Compare commits

..

7 Commits

Author SHA1 Message Date
d47d230c25 fix: restore corrupted variable names (${OPENROUTER_API_KEY}, ${OPENCLAW_GATEWAY_TOKEN})
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-05-21 00:29:16 -04:00
3596ac5219 fix: restore command: gateway run and OPENROUTER_API_KEY variable
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-05-21 00:27:01 -04:00
802c71cf4e chore: remove Hermes config files from repo — lives on persistent volume
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-05-20 23:45:32 -04:00
8ce9f7189f chore: remove .env.example
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-05-20 23:38:15 -04:00
e3f47cac6b feat: keep only Honcho, remove OpenViking from memory providers 2026-05-20 23:38:15 -04:00
04dcca1aa7 Merge remote-tracking branch 'origin/master' into feat/memory-providers
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-05-20 23:08:44 -04:00
01fbf2ab62 feat: add self-hosted memory providers (OpenViking, Honcho, Holographic)
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
- Add OpenViking service (knowledge graph) using official GHCR image
- Add Honcho stack (user modeling): API + PostgreSQL pgvector + Redis
- Add Holographic config to Hermes (local SQLite, no server needed)
- Hermes: install httpx for OpenViking client
- Hermes: auto-generate config.yaml + honcho.json on first boot
- All data 100% local, zero cloud dependencies
2026-05-17 17:10:04 -04:00
20 changed files with 267 additions and 430 deletions

