2026-04-20 19:20:15 +00:00
|
|
|
apiVersion: apps/v1
|
|
|
|
|
kind: Deployment
|
|
|
|
|
metadata:
|
|
|
|
|
name: hermes-agent
|
|
|
|
|
namespace: customer1
|
|
|
|
|
spec:
|
|
|
|
|
replicas: 1
|
|
|
|
|
selector:
|
|
|
|
|
matchLabels:
|
|
|
|
|
app: hermes-agent
|
|
|
|
|
template:
|
|
|
|
|
metadata:
|
|
|
|
|
labels:
|
|
|
|
|
app: hermes-agent
|
|
|
|
|
spec:
|
2026-05-06 19:56:22 +00:00
|
|
|
securityContext:
|
|
|
|
|
fsGroup: 1000
|
2026-05-07 09:58:43 -04:00
|
|
|
runAsUser: 1000
|
2026-04-20 19:20:15 +00:00
|
|
|
containers:
|
|
|
|
|
- name: hermes-agent
|
2026-05-06 19:56:22 +00:00
|
|
|
securityContext:
|
2026-05-07 09:58:43 -04:00
|
|
|
allowPrivilegeEscalation: true
|
2026-05-06 19:56:22 +00:00
|
|
|
capabilities:
|
|
|
|
|
drop:
|
|
|
|
|
- ALL
|
2026-05-07 01:28:39 +00:00
|
|
|
runAsUser: 0
|
|
|
|
|
runAsGroup: 0
|
2026-05-06 19:56:22 +00:00
|
|
|
seccompProfile:
|
|
|
|
|
type: RuntimeDefault
|
2026-04-25 11:25:23 -04:00
|
|
|
image: nousresearch/hermes-agent:latest
|
2026-04-20 19:20:15 +00:00
|
|
|
command: ["/bin/bash", "-c"]
|
|
|
|
|
args:
|
|
|
|
|
- |
|
2026-05-06 16:43:30 -04:00
|
|
|
set -euo pipefail
|
2026-04-25 11:25:23 -04:00
|
|
|
echo "Hermes Agent starting (Telegram polling + full config persistence)..."
|
2026-05-06 16:43:30 -04:00
|
|
|
|
2026-05-06 16:26:34 -04:00
|
|
|
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
|
2026-05-06 16:43:30 -04:00
|
|
|
|
|
|
|
|
if [ ! -x "$HERMES_BIN" ]; then
|
|
|
|
|
echo "❌ hermes binary NOT FOUND at $HERMES_BIN"
|
|
|
|
|
echo "Searching filesystem..."
|
|
|
|
|
find / -name hermes -type f 2>/dev/null | head -10 || true
|
|
|
|
|
exit 1
|
|
|
|
|
fi
|
|
|
|
|
|
|
|
|
|
echo "✅ Found hermes at: $HERMES_BIN"
|
|
|
|
|
|
|
|
|
|
# Copy config
|
|
|
|
|
cp -f /etc/hermes/config.yaml /opt/data/config.yaml || true
|
|
|
|
|
|
|
|
|
|
# Create symlink in a writable location (PVC) so it works when you exec in
|
|
|
|
|
mkdir -p /opt/data/bin
|
|
|
|
|
ln -sf "$HERMES_BIN" /opt/data/bin/hermes || true
|
|
|
|
|
export PATH="/opt/data/bin:$PATH"
|
|
|
|
|
|
|
|
|
|
echo "🚀 Starting hermes gateway..."
