Compare commits

..

1 Commits

Author SHA1 Message Date
bbbdb92583 Merge pull request 'fix: remove stale COPY line for deleted run-multi-gateways.sh' (#59) from fix/remove-stale-copy into master
Some checks failed
Build Hermes agent / build (push) Has been cancelled
Reviewed-on: #59
2026-07-08 02:34:52 +00:00

View File

@@ -1,90 +1,106 @@
services: services:
hermes: hermes:
build: build:
context: ./hermes context: ./hermes
ssh:
- default
container_name: hermes container_name: hermes
restart: always restart: always
# Gateway run enables the internal API server on port 8642
command: gateway run command: gateway run
environment: environment:
- HERMES_UID=10000 - HERMES_UID=10000
- HERMES_GID=10000 - HERMES_GID=10000
- OLLAMA_HOST=http://ollama-cpu:11434 - OLLAMA_HOST=http://ollama-cpu:11434
- HERMES_DASHBOARD=1 - HERMES_DASHBOARD=1
- API_SERVER_ENABLED=true - API_SERVER_ENABLED=true
- API_SERVER_PORT=8642 - API_SERVER_PORT=8642
- API_SERVER_HOST=0.0.0.0 - API_SERVER_HOST=0.0.0.0
- API_SERVER_KEY=hermes_local_key - API_SERVER_KEY=hermes_local_key
- GATEWAY_ALLOW_ALL_USERS=true - GATEWAY_ALLOW_ALL_USERS=true
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY} - OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
- OPENCODE_API_KEY=${OPENCODE_API_KEY} - OPENCODE_API_KEY=${OPENCODE_API_KEY}
- HSA_OVERRIDE_GFX_VERSION=9.0.6 # ROCm for GPU-accelerated faster-whisper STT
- HCC_AMDGPU_TARGET=gfx906 - HSA_OVERRIDE_GFX_VERSION=9.0.6
- HIP_VISIBLE_DEVICES=0,1 - HCC_AMDGPU_TARGET=gfx906
- ROCR_VISIBLE_DEVICES=0,1 - HIP_VISIBLE_DEVICES=0,1
- HSA_ENABLE_SDMA=0 - ROCR_VISIBLE_DEVICES=0,1
- TZ=America/Montreal - HSA_ENABLE_SDMA=0
- TZ=America/Montreal
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data - /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex - /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex
devices: devices:
- /dev/kfd:/dev/kfd - /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
group_add: group_add:
- '303' - "303"
- '26' - "26"
networks: networks:
ai_backend: null - ai_backend
ai_net: null - ai_net
vpn_net:
ipv4_address: 172.24.0.5
depends_on: depends_on:
- honcho - honcho
labels: labels:
- traefik.enable=true - "traefik.enable=true"
- traefik.docker.network=ai_net - "traefik.docker.network=ai_net"
- traefik.http.routers.hermes-web-http.rule=Host(`hermes.lazyworkhorse.net`)
- traefik.http.routers.hermes-web-http.entrypoints=web # Router for HTTP + redirection to HTTPS
- traefik.http.routers.hermes-web-http.middlewares=redirect-to-https - "traefik.http.routers.hermes-web-http.rule=Host(`hermes.lazyworkhorse.net`)"
- traefik.http.routers.hermes-web-https.rule=Host(`hermes.lazyworkhorse.net`) - "traefik.http.routers.hermes-web-http.entrypoints=web"
- traefik.http.routers.hermes-web-https.entrypoints=websecure - "traefik.http.routers.hermes-web-http.middlewares=redirect-to-https"
- traefik.http.routers.hermes-web-https.tls=true
- traefik.http.routers.hermes-web-https.tls.certresolver=njalla # Router for HTTPS with TLS — protected by Authelia
- traefik.http.routers.hermes-web-https.middlewares=hermes-auth - "traefik.http.routers.hermes-web-https.rule=Host(`hermes.lazyworkhorse.net`)"
- traefik.http.middlewares.hermes-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/ - "traefik.http.routers.hermes-web-https.entrypoints=websecure"
- traefik.http.middlewares.hermes-auth.forwardauth.trustforwardheader=true - "traefik.http.routers.hermes-web-https.tls=true"
