Compare commits

..

3 Commits

Author SHA1 Message Date
be9c02389a hermes: add dashboard-cathou to s6 boot bundle (auto-start on recreate)
Some checks are pending
Build Hermes agent / build (pull_request) Waiting to run
Build ollama (gfx906) / build (pull_request) Waiting to run
2026-09-18 17:12:26 -04:00
888523079f hermes: route all dashboard/honcho secrets through age-backed env (no hardcoded values for public repo); add main-dash auth env
Some checks are pending
Build Hermes agent / build (pull_request) Waiting to run
Build ollama (gfx906) / build (pull_request) Waiting to run
2026-09-18 16:23:28 -04:00
5e8d669a2c hermes: add supervised dashboard-cathou service (:9120, own identity). Second s6 service reusing the main dashboard machinery, mounted read-only; env injected in compose. Runs the command directly to dodge the with-contenv env reset that would collapse it to the main service identity. 2026-09-18 16:04:06 -04:00
6 changed files with 32 additions and 2 deletions

View File

@@ -23,9 +23,16 @@ services:
- ROCR_VISIBLE_DEVICES=0,1
- HSA_ENABLE_SDMA=0
- TZ=America/Montreal
- CATHOU_SERVE_PASSWORD=${CATHOU_SERVE_PASSWORD:?must be set}
- CATHOU_SERVE_SECRET=${CATHOU_SERVE_SECRET:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_USERNAME=thierry
- HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=${HERMES_DASHBOARD_BASIC_AUTH_PASSWORD:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_SECRET=${HERMES_DASHBOARD_BASIC_AUTH_SECRET:?must be set}
volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex
- ./s6/dashboard-cathou:/etc/s6-overlay/s6-rc.d/dashboard-cathou:ro
- ./s6/user/contents.d/dashboard-cathou:/etc/s6-overlay/s6-rc.d/user/contents.d/dashboard-cathou:ro
devices:
- /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri
@@ -138,7 +145,7 @@ services:
container_name: honcho
restart: unless-stopped
environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho
- DB_CONNECTION_URI=postgresql+psycopg://honcho:${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024
@@ -179,7 +186,7 @@ services:
environment:
- POSTGRES_DB=honcho
- POSTGRES_USER=honcho
- POSTGRES_PASSWORD=honcho_pass
- POSTGRES_PASSWORD=${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}
- PGDATA=/var/lib/postgresql/data/pgdata
volumes:
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data

View File

@@ -0,0 +1 @@
base

View File

@@ -0,0 +1,4 @@
#!/command/with-contenv sh
# Always restart on exit (exit != 125). Crash-loop with a bad auth
# config is the intended fail-closed signal.
exit 0

View File

@@ -0,0 +1,17 @@
#!/command/with-contenv sh
# Personal dashboard serve (:9120) for cathou — same machinery as the
# main dashboard service, but runs the command directly so its OWN
# with-contenv shebang can't wipe our env (a second with-contenv reset
# would drop the port + auth variables). Supervised by s6: restarts on crash.
export HERMES_DASHBOARD_PORT=9120
export HERMES_DASHBOARD_BASIC_AUTH_USERNAME=cathou
export HERMES_DASHBOARD_BASIC_AUTH_PASSWORD="${CATHOU_SERVE_PASSWORD:-}"
export HERMES_DASHBOARD_BASIC_AUTH_SECRET="${CATHOU_SERVE_SECRET:-}"
export HOME=/opt/data
cd /opt/data
# shellcheck disable=SC1091
. /opt/hermes/.venv/bin/activate
# Fail-closed: missing password => provider won't register => serve fails
# => s6 crash-loop surfaces it, never a silent unauthenticated bind.
[ "$(id -u)" = 0 ] || exec hermes dashboard --host 0.0.0.0 --port 9120 --no-open
exec s6-setuidgid hermes hermes dashboard --host 0.0.0.0 --port 9120 --no-open

View File

@@ -0,0 +1 @@
longrun

View File