View File

@@ -1,33 +1,50 @@
version: "3.8"
services: services:
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
hermes: hermes:
build: build:
context: ./hermes context: ./hermes
ssh: ssh:
- default - default
container_name: hermes container_name: hermes
entrypoint: ["/bin/bash", "-c",
"bash /opt/data/hermes-tools/install.sh && . /opt/hermes/.venv/bin/activate && uv pip install openai 'mautrix[encryption]' -q && exec /usr/bin/tini -g -- /opt/hermes/docker/entrypoint.sh \"$@\"",
"hermes-entrypoint"]
restart: always restart: always
# Use the image default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"] # Gateway run enables the internal API server on port 8642
# for proper s6-overlay supervision. The CMD runs our multi-profile launcher command: gateway run
# which spawns per-profile gateways in background, then the default gateway
# in foreground (keeps the container alive).
command: ["/usr/local/bin/start-hermes.sh"]
environment: environment:
- HERMES_UID=10000
- HERMES_GID=10000
- OLLAMA_HOST=http://ollama:11434 - OLLAMA_HOST=http://ollama:11434
- HERMES_DASHBOARD=1
# Multi-profile: comma-separated list of profiles to run as gateways.
# start-hermes.sh reads this and starts one gateway per profile.
# Add profiles here when they exist on disk (e.g. default,researcher,writer)
- HERMES_PROFILES=ashley,claire,finn,matt,paul
- API_SERVER_ENABLED=true - API_SERVER_ENABLED=true
- API_SERVER_PORT=8642 - API_SERVER_PORT=8642
- API_SERVER_HOST=0.0.0.0 - API_SERVER_HOST=0.0.0.0
- API_SERVER_KEY=hermes_local_key - API_SERVER_KEY=hermes_local_key
- GATEWAY_ALLOW_ALL_USERS=true - GATEWAY_ALLOW_ALL_USERS=true
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY} - OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
- OPENCODE_API_KEY=${OPENCODE_API_KEY}
# ROCm for GPU-accelerated faster-whisper STT # ROCm for GPU-accelerated faster-whisper STT
- HSA_OVERRIDE_GFX_VERSION=9.0.6 - HSA_OVERRIDE_GFX_VERSION=9.0.6
- HCC_AMDGPU_TARGET=gfx906 - HCC_AMDGPU_TARGET=gfx906
@@ -37,7 +54,12 @@ services:
- TZ=America/Montreal - TZ=America/Montreal
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data - /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex # Syncthing-shared org files — read-only view of user's agenda
- /mnt/HoardingCow_docker_data/Syncthing/telos-ro:/opt/data/telos-ro:ro
# Syncthing-shared inbox — write tasks here, they sync to user's laptop
- /mnt/HoardingCow_docker_data/Syncthing/telos-rw:/opt/data/telos-rw:rw
# Persist Python venv across container recreation (Matrix bridge deps, etc.)
- /mnt/HoardingCow_docker_data/Hermes/venv:/opt/hermes/.venv
devices: devices:
- /dev/kfd:/dev/kfd - /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
@@ -46,32 +68,8 @@ services:
- "26" - "26"
networks: networks:
- ai_backend - ai_backend
- ai_net
depends_on: depends_on:
- honcho - honcho
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
# Router for HTTP + redirection to HTTPS
- "traefik.http.routers.hermes-web-http.rule=Host(`hermes.lazyworkhorse.net`)"
- "traefik.http.routers.hermes-web-http.entrypoints=web"
- "traefik.http.routers.hermes-web-http.middlewares=redirect-to-https"
# Router for HTTPS with TLS — protected by Authelia
- "traefik.http.routers.hermes-web-https.rule=Host(`hermes.lazyworkhorse.net`)"
- "traefik.http.routers.hermes-web-https.entrypoints=websecure"
- "traefik.http.routers.hermes-web-https.tls=true"
- "traefik.http.routers.hermes-web-https.tls.certresolver=njalla"
- "traefik.http.routers.hermes-web-https.middlewares=hermes-auth"
# Authelia forwardAuth
- "traefik.http.middlewares.hermes-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/"
- "traefik.http.middlewares.hermes-auth.forwardauth.trustforwardheader=true"
- "traefik.http.middlewares.hermes-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups"
# Service Loadbalancer (dashboard port 9119)
- "traefik.http.services.hermes-web.loadbalancer.server.port=9119"
syncthing: syncthing:
image: syncthing/syncthing:latest image: syncthing/syncthing:latest
@@ -84,28 +82,22 @@ services:
- "21027:21027/udp" - "21027:21027/udp"
environment: environment:
- TZ=America/Montreal - TZ=America/Montreal
- PUID=10000
- PGID=10000
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config - /mnt/HoardingCow_docker_data/Syncthing/config:/var/syncthing/config
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex - /mnt/HoardingCow_docker_data/Syncthing/telos-ro:/telos-ro
- /mnt/HoardingCow_docker_data/Syncthing/telos-rw:/telos-rw
networks: networks:
- ai_backend - ai_backend
- ai_net - ai_net
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=ai_net"
- "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)" - "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-http.entrypoints=web" - "traefik.http.routers.syncthing-http.entrypoints=web"
- "traefik.http.routers.syncthing-http.middlewares=redirect-to-https" - "traefik.http.routers.syncthing-http.middlewares=redirect-to-https"
- "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)" - "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-https.entrypoints=websecure" - "traefik.http.routers.syncthing-https.entrypoints=websecure"
- "traefik.http.routers.syncthing-https.tls=true" - "traefik.http.routers.syncthing-https.tls=true"
- "traefik.http.routers.syncthing-https.tls.certresolver=njalla" - "traefik.http.routers.syncthing-https.tls.certresolver=njalla"
- "traefik.http.routers.syncthing-https.middlewares=hermes-auth"
- "traefik.http.services.syncthing.loadbalancer.server.port=8384" - "traefik.http.services.syncthing.loadbalancer.server.port=8384"
ollama: ollama:
@@ -141,50 +133,26 @@ services:
- "303" - "303"
- "26" - "26"
# --- Honcho + OpenConcho combiné: API + Web UI nginx/FastAPI --- # --- Honcho: AI-native user modeling ---
honcho: honcho:
build: build: ./honcho
context: ./honcho
ssh:
- default
container_name: honcho container_name: honcho
restart: unless-stopped restart: unless-stopped
ports:
- "127.0.0.1:8000:8000"
environment: environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho - DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0 - CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true - CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024
- AUTH_USE_AUTH=true
- AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET}
# Needed by deriver/dream to make LLM calls (api_key_env = "HONCHO_OPENAI_API_KEY" in config.toml)
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY}
volumes: volumes:
- /mnt/HoardingCow_docker_data/Honcho/data:/app/data - /mnt/HoardingCow_docker_data/Honcho/data:/app/data
- /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro
networks: networks:
- ai_backend - ai_backend
- ai_net
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
# Router for HTTP + redirect to HTTPS
- "traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-http.entrypoints=web"
- "traefik.http.routers.honcho-http.middlewares=redirect-to-https"
# Router for HTTPS with TLS — protected by Authelia
- "traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-https.entrypoints=websecure"
- "traefik.http.routers.honcho-https.tls=true"
- "traefik.http.routers.honcho-https.tls.certresolver=njalla"
- "traefik.http.routers.honcho-https.middlewares=hermes-auth"
# Service Loadbalancer (nginx port)
- "traefik.http.services.honcho.loadbalancer.server.port=80"
depends_on: depends_on:
- honcho-db honcho-db:
- honcho-redis condition: service_healthy
honcho-redis:
condition: service_healthy
honcho-db: honcho-db:
image: pgvector/pgvector:pg15 image: pgvector/pgvector:pg15
@@ -203,6 +171,11 @@ services:
- ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro - ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro
networks: networks:
- ai_backend - ai_backend
healthcheck:
test: ["CMD-SHELL", "pg_isready -U honcho -d honcho"]
interval: 5s
timeout: 5s
retries: 5
honcho-redis: honcho-redis:
image: redis:8 image: redis:8
@@ -214,20 +187,20 @@ services:
- /mnt/HoardingCow_docker_data/Honcho/redis:/data - /mnt/HoardingCow_docker_data/Honcho/redis:/data
networks: networks:
- ai_backend - ai_backend
healthcheck:
test: ["CMD-SHELL", "redis-cli ping"]
interval: 5s
timeout: 5s
retries: 5
networks: networks:
ai_net: ai_net:
driver: bridge external: true
name: ai_net name: ai_net
ai_backend: ai_backend:
driver: bridge driver: bridge
name: ai_backend name: ai_backend
volumes:
honcho_data:
driver: bridge
name: honcho_data
# llama_cpp_devstral: # llama_cpp_devstral:
# image: ghcr.io/ggml-org/llama.cpp:server-rocm # image: ghcr.io/ggml-org/llama.cpp:server-rocm
# container_name: llama_cpp_devstral # container_name: llama_cpp_devstral
@@ -316,30 +289,6 @@ volumes:
# - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface # - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface
# restart: unless-stopped # restart: unless-stopped
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
# n8n: # n8n:
# image: n8nio/n8n:latest # image: n8nio/n8n:latest
# container_name: n8n # container_name: n8n