- traefik.http.middlewares.hermes-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups - "traefik.http.routers.hermes-web-https.tls.certresolver=njalla"
- traefik.http.services.hermes-web.loadbalancer.server.port=9119 - "traefik.http.routers.hermes-web-https.middlewares=hermes-auth"
# Authelia forwardAuth
- "traefik.http.middlewares.hermes-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/"
- "traefik.http.middlewares.hermes-auth.forwardauth.trustforwardheader=true"
- "traefik.http.middlewares.hermes-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups"
# Service Loadbalancer (dashboard port 9119)
- "traefik.http.services.hermes-web.loadbalancer.server.port=9119"
syncthing: syncthing:
image: syncthing/syncthing:latest image: syncthing/syncthing:latest
container_name: syncthing container_name: syncthing
hostname: syncthing hostname: syncthing
restart: always restart: always
ports: ports:
- 8384:8384 - "8384:8384"
- 22000:22000 - "22000:22000"
- 21027:21027/udp - "21027:21027/udp"
environment: environment:
- TZ=America/Montreal - TZ=America/Montreal
- PUID=10000 - PUID=10000
- PGID=10000 - PGID=10000
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config - /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex - /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex
networks: networks:
- ai_backend - ai_backend
- ai_net - ai_net
labels: labels:
- traefik.enable=true - "traefik.enable=true"
- traefik.docker.network=ai_net - "traefik.docker.network=ai_net"
- traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)
- traefik.http.routers.syncthing-http.entrypoints=web - "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)"
- traefik.http.routers.syncthing-http.middlewares=redirect-to-https - "traefik.http.routers.syncthing-http.entrypoints=web"
- traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`) - "traefik.http.routers.syncthing-http.middlewares=redirect-to-https"
- traefik.http.routers.syncthing-https.entrypoints=websecure
- traefik.http.routers.syncthing-https.tls=true - "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)"
- traefik.http.routers.syncthing-https.tls.certresolver=njalla - "traefik.http.routers.syncthing-https.entrypoints=websecure"
- traefik.http.routers.syncthing-https.middlewares=hermes-auth - "traefik.http.routers.syncthing-https.tls=true"
- traefik.http.services.syncthing.loadbalancer.server.port=8384 - "traefik.http.routers.syncthing-https.tls.certresolver=njalla"
- "traefik.http.routers.syncthing-https.middlewares=hermes-auth"
- "traefik.http.services.syncthing.loadbalancer.server.port=8384"
ollama-cpu: ollama-cpu:
build: build:
context: ./ollama context: ./ollama
@@ -92,110 +108,126 @@ services:
image: ollama/ollama:rocm-gfx906 image: ollama/ollama:rocm-gfx906
container_name: ollama-cpu container_name: ollama-cpu
tty: true tty: true
restart: always restart: always
ports: ports:
- 127.0.0.1:11434:11434 - "127.0.0.1:11434:11434"
networks: networks:
- ai_backend - ai_backend
volumes: volumes:
- /mnt/HoardingCow_docker_data/Ollama/ollama:/root/.ollama - /mnt/HoardingCow_docker_data/Ollama/ollama:/root/.ollama
environment: environment:
- OLLAMA_VULKAN=0 - OLLAMA_VULKAN=0
- OLLAMA_HOST=0.0.0.0 - OLLAMA_HOST=0.0.0.0
llama-cpp-hermes: llama-cpp-hermes:
image: llama-cpp:rocm-gfx906 image: llama-cpp:rocm-gfx906
container_name: llama-cpp-hermes container_name: llama-cpp-hermes