|
|
|
|
|
exec "$HERMES_BIN" gateway run
|
2026-04-25 11:25:23 -04:00
|
|
|
env:
|
|
|
|
|
# === Hermes Home - REQUIRED for config persistence ===
|
|
|
|
|
- name: HERMES_HOME
|
|
|
|
|
value: "/opt/data"
|
2026-05-06 16:51:45 -04:00
|
|
|
- name: HOME
|
2026-05-06 16:56:47 -04:00
|
|
|
value: "/opt/data"
|
2026-05-06 16:51:45 -04:00
|
|
|
- name: XDG_CACHE_HOME
|
|
|
|
|
value: "/opt/data/.cache"
|
|
|
|
|
- name: XDG_CONFIG_HOME
|
|
|
|
|
value: "/opt/data/.config"
|
2026-04-25 11:25:23 -04:00
|
|
|
|
|
|
|
|
# === Telegram Configuration (polling only - no public exposure) ===
|
|
|
|
|
- name: TELEGRAM_BOT_TOKEN
|
2026-04-25 21:02:14 +00:00
|
|
|
valueFrom:
|
|
|
|
|
secretKeyRef:
|
|
|
|
|
name: hermes-secrets
|
2026-04-25 21:11:57 +00:00
|
|
|
key: TELEGRAM_BOT_TOKEN
|
2026-04-25 21:02:14 +00:00
|
|
|
- name: XAI_API_KEY
|
2026-05-06 16:15:06 -04:00
|
|
|
valueFrom:
|
2026-04-25 21:02:14 +00:00
|
|
|
secretKeyRef:
|
|
|
|
|
name: xai-apikey
|
|
|
|
|
key: XAI_API_KEY
|
|
|
|
|
|
2026-04-25 11:25:23 -04:00
|
|
|
- name: TELEGRAM_ALLOWED_USERS
|
2026-04-25 21:02:14 +00:00
|
|
|
value: "7528130947"
|
2026-04-25 11:25:23 -04:00
|
|
|
|
|
|
|
|
# === Local vLLM (OpenAI-compatible) ===
|
|
|
|
|
- name: OPENAI_BASE_URL
|
2026-04-25 21:02:14 +00:00
|
|
|
value: "http://openclaw-brain-service.customer1.svc.cluster.local:8000/v1" # ← adjust if your service name differs
|
|
|
|
|
|
2026-04-25 21:26:54 +00:00
|
|
|
- name: HERMES_MODEL_PROVIDER
|
|
|
|
|
value: xai
|
|
|
|
|
|
2026-04-25 23:23:48 +00:00
|
|
|
- name: HERMES_MODEL
|
2026-04-25 21:26:54 +00:00
|
|
|
value: grok-4.1-fast
|
2026-04-25 23:23:48 +00:00
|
|
|
|
2026-04-25 11:25:23 -04:00
|
|
|
- name: OPENAI_API_KEY
|
|
|
|
|
value: "dummy" # vLLM ignores this
|
|
|
|
|
|
2026-05-06 19:25:28 +00:00
|
|
|
# === API Server (for external OpenAI-compatible clients) ===
|
2026-05-06 15:36:27 +00:00
|
|
|
- name: API_SERVER_ENABLED
|
|
|
|
|
value: "true"
|
|
|
|
|
- name: API_SERVER_HOST
|
|
|
|
|
value: "0.0.0.0"
|
|
|
|
|
- name: API_SERVER_PORT
|
|
|
|
|
value: "8642"
|
|
|
|
|
- name: API_SERVER_KEY
|
|
|
|
|
value: "" # empty = no auth (tailnet-only, private)
|
|
|
|
|
- name: API_SERVER_MODEL_NAME
|
|
|
|
|
value: "hermes-agent"
|
|
|
|
|
|
2026-04-25 11:25:23 -04:00
|
|
|
# === Optional ===
|
|
|
|
|
# - name: LOG_LEVEL
|
|
|
|
|
# value: "INFO"
|
2026-04-20 19:20:15 +00:00
|
|
|
volumeMounts:
|
|
|
|
|
- name: hermes-data
|
2026-04-25 11:25:23 -04:00