View File

@@ -9,12 +9,37 @@
# ---------- Base: official Hermes image (system deps, npm, uv, Playwright) ---------- # ---------- Base: official Hermes image (system deps, npm, uv, Playwright) ----------
FROM nousresearch/hermes-agent:latest FROM nousresearch/hermes-agent:latest
# ---------- Overlay our forked source ----------
# Uses SSH agent forwarding from the build host (no key baked into image).
# --exclude node_modules/.venv keeps the base image's pre-built layers intact.
# Only the Python source, web UI source, and config change.
RUN --mount=type=ssh \
mkdir -p /root/.ssh && \
ssh-keyscan -p 2222 code.lazyworkhorse.net >> /root/.ssh/known_hosts 2>/dev/null && \
cd /tmp && \
GIT_SSH_COMMAND='ssh -p 2222 -o StrictHostKeyChecking=no' \
git clone --depth 1 --branch main \
git@code.lazyworkhorse.net:gortium/hermes-agent.git fork && \
rsync -a --delete fork/ /opt/hermes/ \
--exclude node_modules \
--exclude .venv \
--exclude .git && \
rm -rf /tmp/fork /root/.ssh/
# ---------- Rebuild web UI ----------
# Source files changed; node_modules (from base image) reused.
RUN cd /opt/hermes && npm run build
# ---------- Reinstall Python package (editable) ----------
# Picks up source changes from our fork.
RUN . /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir --no-deps -e /opt/hermes
# ---------- Extra system deps ---------- # ---------- Extra system deps ----------
USER root USER root
RUN apt-get update && \ RUN apt-get update && \
apt-get install -y --no-install-recommends \ apt-get install -y --no-install-recommends \
libportaudio2 ca-certificates poppler-utils imagemagick \ libportaudio2 ca-certificates poppler-utils imagemagick \
libolm-dev \
texlive-latex-base texlive-latex-extra texlive-fonts-recommended \ texlive-latex-base texlive-latex-extra texlive-fonts-recommended \
texlive-xetex texlive-science \ texlive-xetex texlive-science \
qemu-user-static binfmt-support emacs-nox && \ qemu-user-static binfmt-support emacs-nox && \
@@ -25,11 +50,11 @@ COPY --chmod=0755 --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/
WORKDIR /opt/hermes WORKDIR /opt/hermes
# ---------- Matrix bridge + extra pip deps ---------- # ---------- Memory provider dependencies ----------
# Previously installed inline at container startup and persisted via volume mount. # httpx: HTTP client for OpenViking plugin
# Now baked into the image so the fragile venv volume mount can be removed. # honcho-ai: already installed in upstream image (v2.1.1+)
RUN . /opt/hermes/.venv/bin/activate && \ RUN . /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir 'mautrix[encryption]' openai uv pip install --no-cache-dir httpx
# ---------- Piper TTS ---------- # ---------- Piper TTS ----------
RUN . /opt/hermes/.venv/bin/activate && \ RUN . /opt/hermes/.venv/bin/activate && \
@@ -58,14 +83,9 @@ os.remove(tgz)
print('himalaya v1.2.0 installed') print('himalaya v1.2.0 installed')
PYEOF PYEOF
# ---------- Install multi-gateway launcher ---------- # ---------- Install himalaya-ro wrapper ----------
# Launches one gateway process per profile (HERMES_PROFILES env var) COPY --chmod=0755 himalaya-ro.sh /usr/local/bin/himalaya-ro
COPY --chmod=0755 run-multi-gateways.sh /usr/local/bin/run-multi-gateways.sh
# ---------- Install s6-overlay compatible startup script ----------
# Runs as the CMD via s6-overlay's main-program model.
# Replaces the old bash->tini->entrypoint.sh chain that caused SIGTERM crash loops.
COPY --chmod=0755 start-hermes.sh /usr/local/bin/start-hermes.sh
# ---------- Runtime ---------- # ---------- Runtime ----------
USER hermes USER hermes
@@ -76,12 +96,6 @@ ENV CHROME_EXECUTABLE=/opt/hermes/.playwright/chromium/chrome-linux/chrome
# Ensure tools directory and toolsets.py are writable by the hermes runtime user # Ensure tools directory and toolsets.py are writable by the hermes runtime user
# so custom tools can be injected from the persistent volume at startup. # so custom tools can be injected from the persistent volume at startup.
USER root
RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py
VOLUME [ "/opt/data" ] VOLUME [ "/opt/data" ]
# Switch to the hermes user so the container runs unprivileged.
# All child processes inherit this user — no more orphan root processes
# that escape gosu privilege drops in the entrypoint.
USER hermes

