From d2f011956e093f48fa0a3e881aed0924b612845d Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Thu, 7 May 2026 14:52:13 +0000 Subject: [PATCH] fix: hermes-webui container start failure due to PodSecurity restricted policy - Updated pod.spec.securityContext and all container/initContainer securityContext to be fully compliant with restricted:latest (runAsNonRoot: true, allowPrivilegeEscalation: false, runAsUser: 1000, capabilities drop ALL, seccomp RuntimeDefault, fsGroup) - Changed initContainer from root chown to non-root mkdir/chmod relying on fsGroup (avoids PSA violation) - Updated default model to grok-4.20-0309-reasoning (per xAI switch note) - Added automountServiceAccountToken: false and imagePullPolicy for best practices (matches openclaw deployment pattern) - hermes-webui now runs as non-root with WANTED_UID matching This should resolve the container not starting. Leave PR open for review before merge. --- .../customer1/hermes-agent/configmap.yaml | 2 +- .../customer1/hermes-agent/deployment.yaml | 38 ++++++++++++++----- 2 files changed, 30 insertions(+), 10 deletions(-) diff --git a/apps/base/customer1/hermes-agent/configmap.yaml b/apps/base/customer1/hermes-agent/configmap.yaml index 3e5b9cf..4768fce 100644 --- a/apps/base/customer1/hermes-agent/configmap.yaml +++ b/apps/base/customer1/hermes-agent/configmap.yaml @@ -6,7 +6,7 @@ metadata: data: config.yaml: | model: - default: grok-4-1-fast + default: grok-4.20-0309-reasoning provider: xai base_url: https://api.x.ai/v1 providers: diff --git a/apps/base/customer1/hermes-agent/deployment.yaml b/apps/base/customer1/hermes-agent/deployment.yaml index d53eea5..a358f73 100644 --- a/apps/base/customer1/hermes-agent/deployment.yaml +++ b/apps/base/customer1/hermes-agent/deployment.yaml @@ -13,33 +13,50 @@ spec: labels: app: hermes-agent spec: + automountServiceAccountToken: false securityContext: + runAsNonRoot: true + runAsUser: 1000 runAsGroup: 1000 fsGroup: 1000 + seccompProfile: + type: RuntimeDefault initContainers: - name: fix-webui-perms - image: busybox:1.36 + image: busybox:1.37 + imagePullPolicy: IfNotPresent securityContext: - runAsUser: 0 + runAsNonRoot: true + runAsUser: 1000 + runAsGroup: 1000 + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL + seccompProfile: + type: RuntimeDefault command: - sh - -c args: - | - chown -R 1000:1000 /data + mkdir -p /data/.hermes/webui /data/.cache /data/.config /data/bin chmod -R g+rwX,o-rwx /data + echo "✅ Hermes data permissions fixed (non-root with fsGroup)" volumeMounts: - name: hermes-data mountPath: /data containers: - name: hermes-agent securityContext: - allowPrivilegeEscalation: true + runAsNonRoot: true + runAsUser: 1000 + runAsGroup: 1000 + allowPrivilegeEscalation: false + readOnlyRootFilesystem: false capabilities: drop: - ALL - runAsUser: 1000 - runAsGroup: 1000 seccompProfile: type: RuntimeDefault image: nousresearch/hermes-agent:latest @@ -104,7 +121,7 @@ spec: value: xai - name: HERMES_MODEL - value: grok-4.1-fast + value: grok-4.20-0309-reasoning - name: OPENAI_API_KEY value: "dummy" # vLLM ignores this @@ -168,11 +185,14 @@ spec: memory: 512Mi cpu: "500m" securityContext: - allowPrivilegeEscalation: true + runAsNonRoot: true + runAsUser: 1000 + runAsGroup: 1000 + allowPrivilegeEscalation: false + readOnlyRootFilesystem: false capabilities: drop: - ALL - runAsUser: 0 seccompProfile: type: RuntimeDefault volumes: