4
Synthesis modes
7
CROSS_DOMAIN · CAUSAL · EMERGENT · CONTRASTIVE + 3
Running services
| Container | Host | Health |
|---|---|---|
| rod-agents-dashboard | WSL :8080 | Healthy |
| rod-agents-qdrant | WSL | Healthy |
| rod-agents-redis | WSL | Healthy |
| rod-agents-watcher | WSL | Unhealthy |
| agent-chat-v3 | WSL | Up |
| agent-chat | rod-server | Up |
Coordination layer (chat.rodhub.ca)
chat.*
Message bus — !battle !debate !research
agents.*
Dashboard — web UI :8080
agents-mcp.*
MCP gateway :9100
mem.*
Shared memory :37777
Drift: terminal-scanner.sh is referenced across multiple docs as the systemd-timer that populates /api/terminals/*, but the script is not in the repo tree. Either commit it or mark the terminal-broadcast feature aspirational.
Infrastructure
rod-server (10.0.1.6) — primary host
| Stack | Compose project | Containers | Role |
|---|---|---|---|
| Hosting | hosting | 38 | Traefik, Portainer, Dockge, Nextcloud, Forgejo, n8n, HA, Ollama, Grafana, Pihole, Frigate, Redis, MariaDB, RustDesk, qBittorrent, SFTP, RomM, GWS-MCP, GWS-Portal |
| LibroSynth v3 | librosynth | 11 | API Gateway, Orchestrator, 4 engines, dashboard, Postgres :5433, RabbitMQ, MinIO, MCP |
| MCP Tools | mcp-tools | 4 | grafana-mcp, huggingface-mcp, pubmed-mcp, mermaid-mcp |
| Genome | genome-platform-stack | 6 | Orchestrator + 4 workers + nginx relay |
| Deep Research | deep-research | 2 | API :8010 + Qdrant |
| Farming | farming_innovation | 2 | Postgres :5434 + Adminer |
| Crypto | crypto-predictor | 2 | Predictor + Prometheus |
| Transcript Correction | transcript-correction-mcp | 1 | FastAPI + FastMCP |
| Home Dashboard | home-dashboard | 1 | Nginx |
| Host services | — | — | Audiobookshelf :13378, Plex :32400, Claude CLI Proxy :3300, LAN DNS |
rod-ml / WSL (10.0.1.3) — development + GPU
| Stack | Containers | Notes |
|---|---|---|
| HRTO Litigation | 7 | case-binder, case-navigator, chatbot, evidence-api, filing-viewer, hrlsc-portal, nginx |
| Genomics (GPU) | 4 | portal-gpu, qdrant, redis, gene-iobio-ui |
| Deep Research | 2 | local mirror of rod-server |
| Ignition SCADA | 3 | gateway, postgres, redis |
| Debts App | 3 | api, package-worker, qdrant |
| Rod-Agents | 4 | dashboard, qdrant, redis, watcher |
| Agent chat | 1 | agent-chat-v3 |
| Infrastructure | 7 | portainer/+agent, dockge, homepage, ollama, ml-service, ocr-rpa |
| Apps | 2 | postgres-fast, sanchez-budget-dashboard |
| ComfyUI | 2 | comfyui (RTX 4090), comfyui-api · 0 models |
Telemetry note: this dashboard loads a static snapshot. To refresh with live container/domain status, run
./tools/cli/operation-center-refresh.sh on rod-ml (which SSH-es rod-server) — updated JSON lands at web/data/op-center.json.n8n Workflows · RPA · CLI Proxies
| Asset | Documented | On disk | Status |
|---|---|---|---|
| n8n workflow JSONs | 5+ | 1 (rod_agents_task_sync.json) | gap |
| WhatsApp integration | design doc | absent | gap |
Claude CLI proxy /v1/messages | yes | missing | missing endpoint |
Claude CLI proxy /health, /chat | yes | present | OK |
| Agent proxies (Qwen/Gemini/Codex) | 3 systemd units | 3 present | OK |
| RPA agent YAMLs | 5 | 5 | OK |
| RPA scripts | 43 | 43 | OK |
| Transcript-correction LLM chain | 6 providers | 6 providers | OK |
Proxy ports
Claude CLI Proxy
:3300
OAuth, no API key · rod-server host service
Qwen Proxy
:3301
coder-model · WSL systemd
Gemini Proxy
:3302
gemini-2.5-pro · WSL systemd
Codex Proxy
:3303
gpt-5.3-codex · WSL systemd
Hostinger · Cloudflare · External
| Area | Status | Notes |
|---|---|---|
| Hostinger MCP registrations | 3/5 agents | Claude, Gemini, OpenCode · Qwen and Codex missing |
| Hostinger active account | Empiric | SSH 82.25.83.254:65002, user u765222744 |
hostinger-2 placeholder | empty | No real API token |
| Hostinger deploy script | missing | No hostinger-deploy.sh, no rsync target, no FTP creds, no GH Action |
| Operation Center Hostinger mirror | not set up | See deploy plan |
| Cloudflare domain registrar | active | rodhub.ca |
| Cloudflare DNS | managed | Via Cloudflare |
| Cloudflare credentials | env vars | rod_infrastructure/.env — no plaintext leak |
| Cloudflare MCP | unregistered | Live in session · not in any Rod Hub agent config |
| Cloudflare Workers / KV / D1 / R2 | audit pending | Needs Cloudflare MCP sweep |
Security
| Check | Status | Evidence |
|---|---|---|
Hardcoded secrets in dev/ and services/ | clean | grep + file audit found none |
| n8n JWT in plaintext across 3 MCP registries | CRIT | config/claude.json, .gemini/settings.json, opencode.json |
Codex approval_policy="never" | CRIT | .codex/config.toml |
Codex sandbox_mode="danger-full-access" | CRIT | .codex/config.toml |
env_files/ (51 files) secret audit | not run | Recommend trufflehog filesystem env_files/ |
| Cloudflare credentials scope | scoped | env vars in rod_infrastructure/.env |
| GWS credentials location | isolated | Docker volume gws_creds, not on host FS |
| NotebookLM Patchright auth | isolated | Docker volume, not repo |
| Forgejo SSH :2224 public reachability | unknown | UFW config not inspected |
| Audiobookshelf :13378 / Plex :32400 exposure | unknown | Host services; LAN-only intended |
14-Point Roadmap
Ordered by impact × urgency. Time-to-green (all HIGH+ closed): ~2 days. Time-to-excellent: 2–3 weeks.
| # | Gap | Severity | Effort | Owner | Order |
|---|---|---|---|---|---|
| 1 | Codex: flip approval_policy to on-request, register 6 core MCPs | CRIT | 30 min | human | Day 0 |
| 2 | Move n8n JWT + all plaintext tokens to env vars in all 4 registries | CRIT | 1 h | human | Day 0 |
| 3 | Register gws-mcp (137 tools) as streamable-http across all 5 agents | HIGH | 30 min | human | Day 0 |
| 4 | Fix Gemini http:// → https:// for all .home MCP URLs | HIGH | 10 min | human | Day 0 |
| 5 | Commit or decommission terminal-scanner.sh | HIGH | 2 h | human | Day 1 |
| 6 | Build Operation Center dashboard (this pass produces v1) | HIGH | 4 h | Claude | done |
| 7 | Set up SSH key from sandbox to rod-server for live telemetry | HIGH | 15 min | human | Day 1 |
| 8 | Provision ComfyUI models (SDXL + FLUX.1 Schnell + T5-XXL + CLIP-L) | MED | 45 min + transfer | human | Day 2 |
| 9 | Implement 4 WhatsApp-n8n workflow JSONs per design doc | MED | 2–3 days | Claude+human | Week 1 |
| 10 | Add /v1/messages to services/claude_proxy/main.py | MED | 1 h | Claude | Day 1 |
| 11 | Clean CATALOG_REPOS.md — regenerate row count, add last_verified column | MED | 2 h | Claude | Day 2 |
| 12 | Register Cloudflare MCP to all 5 agents; full Cloudflare account audit | MED | 1 h | Claude | Day 2 |
| 13 | Consolidate 4 exporter variants into single unified_exporter/ | MED | 1 day | Claude | Week 1 |
| 14 | Plan + execute Hostinger mirror deploy (rsync + subdomain) | LOW | 1 day | human | Week 2 |
Live Domain Grid
All public subdomains below route through rod-server Traefik (dual-access: .home local CA + .rodhub.ca Let's Encrypt).
dashboardhomepage
agentsRod-Agents UI
chatagent coord
gws-mcpGWS portal
librosynthAI platform
grafanametrics
portainerdocker
dockgecompose
traefikrouting
gitlabForgejo
n8nworkflows
homeassistantHA
nextcloudfiles
vaultvaultwarden
ollamalocal LLM
piholeDNS
kavitaeBooks
frigateNVR
filesfile browser
terminalttyd
qbittorrentdownloads
phpmyadminMariaDB
mcpproxy
comfyuiimage gen
omadanetwork
cryptopredictor
ecosystemlive inventory
Today's Deliverables
Dashboard
this page
web/operation-center.htmlWiring Scripts
5 scripts
tools/cli/operation-center-*.shSub-audits (parallel)
8
Workspace · Agents · MCPs · Rod-Agents · Infra · n8n ·
dev/+services/ · ExternalTelemetry snapshot
static
web/data/op-center.json (refresh via script)Wiring script summary
| Script | Purpose |
|---|---|
operation-center-refresh.sh | Regenerate web/data/op-center.json by running infra-status --json on rod-ml and SSH-ing rod-server |
operation-center-deploy-local.sh | Copy dashboard to ~/www/operation-center/ for local file-URL access |
operation-center-deploy-rod-server.sh | rsync to rod-server + generate Traefik route stub for operation-center.home/.rodhub.ca |
operation-center-deploy-hostinger.sh | Hostinger rsync stub (SSH :65002); requires one-time FTP/SSH credentials |
operation-center-verify.sh | curl health check across all public domains + HTML render verification |