73
ai/hermes/himalaya-ro.sh Normal file
View File

@@ -0,0 +1,73 @@
#!/usr/bin/env bash
# ─────────────────────────────────────────────────────────────
# himalaya-ro — Read-only wrapper for himalaya
#
# Blocks destructive commands and logs audit trail.
# Pass-through for read-only commands (list, read, search).
#
# Usage: himalaya-ro [options] <command> [args...]
#
# Install: place in PATH before the real himalaya, or use
# `ln -sf himalaya-ro /usr/local/bin/himalaya`
# ─────────────────────────────────────────────────────────────
set -o pipefail
# ── Configuration ───────────────────────────────────────────
HIMALAYA_BIN="${HIMALAYA_BIN:-/usr/local/bin/himalaya}"
AUDIT_LOG="${HIMALAYA_AUDIT_LOG:-/var/log/himalaya-audit.log}"
# ── Destructive commands we block ──────────────────────────
BLOCKED_CMDS=(
"message move"
"message delete"
"message copy"
"flag add"
"flag remove"
"folder create"
"folder delete"
"folder rename"
"template send"
"account configure"
"account delete"
)
# ── Determine the subcommand being invoked ─────────────────
# Strip leading options (--account, --output, etc.) to find the verb
ARGS=()
SKIP_NEXT=false
for arg in "$@"; do
if $SKIP_NEXT; then
SKIP_NEXT=false
continue
fi
if [[ "$arg" == --* ]]; then
case "$arg" in
--account|--output|--page|--page-size|--folder|--color|--format)
SKIP_NEXT=true ;;
esac
continue
fi
ARGS+=("$arg")
done
# Build subcommand string and check against blocklist
CMD_STR=""
for ((i=0; i<${#ARGS[@]}; i++)); do
if [ -z "$CMD_STR" ]; then
CMD_STR="${ARGS[$i]}"
else
CMD_STR="$CMD_STR ${ARGS[$i]}"
fi
for blocked in "${BLOCKED_CMDS[@]}"; do
if [[ "$CMD_STR" == "$blocked" ]]; then
TS=$(date '+%Y-%m-%d %H:%M:%S')
echo "[AUDIT] $TS BLOCKED: himalaya $*" >> "$AUDIT_LOG"
echo "ERROR: Command 'himalaya $CMD_STR ...' is blocked by read-only policy." >&2
echo " Audit log: $AUDIT_LOG" >&2
exit 100
fi
done
done
# ── Allow pass-through ─────────────────────────────────────
exec "$HIMALAYA_BIN" "$@"

View File

@@ -1,32 +0,0 @@
#!/bin/bash
# Multi-gateway launcher for HERMES_PROFILES env var.
# Reads comma-separated profile names, spawns one gateway per profile.
# Designed to run before the main entrypoint — gateways run in background.
set -e
if [ -z "${HERMES_PROFILES}" ]; then
echo "HERMES_PROFILES not set — skipping multi-gateway launch"
exit 0
fi
# Source venv to make 'hermes' available (entrypoint.sh sources it later,
# but we need it NOW for the background gateways)
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
if [ ! -x "$HERMES_BIN" ]; then
echo "ERROR: hermes binary not found at $HERMES_BIN"
exit 1
fi
mkdir -p /opt/data/logs
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
for profile in "${PROFILES[@]}"; do
profile="$(echo "${profile}" | xargs)" # trim whitespace
[ -z "${profile}" ] && continue
echo "Starting gateway for profile: ${profile}"
nohup env API_SERVER_ENABLED=false API_SERVER_KEY= gosu hermes "$HERMES_BIN" --profile "${profile}" gateway run \
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
done
echo "All gateways launched: ${HERMES_PROFILES}"

View File

@@ -1,38 +0,0 @@
#!/bin/bash
# Multi-profile + default gateway launcher — runs as the CMD via s6-overlay.
#
# The image's default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"]
# starts the s6 supervision tree, then exec's main-wrapper.sh with the CMD args.
# main-wrapper.sh sources the venv, drops to the hermes user via s6-setuidgid,
# and exec's this script.
#
# This script:
# 1. Launches per-profile background gateways (HERMES_PROFILES env var)
# 2. Starts the default gateway in foreground (keeps the container alive)
#
# Replaces the old approach of chaining bash -> tini -g -> deprecated entrypoint.sh
# which bypassed s6-overlay and caused the SIGTERM crash loop.
set -e
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
# --- Multi-profile gateways (background) ---
if [ -n "${HERMES_PROFILES:-}" ]; then
echo "[start-hermes] Launching per-profile gateways: ${HERMES_PROFILES}"
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
for profile in "${PROFILES[@]}"; do
profile="$(echo "${profile}" | xargs)" # trim whitespace
[ -z "${profile}" ] && continue
echo "[start-hermes] -> background gateway for profile '${profile}'"
# No gosu/s6-setuidgid needed — we're already running as the hermes user
# (main-wrapper.sh drops privileges before exec'ing this script).
nohup "${HERMES_BIN}" --profile "${profile}" gateway run \
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
done
echo "[start-hermes] All profile gateways launched"
fi
# --- Default gateway (foreground — keeps container alive) ---
echo "[start-hermes] Starting default gateway (foreground)"
exec "${HERMES_BIN}" gateway run

View File

@@ -1,75 +1,42 @@
# build stage — fetches and builds Honcho from source # build stage — fetches and builds Honcho from source
FROM python:3.13-slim-bookworm AS honcho-builder # Using buildkit cache mounts for speed across rebuilds
FROM python:3.13-slim-bookworm AS builder
RUN apt-get update && \ RUN apt-get update && \
apt-get install -y --no-install-recommends git openssh-client && \ apt-get install -y --no-install-recommends git && \
rm -rf /var/lib/apt/lists/* rm -rf /var/lib/apt/lists/*
COPY --from=ghcr.io/astral-sh/uv:0.9.24 /uv /bin/uv COPY --from=ghcr.io/astral-sh/uv:0.9.24 /uv /bin/uv
ARG HONCHO_REPO=ssh://git@code.lazyworkhorse.net:2222/Hermes/honcho.git # Clone Honcho at a pinned commit for reproducibility
ARG HONCHO_REPO=https://github.com/plastic-labs/honcho
ARG HONCHO_REF=main ARG HONCHO_REF=main
RUN mkdir -p -m 0700 ~/.ssh && ssh-keyscan -p 2222 code.lazyworkhorse.net >> ~/.ssh/known_hosts 2>/dev/null RUN git clone --depth 1 --branch ${HONCHO_REF} ${HONCHO_REPO} /app
RUN --mount=type=ssh git clone --depth 1 --branch ${HONCHO_REF} ${HONCHO_REPO} /app
WORKDIR /app WORKDIR /app
ENV UV_COMPILE_BYTECODE=1 ENV UV_COMPILE_BYTECODE=1
ENV UV_LINK_MODE=copy ENV UV_LINK_MODE=copy
ENV UV_PYTHON=/usr/local/bin/python3.13
RUN uv sync --frozen RUN --mount=type=cache,target=/root/.cache/uv \
uv sync --frozen --no-group dev
# build stage — builds OpenConcho SPA # --- runtime stage ---
FROM node:22-bookworm AS openconcho-builder
ENV PNPM_HOME=/pnpm
ENV PATH=$PNPM_HOME:$PATH
RUN corepack enable && corepack prepare pnpm@latest --activate
WORKDIR /app
RUN apt-get update && apt-get install -y git && rm -rf /var/lib/apt/lists/*
ARG OPENCONCHO_SHA=3b5c3293fc18d768dbe85285264a8d66c896bd81
RUN --mount=type=ssh git clone --depth 1 ssh://git@code.lazyworkhorse.net:2222/gortium/openconcho.git /app && \
git -C /app fetch --depth 1 origin ${OPENCONCHO_SHA} && \
git -C /app checkout ${OPENCONCHO_SHA}
RUN pnpm install --frozen-lockfile
RUN pnpm --filter @openconcho/web build
# runtime stage — nginx + Honcho FastAPI
FROM python:3.13-slim-bookworm FROM python:3.13-slim-bookworm
# Install nginx and create runtime dirs before dropping permissions RUN groupadd --system app && \
RUN apt-get update && apt-get install -y --no-install-recommends nginx && \ useradd --system --gid app --create-home app
rm -rf /var/log/nginx/* && \
rm -rf /var/lib/apt/lists/* && \
rm -f /etc/nginx/sites-enabled/default
# Patch nginx.conf: comment out "user www-data;" so nginx master stays as root COPY --from=builder /app /app
# (workers inherit root inside a container — fine for single-service isolation) COPY --from=builder /root/.cache/uv /root/.cache/uv
RUN sed -i 's/^user /# user /' /etc/nginx/nginx.conf
# Pre-create nginx runtime directories with proper ownership
RUN mkdir -p /var/lib/nginx/body /var/lib/nginx/proxy /var/lib/nginx/fastcgi \
/var/lib/nginx/uwsgi /var/lib/nginx/scgi /var/lib/nginx/proxy_temp \
/var/cache/nginx && \
chown -R root:root /var/lib/nginx /var/cache/nginx
# Honcho
COPY --from=honcho-builder /app /app
WORKDIR /app WORKDIR /app
ENV PATH="/app/.venv/bin:$PATH" ENV PATH="/app/.venv/bin:$PATH"
ENV HOME=/app ENV HOME=/app
COPY config.toml /app/config.toml
# OpenConcho SPA COPY --chown=app:app config.toml /app/config.toml
COPY --from=openconcho-builder /app/packages/web/dist /usr/share/nginx/html
# nginx config (proxies /v3/, /v2/ to Honcho on localhost:8000) USER app
COPY honcho-nginx.conf /etc/nginx/conf.d/default.conf EXPOSE 8000
EXPOSE 80 CMD ["fastapi", "run", "--host", "0.0.0.0", "src/main.py"]
CMD ["bash", "-c", "nginx -g 'daemon off;' & fastapi run --host 127.0.0.1 --port 8000 src/main.py & python3 -m src.deriver & wait -n"]