|
|
|
mountPath: /opt/data
|
2026-05-06 03:07:30 +00:00
|
|
|
- name: hermes-configmap
|
|
|
|
|
mountPath: /etc/hermes/config.yaml
|
2026-04-29 04:45:18 +00:00
|
|
|
subPath: config.yaml
|
2026-05-06 03:07:30 +00:00
|
|
|
readOnly: true
|
2026-04-29 09:22:34 -04:00
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 2Gi
|
|
|
|
|
cpu: "1"
|
|
|
|
|
limits:
|
2026-04-29 12:59:21 -04:00
|
|
|
memory: 4Gi
|
|
|
|
|
cpu: "2"
|
2026-05-07 09:58:43 -04:00
|
|
|
|
2026-05-06 19:25:28 +00:00
|
|
|
- name: hermes-webui
|
|
|
|
|
image: ghcr.io/nesquena/hermes-webui:latest
|
|
|
|
|
ports:
|
|
|
|
|
- containerPort: 8787
|
|
|
|
|
env:
|
|
|
|
|
- name: HERMES_HOME
|
|
|
|
|
value: "/home/hermeswebui/.hermes"
|
|
|
|
|
- name: HERMES_WEBUI_HOST
|
|
|
|
|
value: "0.0.0.0"
|
|
|
|
|
- name: HERMES_WEBUI_PORT
|
|
|
|
|
value: "8787"
|
|
|
|
|
- name: HERMES_WEBUI_STATE_DIR
|
|
|
|
|
value: "/home/hermeswebui/.hermes/webui"
|
|
|
|
|
- name: WANTED_UID
|
|
|
|
|
value: "1000"
|
|
|
|
|
- name: WANTED_GID
|
|
|
|
|
value: "1000"
|
|
|
|
|
volumeMounts:
|
|
|
|
|
- name: hermes-data
|
|
|
|
|
mountPath: /home/hermeswebui/.hermes
|
2026-05-07 13:14:01 +00:00
|
|
|
|
2026-05-06 19:25:28 +00:00
|
|
|
resources:
|
|
|
|
|
requests:
|
|
|
|
|
memory: 256Mi
|
|
|
|
|
cpu: "100m"
|
|
|
|
|
limits:
|
|
|
|
|
memory: 512Mi
|
|
|
|
|
cpu: "500m"
|
|
|
|
|
securityContext:
|
2026-05-07 13:45:42 +00:00
|
|
|
allowPrivilegeEscalation: false
|
2026-05-06 19:25:28 +00:00
|
|
|
capabilities:
|
|
|
|
|
drop:
|
|
|
|
|
- ALL
|
2026-05-07 13:45:42 +00:00
|
|
|
runAsNonRoot: true
|
|
|
|
|
runAsUser: 1000
|
|
|
|
|
runAsGroup: 1000
|
2026-05-06 19:25:28 +00:00
|
|
|
seccompProfile:
|
|
|
|
|
type: RuntimeDefault
|
2026-04-20 19:20:15 +00:00
|
|
|
volumes:
|
2026-05-06 03:07:30 +00:00
|
|
|
- name: hermes-configmap
|
2026-04-29 04:45:18 +00:00
|
|
|
configMap:
|
|
|
|
|
name: hermes-config
|
2026-04-20 19:20:15 +00:00
|
|
|
- name: hermes-data
|
|
|
|
|
persistentVolumeClaim:
|
2026-05-05 22:46:15 -04:00
|
|
|
claimName: hermes-agent-pvc
|
2026-04-20 19:20:15 +00:00
|
|
|
---
|
|
|
|
|
apiVersion: v1
|
|
|
|
|
kind: PersistentVolumeClaim
|
|
|
|
|
metadata:
|
2026-05-05 22:46:15 -04:00
|
|
|
name: hermes-agent-pvc
|
2026-04-20 19:20:15 +00:00
|
|
|
namespace: customer1
|
|
|
|
|
spec:
|
|
|
|
|
accessModes:
|
|
|
|
|
- ReadWriteOnce
|
|
|
|
|
resources:
|
|
|
|
|
requests:
|
2026-05-07 13:45:42 +00:00
|
|
|
storage: 25Gi
|