restart: unless-stopped restart: unless-stopped
networks: networks:
- ai_backend - ai_backend
ports: ports:
- 127.0.0.1:8300:8080 - "127.0.0.1:8300:8080"
ipc: host ipc: host
devices: devices:
- /dev/kfd:/dev/kfd - /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
group_add: group_add:
- '303' - "303"
- '26' - "26"
environment: environment:
- HSA_OVERRIDE_GFX_VERSION=9.0.6 - HSA_OVERRIDE_GFX_VERSION=9.0.6
- HSA_ENABLE_SDMA=0 - HSA_ENABLE_SDMA=0
- HIP_VISIBLE_DEVICES=0,1 - HIP_VISIBLE_DEVICES=0,1
- LLAMA_CACHE=/models - LLAMA_CACHE=/models
volumes: volumes:
- /mnt/HoardingCow_docker_data/Llama_cpp/models:/models - /mnt/HoardingCow_docker_data/Llama_cpp/models:/models
- /mnt/HoardingCow_docker_data/Ollama/ollama/models/blobs/sha256-17823599694fa3503ef54bf748d5078c6ce881f4d01616cafa255dc05d215a08:/model.gguf:ro - /mnt/HoardingCow_docker_data/Ollama/ollama/models/blobs/sha256-17823599694fa3503ef54bf748d5078c6ce881f4d01616cafa255dc05d215a08:/model.gguf:ro
command: '-m /model.gguf --host 0.0.0.0 --port 8080 --gpu-layers 99 --ctx-size command: >
163840 -ctk f16 -ctv f16 --flash-attn on --split-mode layer --no-mmap --n-predict -m /model.gguf
-1 --host 0.0.0.0
--port 8080
--gpu-layers 99
--ctx-size 163840
-ctk f16 -ctv f16
--flash-attn on
--split-mode layer
--no-mmap
--n-predict -1
' # --- Honcho + OpenConcho combiné: API + Web UI nginx/FastAPI ---
honcho: honcho:
build: build:
context: ./honcho context: ./honcho
ssh: ssh:
- default - default
container_name: honcho container_name: honcho
restart: unless-stopped restart: unless-stopped
environment: environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho - DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0 - CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true - CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024 - EMBEDDING_VECTOR_DIMENSIONS=1024
- AUTH_USE_AUTH=true - AUTH_USE_AUTH=true
- AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET} - AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET}
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY} # Needed by deriver/dream to make LLM calls (api_key_env = "HONCHO_OPENAI_API_KEY" in config.toml)
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY}
volumes: volumes:
- /mnt/HoardingCow_docker_data/Honcho/data:/app/data - /mnt/HoardingCow_docker_data/Honcho/data:/app/data
- /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro - /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro
networks: networks:
- ai_backend - ai_backend
- ai_net - ai_net
labels: labels:
- traefik.enable=true - "traefik.enable=true"
- traefik.docker.network=ai_net - "traefik.docker.network=ai_net"
- traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)
- traefik.http.routers.honcho-http.entrypoints=web # Router for HTTP + redirect to HTTPS
- traefik.http.routers.honcho-http.middlewares=redirect-to-https - "traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)"
- traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`) - "traefik.http.routers.honcho-http.entrypoints=web"
- traefik.http.routers.honcho-https.entrypoints=websecure - "traefik.http.routers.honcho-http.middlewares=redirect-to-https"
- traefik.http.routers.honcho-https.tls=true
- traefik.http.routers.honcho-https.tls.certresolver=njalla # Router for HTTPS with TLS — protected by Authelia
- traefik.http.routers.honcho-https.middlewares=hermes-auth - "traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`)"
- traefik.http.services.honcho.loadbalancer.server.port=80 - "traefik.http.routers.honcho-https.entrypoints=websecure"
- "traefik.http.routers.honcho-https.tls=true"
- "traefik.http.routers.honcho-https.tls.certresolver=njalla"
- "traefik.http.routers.honcho-https.middlewares=hermes-auth"
# Service Loadbalancer (nginx port)
- "traefik.http.services.honcho.loadbalancer.server.port=80"
depends_on: depends_on:
- honcho-db - honcho-db
- honcho-redis - honcho-redis
honcho-db: honcho-db:
image: pgvector/pgvector:pg15 image: pgvector/pgvector:pg15
container_name: honcho-db container_name: honcho-db
restart: unless-stopped restart: unless-stopped
ports: ports:
- 127.0.0.1:5432:5432 - "127.0.0.1:5432:5432"
command: command: ["postgres", "-c", "max_connections=200"]
- postgres
- -c
- max_connections=200
environment: environment:
- POSTGRES_DB=honcho - POSTGRES_DB=honcho
- POSTGRES_USER=honcho - POSTGRES_USER=honcho
- POSTGRES_PASSWORD=honcho_pass - POSTGRES_PASSWORD=honcho_pass
- PGDATA=/var/lib/postgresql/data/pgdata - PGDATA=/var/lib/postgresql/data/pgdata
volumes: volumes:
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data - /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data
- ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro - ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro
networks: networks:
- ai_backend - ai_backend
honcho-redis: honcho-redis:
image: redis:8 image: redis:8
container_name: honcho-redis container_name: honcho-redis
restart: unless-stopped restart: unless-stopped
ports: ports:
- 127.0.0.1:6379:6379 - "127.0.0.1:6379:6379"
volumes: volumes:
- /mnt/HoardingCow_docker_data/Honcho/redis:/data - /mnt/HoardingCow_docker_data/Honcho/redis:/data
networks: networks:
- ai_backend - ai_backend
networks: networks:
ai_net: ai_net:
driver: bridge driver: bridge
@@ -203,10 +235,193 @@ networks:
ai_backend: ai_backend:
driver: bridge driver: bridge
name: ai_backend name: ai_backend
vpn_net:
external: true
name: vpn_net
volumes: volumes:
honcho_data: honcho_data:
driver: bridge driver: bridge
name: honcho_data name: honcho_data
# vllm:
# image: nalanzeyu/vllm-gfx906:v0.9.0-rocm6.3
# container_name: vllm
# # Required for multi-GPU communication (NCCL)
# ipc: host
# init: true
# shm_size: '2g'
# networks:
# - ai_backend
# ports:
# - "8300:8000"
# devices:
# - "/dev/kfd:/dev/kfd"
# - "/dev/dri:/dev/dri"
# group_add:
# - "303"
# - "26"
# environment:
# HSA_OVERRIDE_GFX_VERSION: 9.0.6
# HSA_ENABLE_SDMA: 0
# HIP_VISIBLE_DEVICES: 0,1
# NCCL_P2P_DISABLE: 1
# VLLM_WORKER_MULTIPROC_METHOD: spawn
# VLLM_USE_TRITON_FLASH_ATTN: 0
# VLLM_USE_ROCM_CUSTOM_PAGED_ATTN: 0
# VLLM_ATTENTION_BACKEND: ROPE_NAIVE
# VLLM_SKIP_WARMUP: 1
# VLLM_USE_V1: 0
# HF_TOKEN: ${HF_TOKEN}
# command: >
# vllm serve "mistralai/Devstral-Small-2-24B-Instruct-2512"
# --tensor-parallel-size 2
# --max-model-len 8192
# --gpu-memory-utilization 0.90
# --tokenizer_mode mistral
# --config_format auto
# --load-format auto
# --enforce-eager
# --disable-custom-all-reduce
# --trust-remote-code
# --task generate
# --block-size 16
# volumes:
# - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface
# restart: unless-stopped
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
