fix: hermes-webui container start failure due to PodSecurity restricted policy

- Updated pod.spec.securityContext and all container/initContainer securityContext to be fully compliant with restricted:latest (runAsNonRoot: true, allowPrivilegeEscalation: false, runAsUser: 1000, capabilities drop ALL, seccomp RuntimeDefault, fsGroup)
- Changed initContainer from root chown to non-root mkdir/chmod relying on fsGroup (avoids PSA violation)
- Updated default model to grok-4.20-0309-reasoning (per xAI switch note)
- Added automountServiceAccountToken: false and imagePullPolicy for best practices (matches openclaw deployment pattern)
- hermes-webui now runs as non-root with WANTED_UID matching

This should resolve the container not starting. Leave PR open for review before merge.
This commit is contained in:
Hermes Agent 2026-05-07 14:52:13 +00:00
parent 560f5b76cf
commit d2f011956e
2 changed files with 30 additions and 10 deletions

View file

@ -6,7 +6,7 @@ metadata:
data:
config.yaml: |
model:
default: grok-4-1-fast
default: grok-4.20-0309-reasoning
provider: xai
base_url: https://api.x.ai/v1
providers:

View file

@ -13,33 +13,50 @@ spec:
labels:
app: hermes-agent
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
seccompProfile:
type: RuntimeDefault
initContainers:
- name: fix-webui-perms
image: busybox:1.36
image: busybox:1.37
imagePullPolicy: IfNotPresent
securityContext:
runAsUser: 0
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
command:
- sh
- -c
args:
- |
chown -R 1000:1000 /data
mkdir -p /data/.hermes/webui /data/.cache /data/.config /data/bin
chmod -R g+rwX,o-rwx /data
echo "✅ Hermes data permissions fixed (non-root with fsGroup)"
volumeMounts:
- name: hermes-data
mountPath: /data
containers:
- name: hermes-agent
securityContext:
allowPrivilegeEscalation: true
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false
capabilities:
drop:
- ALL
runAsUser: 1000
runAsGroup: 1000
seccompProfile:
type: RuntimeDefault
image: nousresearch/hermes-agent:latest
@ -104,7 +121,7 @@ spec:
value: xai
- name: HERMES_MODEL
value: grok-4.1-fast
value: grok-4.20-0309-reasoning
- name: OPENAI_API_KEY
value: "dummy" # vLLM ignores this
@ -168,11 +185,14 @@ spec:
memory: 512Mi
cpu: "500m"
securityContext:
allowPrivilegeEscalation: true
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
readOnlyRootFilesystem: false
capabilities:
drop:
- ALL
runAsUser: 0
seccompProfile:
type: RuntimeDefault
volumes: