CW-031 · A public demo instance, on Render
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- docker, typescript
- Domain
- backend, cloud, devops, documentation
Research direction
Start with docs/backlog.md, docs/, README.md, and the deployment configuration to understand the current local setup and the phase-3 blocker. Confirm the LLM funding decision and map the hosted reset, demo sign-in, assistant limits, and deployment work to the stated acceptance criteria: a visitor can approve leave within a minute and cannot exceed the spending cap.
Written by the indexing model from the issue text.
Description
Priority P2 · Area project · Estimate M · Phase 3, first
Evaluating Cwork means cloning it, writing an .env, running compose, migrating and seeding. The README's screenshots help, but nobody can try an approval flow from a picture. The landing page's only button is a download, and the people it is written for (HR managers and owners) cannot act on that on their own.
Decided 2026-09-25: no budget for the demo's LLM usage, so the assistant is off in the demo. Asking visitors for their own API key was never an option. It trains people to paste credentials into unfamiliar sites, and would make this project the holder of other people's keys. The recorded walkthrough, already shipped in Thai and English, is what shows the assistant.
Decided 2026-09-26: hosted on Render, and first in phase 3. The owner creates the Render account and services; everything else is in the repository, so the demo can be rebuilt from the repository alone and nobody has to remember how it was set up.
Scope
- A hosted instance, writable, so an approval flow can be tried end to end.
- Sign-in as employee, manager or HR in one click. Nobody types a password or a two-factor code, and no working password appears on the page, in the repository or in the landing page. The demo accounts' password is generated at deploy time and never shown.
- Demo mode cannot be turned on by one mistaken variable. Whatever enables the one-click sign-in and the reset must refuse to run on a database holding an organisation the demo seed did not create. It should refuse rather than wipe, and refuse rather than open. The seed's
assertDemoDatabaseis the precedent. - The data resets to the seed at least hourly. A banner says when the next reset is, and a visitor who arrives mid-reset sees a message rather than an error.
- Nothing a visitor does can lock the next visitor out before the reset. The obvious routes are changing a demo account's password or 2FA, deactivating it, revoking its sessions, changing its role, and tripping the lockout.
- Off in the demo: the assistant (CW-027 already hides it), email and push, and file uploads. Uploads are unscanned without ClamAV, and a public demo would serve whatever anybody uploads to the next visitor.
- The demo links to the recorded walkthrough, for the assistant.
- Landing page (
landing/, both languages): the main button becomes "ลองใช้ทันที" / "Try it now", which opens the demo for HR. Download moves to a second path, "ติดตั้งเอง" / "Install it yourself", which points IT at GitHub and#install. - A runbook in
docs/covering how the demo is deployed, where its secrets live, and what to do when something on Render expires.
To check against Render before building
render.com could not be reached from the PO session, so these are assumptions, not facts. Each one changes the design if it holds:
| Assumption about the free tier | If true, the ticket needs |
|---|---|
| Web services sleep when idle, and the first request waits about a minute | The one-minute acceptance below is measured from a sleeping instance, or the landing page wakes it. Pinging it to keep it awake is not an answer; see the hours row. |
| Free instance hours per month are capped | Two services that sleep fit; two kept awake may not. |
| Free Postgres expires after about a month, one per account | Replacing it is a runbook step that needs no code change. Only DATABASE_URL changes. |
| Cron jobs are not free | The reset cannot be a Render cron job. It also cannot be an endpoint anyone on the internet can call. |
| Free services cannot receive private-network traffic, and pre-deploy commands are paid | web/nginx.conf proxies to a fixed api:3000, and the runtime image ships no Prisma CLI, so it cannot migrate or seed by itself. |
Render Postgres offers pgvector |
The init migration runs CREATE EXTENSION "vector" unconditionally. |
| A free instance has about 512 MB of memory | The seed boots the whole application to create history (db:demo), and has only ever run on a developer machine. |
Record what was found in the runbook. If the free tier cannot meet the acceptance, say which part and what it would cost, and bring it back to the PO rather than trimming the acceptance.
Acceptance
- Someone with no local setup can approve a leave request within a minute of opening the link.
- Each of the three roles signs in with one click, and no working password exists anywhere a visitor can read.
- Pointing the demo configuration at a database that holds a real organisation makes it refuse to start, with a message. Nothing is wiped. A test proves it.
- After any sequence of actions available in the console, all three one-click sign-ins still work. A test covers each route listed in the scope.
- The data returns to the seed on schedule without anyone doing anything.
- The landing page's first button opens the demo, in both languages.
- The demo can be rebuilt from the repository and the runbook, by someone who has not seen it before.
Files landing/, docs/, README.md, web/, backend/, deployment configuration
Tracked in docs/backlog.md.
- Dominant language
- TypeScript
- Stars
- 0
- Forks
- 0
- Avg merge
- 37m
- Merged PRs (30d)
- 1
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from SuruchBoss/Cwork
-
documentation good first issue P3 phase-E
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
SuruchBoss/Cwork#50 ·
-
good first issue mobile P2
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SuruchBoss/Cwork#11 ·
-
P1 payroll phase-3
Difficulty 5/5 Over a week Newbie friendliness 30/100
SuruchBoss/Cwork#59 ·
-
P2 phase-3
Difficulty 5/5 Over a week Newbie friendliness 45/100
SuruchBoss/Cwork#58 ·
-
P3 project
Difficulty 3/5 1-2 days Newbie friendliness 76/100
SuruchBoss/Cwork#56 ·
All issues in SuruchBoss/Cwork
Similar issues
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
inu-appcenter/memorIN-frontend#106 ·
Maintainers usually reply within 1 day
-
kind/bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 7 days
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
CSCfi/sd-search-ui#145 ·
Maintainers usually reply within 1 day
-
Add: Cbeebies pl SDOpencheck:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day