# n8n:
# image: n8nio/n8n:latest
# container_name: n8n
# restart: unless-stopped
# networks:
# - ai_net
# environment:
# - N8N_HOST=n8n.lazyworkhorse.net
# - N8N_PORT=5678
# - N8N_PROTOCOL=https
# - NODE_ENV=production
# - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
# - WEBHOOK_URL=https://n8n.lazyworkhorse.net/
# - GENERIC_TIMEZONE=America/New_York # Adjust to your timezone
# - N8N_BLOCK_EXTERNAL_STORAGE_ACCESS=false
# - N8N_NODES_PYTHON_CAN_IMPORT_MODULES=true
# - N8N_NATIVE_PYTHON_RUNNER=true
# - N8N_PYTHON_ALLOW_STDLIB=uuid,re,os,json
# - N8N_PYTHON_ALLOW_EXTERNAL=requests,pandas
# - NODE_FUNCTION_ALLOW_EXTERNAL=uuid,requests
# volumes:
# - /mnt/HoardingCow_docker_data/n8n:/home/node/.n8n
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.n8n-http.rule=Host(`n8n.lazyworkhorse.net`)"
# - "traefik.http.routers.n8n-http.entrypoints=web"
# - "traefik.http.routers.n8n-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.n8n-https.rule=Host(`n8n.lazyworkhorse.net`)"
# - "traefik.http.routers.n8n-https.entrypoints=websecure"
# - "traefik.http.routers.n8n-https.tls=true"
# - "traefik.http.routers.n8n-https.tls.certresolver=njalla"
# # Service Loadbalancer (n8n default port)
# - "traefik.http.services.n8n.loadbalancer.server.port=5678"
# openclaw:
# image: coollabsio/openclaw:latest
# container_name: openclaw
# restart: unless-stopped
# expose:
# - "8080" # WebUI
# - "18789" # Gateway/WebSocket
# - "8788" # Nextcloud Webhook
# networks:
# - ai_net
# - ai_backend
# volumes:
# - /mnt/HoardingCow_docker_data/openclaw/data:/data
# - /home/gortium/infra:/data/workspace/infra
# environment:
# - TZ=America/Toronto
# - OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN}
# - OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
# # Point to the sidecar browser
# - BROWSER_CDP_URL=http://openclaw-browser:9222
# - BROWSER_EVALUATE_ENABLED=true
# - OPENCLAW_GATEWAY_HOST=0.0.0.0
# - OPENCLAW_ALLOWED_ORIGINS=https://claw.lazyworkhorse.net
# labels:
# - "traefik.enable=true"
# - "traefik.http.routers.openclaw-http.rule=Host(`claw.lazyworkhorse.net`)"
# - "traefik.http.routers.openclaw-http.entrypoints=web"
# - "traefik.http.routers.openclaw-http.middlewares=redirect-to-https"
# - "traefik.http.routers.openclaw-https.rule=Host(`claw.lazyworkhorse.net`)"
# - "traefik.http.routers.openclaw-https.priority=50"
# - "traefik.http.routers.openclaw-https.entrypoints=websecure"
# - "traefik.http.routers.openclaw-https.tls=true"
# - "traefik.http.routers.openclaw-https.tls.certresolver=njalla"
# - "traefik.http.services.openclaw.loadbalancer.server.port=8080"
# depends_on:
# - openclaw-browser
# openclaw-browser:
# image: ghcr.io/browserless/chromium:latest
# restart: always
# expose:
# - "3000"
# environment:
# - MAX_CONCURRENT_SESSIONS=10
# - CONNECTION_TIMEOUT=300000
# - PREBOOT_CHROME=true
# - DEMO_MODE=false
# networks:
# ai_backend:
# aliases:
# - browser
# openclaw-ssh:
# image: linuxserver/openssh-server:latest
# container_name: openclaw-ssh
# environment:
# - PUID=1000
# - PGID=1000
# - PUBLIC_KEY_FILE=/config/ssh/authorized_keys
# - SUDO_ACCESS=false
# - PASSWORD_ACCESS=false
# volumes:
# - /mnt/HoardingCow_docker_data/openclaw/ssh-config:/config
# - /home/gortium/infra:/data/workspace/infra:ro
# restart: unless-stopped
# networks:
# - ai_backend
# labels:
# - "traefik.enable=true"
# - "traefik.tcp.routers.openclaw-ssh.rule=HostSNI(*)"
# - "traefik.tcp.routers.openclaw-ssh.entrypoints=sshnode"
# - "traefik.tcp.routers.openclaw-ssh.tls.passthrough=false"
# - "traefik.tcp.services.openclaw-ssh.loadbalancer.server.port=2222"