View File

@@ -29,17 +29,17 @@ URL = "redis://honcho-redis:6379/0"
[llm] [llm]
DEFAULT_MAX_TOKENS = 4096 DEFAULT_MAX_TOKENS = 4096
# Embeddings via Ollama — bge-m3 provides 1024-dim # Embeddings via Ollama (nomic-embed-text recommended on this system)
[embedding] [embedding]
VECTOR_DIMENSIONS = 1024 VECTOR_DIMENSIONS = 768
MAX_INPUT_TOKENS = 8192 MAX_INPUT_TOKENS = 8192
[embedding.model_config] [embedding.model_config]
transport = "openai" transport = "openai"
model = "bge-m3" model = "nomic-embed-text"
overrides = {base_url = "http://ollama:11434/v1", api_key = "ollama"} base_url = "http://ollama:11434/v1"
# --- Deriver --- # --- Deriver (user representation builder) ---
[deriver] [deriver]
ENABLED = true ENABLED = true
WORKERS = 1 WORKERS = 1
@@ -47,9 +47,9 @@ POLLING_SLEEP_INTERVAL_SECONDS = 5.0
FLUSH_ENABLED = true FLUSH_ENABLED = true
[deriver.model_config] [deriver.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
# --- Dialectic --- # --- Dialectic ---
[dialectic] [dialectic]
@@ -60,37 +60,37 @@ SESSION_HISTORY_MAX_TOKENS = 8192
MAX_TOOL_ITERATIONS = 1 MAX_TOOL_ITERATIONS = 1
MAX_OUTPUT_TOKENS = 512 MAX_OUTPUT_TOKENS = 512
[dialectic.levels.minimal.model_config] [dialectic.levels.minimal.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
[dialectic.levels.low] [dialectic.levels.low]
MAX_TOOL_ITERATIONS = 3 MAX_TOOL_ITERATIONS = 3
[dialectic.levels.low.model_config] [dialectic.levels.low.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
[dialectic.levels.medium] [dialectic.levels.medium]
MAX_TOOL_ITERATIONS = 2 MAX_TOOL_ITERATIONS = 2
[dialectic.levels.medium.model_config] [dialectic.levels.medium.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
[dialectic.levels.high] [dialectic.levels.high]
MAX_TOOL_ITERATIONS = 4 MAX_TOOL_ITERATIONS = 4
[dialectic.levels.high.model_config] [dialectic.levels.high.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
[dialectic.levels.max] [dialectic.levels.max]
MAX_TOOL_ITERATIONS = 10 MAX_TOOL_ITERATIONS = 10
[dialectic.levels.max.model_config] [dialectic.levels.max.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
# --- Summary --- # --- Summary ---
[summary] [summary]
@@ -99,28 +99,13 @@ MESSAGES_PER_SHORT_SUMMARY = 20
MESSAGES_PER_LONG_SUMMARY = 60 MESSAGES_PER_LONG_SUMMARY = 60
[summary.model_config] [summary.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai" transport = "openai"
model = "deepseek-v4-flash" model = "hermes-3"
base_url = "http://ollama:11434/v1"
# --- Dream --- # --- Dream ---
[dream] [dream]
ENABLED = true ENABLED = false
[dream.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dream.deduction_model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dream.induction_model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
# --- Peer Card --- # --- Peer Card ---
[peer_card] [peer_card]
@@ -129,4 +114,4 @@ ENABLED = true
# --- Vector Store --- # --- Vector Store ---
[vector_store] [vector_store]
TYPE = "pgvector" TYPE = "pgvector"
# DIMENSIONS is deprecated — EMBEDDING.VECTOR_DIMENSIONS is authoritative DIMENSIONS = 768

View File

@@ -1,52 +0,0 @@
server {
listen 80 default_server;
listen [::]:80 default_server;
server_name _;
root /usr/share/nginx/html;
index index.html;
# Honcho API proxy
location /v3/ {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /v2/ {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# Honcho health
location /health {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# OpenAPI docs
location /openapi.json {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# SPA: fallback to index.html for client-side routing
location / {
try_files $uri $uri/ /index.html;
}
}

View File

@@ -32,5 +32,5 @@ services:
networks: networks:
auth_net: auth_net:
driver: bridge external: true
name: auth_net name: auth_net

View File

@@ -68,33 +68,33 @@ services:
labels: labels:
- "traefik.enable=false" # Internal only, accessed by restic-browser - "traefik.enable=false" # Internal only, accessed by restic-browser
# restic-browser: restic-browser:
# image: mazzolino/restic-browser:latest image: embergarage/restic-browser:latest
# container_name: restic-browser container_name: restic-browser
# restart: always restart: always
# environment: environment:
# - TZ=America/Montreal - TZ=America/Montreal
# - RESTIC_REPOSITORY=http://restic-server:8080 - RESTIC_REPOSITORY=http://restic-server:8080
# - RESTIC_PASSWORD=${RESTIC_PASSWORD} - RESTIC_PASSWORD=${RESTIC_PASSWORD}
# networks: networks:
# - backup_net - backup_net
# labels: labels:
# - "traefik.enable=true" - "traefik.enable=true"
# # 1. HTTP to HTTPS Redirect # 1. HTTP to HTTPS Redirect
# - "traefik.http.routers.restic-browser-http.rule=Host(`backup.lazyworkhorse.net`)" - "traefik.http.routers.restic-browser-http.rule=Host(`backup.lazyworkhorse.net`)"
# - "traefik.http.routers.restic-browser-http.entrypoints=web" - "traefik.http.routers.restic-browser-http.entrypoints=web"
# - "traefik.http.routers.restic-browser-http.middlewares=redirect-to-https@docker" - "traefik.http.routers.restic-browser-http.middlewares=redirect-to-https@docker"
#
# # 2. HTTPS Configuration # 2. HTTPS Configuration
# - "traefik.http.routers.restic-browser.rule=Host(`backup.lazyworkhorse.net`)" - "traefik.http.routers.restic-browser.rule=Host(`backup.lazyworkhorse.net`)"
# - "traefik.http.routers.restic-browser.entrypoints=websecure" - "traefik.http.routers.restic-browser.entrypoints=websecure"
# - "traefik.http.routers.restic-browser.tls=true" - "traefik.http.routers.restic-browser.tls=true"
# - "traefik.http.routers.restic-browser.tls.certresolver=njalla" - "traefik.http.routers.restic-browser.tls.certresolver=njalla"
#
# # 3. Backend Service Config # 3. Backend Service Config
# - "traefik.http.services.restic-browser.loadbalancer.server.port=8000" - "traefik.http.services.restic-browser.loadbalancer.server.port=8000"
networks: networks:
backup_net: backup_net:
driver: bridge external: true
name: backup_net name: backup_net

View File

@@ -6,7 +6,6 @@ services:
restart: always restart: always
networks: networks:
- cloud_net - cloud_net
- cloud_internal
environment: environment:
- PUID=1000 - PUID=1000
- PGID=1000 - PGID=1000
@@ -52,7 +51,7 @@ services:
container_name: nextcloud_cron container_name: nextcloud_cron
restart: always restart: always
networks: networks:
- cloud_internal - cloud_net
entrypoint: /cron.sh entrypoint: /cron.sh
volumes: volumes:
- /mnt/HoardingCow_docker_data/NextCloud/data:/var/www/html:rw - /mnt/HoardingCow_docker_data/NextCloud/data:/var/www/html:rw
@@ -76,7 +75,7 @@ services:
networks: networks:
cloud_net: cloud_net:
driver: bridge external: true
name: cloud_net name: cloud_net
cloud_internal: cloud_internal:
driver: bridge driver: bridge

View File

@@ -103,7 +103,7 @@ services:
networks: networks:
coms_net: coms_net:
driver: bridge external: true
name: coms_net name: coms_net
coms_backend: coms_backend:
driver: bridge driver: bridge

View File

@@ -37,5 +37,4 @@ services:
networks: networks:
finance_net: finance_net:
driver: bridge external: true
name: finance_net

View File

@@ -12,8 +12,8 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/Home_Assistant:/config:rw - /mnt/HoardingCow_docker_data/Home_Assistant:/config:rw
networks: networks:
- home_net - home_auto_net
- home_backend - home_auto_backend
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
@@ -34,7 +34,7 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/Mosquitto:/mosquitto - /mnt/HoardingCow_docker_data/Mosquitto:/mosquitto
networks: networks:
- home_backend - home_auto_backend
# ports: # ports:
# - 1883:1883 # - 1883:1883
# - 9001:9001 # - 9001:9001
@@ -43,7 +43,7 @@ services:
image: registry.gitlab.com/hydroqc/hydroqc2mqtt:1.3.0 image: registry.gitlab.com/hydroqc/hydroqc2mqtt:1.3.0
restart: always restart: always
networks: networks:
- home_backend - home_auto_backend
environment: environment:
MQTT_USERNAME: hass MQTT_USERNAME: hass
MQTT_PASSWORD: ${MQTT_PASSWORD} MQTT_PASSWORD: ${MQTT_PASSWORD}
@@ -88,9 +88,8 @@ services:
# restart: unless-stopped # restart: unless-stopped
networks: networks:
home_net: home_auto_net:
external: true
home_auto_backend:
driver: bridge driver: bridge
name: home_net name: home_auto_backend
home_backend:
driver: bridge
name: home_backend

View File

@@ -38,5 +38,4 @@ services:
networks: networks:
homepage_net: homepage_net:
driver: bridge external: true
name: homepage_net

View File

@@ -36,9 +36,9 @@ services:
- cloud_net - cloud_net
- coms_net - coms_net
- finance_net - finance_net
- home_net - home_auto_net
- homepage_net - homepage_net
- pass_net - passman_net
- tak_net - tak_net
- vc_net - vc_net
@@ -82,37 +82,37 @@ networks:
driver: bridge driver: bridge
name: traefik_backend name: traefik_backend
ai_net: ai_net:
driver: bridge external: true
name: ai_net name: ai_net
auth_net: auth_net:
driver: bridge external: true
name: auth_net name: auth_net
backup_net: backup_net:
driver: bridge external: true
name: backup_net name: backup_net
cloud_net: cloud_net:
driver: bridge external: true
name: cloud_net name: cloud_net
coms_net: coms_net:
driver: bridge external: true
name: coms_net name: coms_net
finance_net: finance_net:
driver: bridge external: true
name: finance_net name: finance_net
home_net: home_auto_net:
driver: bridge external: true
name: home_net name: home_auto_net
homepage_net: homepage_net:
driver: bridge external: true
name: homepage_net name: homepage_net
pass_net: passman_net:
driver: bridge external: true
name: pass_net name: passman_net
tak_net: tak_net:
driver: bridge external: true
name: tak_net name: tak_net
vc_net: vc_net:
driver: bridge external: true
name: vc_net name: vc_net
# duckdns: # duckdns:

View File

@@ -13,7 +13,7 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/BitWarden/data:/data:rw - /mnt/HoardingCow_docker_data/BitWarden/data:/data:rw
networks: networks:
- pass_net - passman_net
restart: always restart: always
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
@@ -32,6 +32,5 @@ services:
# Internal service # Internal service
- "traefik.http.services.pass.loadbalancer.server.port=80" - "traefik.http.services.pass.loadbalancer.server.port=80"
networks: networks:
pass_net: passman_net:
driver: bridge external: true
name: pass_net

View File

@@ -92,8 +92,7 @@ services:
networks: networks:
tak_net: tak_net:
driver: bridge external: true
name: tak_net
tak_backend: tak_backend:
driver: bridge driver: bridge
name: tak_backend name: tak_backend

View File

@@ -61,5 +61,4 @@ services:
networks: networks:
vc_net: vc_net:
driver: bridge external: true
name: vc_net

View File

@@ -12,7 +12,7 @@ services:
- SYS_MODULE - SYS_MODULE
environment: environment:
- WG_HOST=vpn.lazyworkhorse.net - WG_HOST=vpn.lazyworkhorse.net
- PASSWORD_HASH=${WG_PASSWORD_HASH} - PASSWORD=${WG_PASSWORD}
- WG_PORT=51820 - WG_PORT=51820
- WG_DEFAULT_ADDRESS=10.8.0.x - WG_DEFAULT_ADDRESS=10.8.0.x
- WG_DEFAULT_DNS=1.1.1.1,8.8.8.8 - WG_DEFAULT_DNS=1.1.1.1,8.8.8.8
@@ -22,6 +22,7 @@ services:
- UI_CHART_TYPE=0 - UI_CHART_TYPE=0
ports: ports:
- "51820:51820/udp" - "51820:51820/udp"
- "51821:51821/tcp"
volumes: volumes:
- /mnt/HoardingCow_docker_data/WireGuard:/etc/wireguard:rw - /mnt/HoardingCow_docker_data/WireGuard:/etc/wireguard:rw
sysctls: sysctls:
@@ -30,31 +31,8 @@ services:
restart: unless-stopped restart: unless-stopped
networks: networks:
- vpn_net - vpn_net
labels:
- "traefik.enable=true"
# HTTP → HTTPS redirect
- "traefik.http.routers.wireguard-http.rule=Host(vpn.lazyworkhorse.net)"
- "traefik.http.routers.wireguard-http.entrypoints=web"
- "traefik.http.routers.wireguard-http.middlewares=redirect-to-https"
- "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https"
# HTTPS router — protégé par Authelia
- "traefik.http.routers.wireguard-https.rule=Host(vpn.lazyworkhorse.net)"
- "traefik.http.routers.wireguard-https.entrypoints=websecure"
- "traefik.http.routers.wireguard-https.tls=true"
- "traefik.http.routers.wireguard-https.tls.certresolver=njalla"
- "traefik.http.routers.wireguard-https.middlewares=wireguard-auth"
# Authelia forwardAuth
- "traefik.http.middlewares.wireguard-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/"
- "traefik.http.middlewares.wireguard-auth.forwardauth.trustforwardheader=true"
- "traefik.http.middlewares.wireguard-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups"
# Port interne du web UI wg-easy
- "traefik.http.services.wireguard.loadbalancer.server.port=51821"
networks: networks:
vpn_net: vpn_net:
driver: bridge external: true
name: vpn_net name: vpn_net