Compare commits

..

1 Commits

Author SHA1 Message Date
8adbbf0ed4 fix: add Matrix bridge deps to compose entrypoint with persistent venv
Adds uv pip install openai mautrix[encryption] to the hermes container
entrypoint, with volume mount at /opt/hermes/.venv for persistence.

Key changes:
- Entrypoint now activates venv and installs Matrix bridge deps before
  running the official entrypoint.sh
- Handles empty-volume first-boot by recreating the venv from scratch
  (matching Dockerfile install steps)
- Persists venv at /mnt/HoardingCow_docker_data/Hermes/venv so pip
  packages survive container recreation
2026-05-20 14:35:24 -04:00
21 changed files with 142 additions and 576 deletions

180
ai/compose.yml Executable file → Normal file
View File

@@ -1,33 +1,63 @@
version: "3.8"
services: services:
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
hermes: hermes:
build: build:
context: ./hermes context: ./hermes
ssh: ssh:
- default - default
container_name: hermes container_name: hermes
# Install Matrix bridge deps (mautrix[encryption]) + openai into the venv at startup.
# Ensures the venv is usable even on first boot with empty persistent volume.
entrypoint: ["/bin/bash", "-c",
"bash /opt/data/hermes-tools/install.sh && \
if [ ! -f /opt/hermes/.venv/bin/python3 ]; then \
uv venv /opt/hermes/.venv --seed && \
. /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir --no-deps -e /opt/hermes && \
uv pip install --no-cache-dir piper-tts sounddevice numpy; \
else \
. /opt/hermes/.venv/bin/activate; \
fi && \
uv pip install openai 'mautrix[encryption]' -q && \
exec /usr/bin/tini -g -- /opt/hermes/docker/entrypoint.sh \"$@\"",
"hermes-entrypoint"]
restart: always restart: always
# Use the image default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"] # Gateway run enables the internal API server on port 8642
# for proper s6-overlay supervision. The CMD runs our multi-profile launcher command: gateway run
# which spawns per-profile gateways in background, then the default gateway
# in foreground (keeps the container alive).
command: ["/usr/local/bin/start-hermes.sh"]
environment: environment:
- HERMES_UID=10000
- HERMES_GID=10000
- OLLAMA_HOST=http://ollama:11434 - OLLAMA_HOST=http://ollama:11434
- HERMES_DASHBOARD=1 - HERMES_DASHBOARD=1
# Multi-profile: comma-separated list of profiles to run as gateways.
# start-hermes.sh reads this and starts one gateway per profile.
# Add profiles here when they exist on disk (e.g. default,researcher,writer)
- HERMES_PROFILES=ashley,claire,finn,matt,paul
- API_SERVER_ENABLED=true - API_SERVER_ENABLED=true
- API_SERVER_PORT=8642 - API_SERVER_PORT=8642
- API_SERVER_HOST=0.0.0.0 - API_SERVER_HOST=0.0.0.0
- API_SERVER_KEY=hermes_local_key - API_SERVER_KEY=hermes_local_key
- GATEWAY_ALLOW_ALL_USERS=true - GATEWAY_ALLOW_ALL_USERS=true
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY} - OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
- OPENCODE_API_KEY=${OPENCODE_API_KEY}
# ROCm for GPU-accelerated faster-whisper STT # ROCm for GPU-accelerated faster-whisper STT
- HSA_OVERRIDE_GFX_VERSION=9.0.6 - HSA_OVERRIDE_GFX_VERSION=9.0.6
- HCC_AMDGPU_TARGET=gfx906 - HCC_AMDGPU_TARGET=gfx906
@@ -37,7 +67,12 @@ services:
- TZ=America/Montreal - TZ=America/Montreal
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data - /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex # Syncthing-shared org files — read-only view of user's agenda
- /mnt/HoardingCow_docker_data/Syncthing/telos-ro:/opt/data/telos-ro:ro
# Syncthing-shared inbox — write tasks here, they sync to user's laptop
- /mnt/HoardingCow_docker_data/Syncthing/telos-rw:/opt/data/telos-rw:rw
# Persist Python venv across container recreation (Matrix bridge deps, etc.)
- /mnt/HoardingCow_docker_data/Hermes/venv:/opt/hermes/.venv
devices: devices:
- /dev/kfd:/dev/kfd - /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri - /dev/dri:/dev/dri
@@ -47,8 +82,6 @@ services:
networks: networks:
- ai_backend - ai_backend
- ai_net - ai_net
depends_on:
- honcho
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=ai_net" - "traefik.docker.network=ai_net"
@@ -84,28 +117,22 @@ services:
- "21027:21027/udp" - "21027:21027/udp"
environment: environment:
- TZ=America/Montreal - TZ=America/Montreal
- PUID=10000
- PGID=10000
volumes: volumes:
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config - /mnt/HoardingCow_docker_data/Syncthing/config:/var/syncthing/config
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex - /mnt/HoardingCow_docker_data/Syncthing/telos-ro:/telos-ro
- /mnt/HoardingCow_docker_data/Syncthing/telos-rw:/telos-rw
networks: networks:
- ai_backend - ai_backend
- ai_net - ai_net
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
- "traefik.docker.network=ai_net"
- "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)" - "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-http.entrypoints=web" - "traefik.http.routers.syncthing-http.entrypoints=web"
- "traefik.http.routers.syncthing-http.middlewares=redirect-to-https" - "traefik.http.routers.syncthing-http.middlewares=redirect-to-https"
- "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)" - "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-https.entrypoints=websecure" - "traefik.http.routers.syncthing-https.entrypoints=websecure"
- "traefik.http.routers.syncthing-https.tls=true" - "traefik.http.routers.syncthing-https.tls=true"
- "traefik.http.routers.syncthing-https.tls.certresolver=njalla" - "traefik.http.routers.syncthing-https.tls.certresolver=njalla"
- "traefik.http.routers.syncthing-https.middlewares=hermes-auth"
- "traefik.http.services.syncthing.loadbalancer.server.port=8384" - "traefik.http.services.syncthing.loadbalancer.server.port=8384"
ollama: ollama:
@@ -141,92 +168,13 @@ services:
- "303" - "303"
- "26" - "26"
# --- Honcho + OpenConcho combiné: API + Web UI nginx/FastAPI ---
honcho:
build:
context: ./honcho
ssh:
- default
container_name: honcho
restart: unless-stopped
environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024
- AUTH_USE_AUTH=true
- AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET}
# Needed by deriver/dream to make LLM calls (api_key_env = "HONCHO_OPENAI_API_KEY" in config.toml)
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY}
volumes:
- /mnt/HoardingCow_docker_data/Honcho/data:/app/data
- /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro
networks:
- ai_backend
- ai_net
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
# Router for HTTP + redirect to HTTPS
- "traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-http.entrypoints=web"
- "traefik.http.routers.honcho-http.middlewares=redirect-to-https"
# Router for HTTPS with TLS — protected by Authelia
- "traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-https.entrypoints=websecure"
- "traefik.http.routers.honcho-https.tls=true"
- "traefik.http.routers.honcho-https.tls.certresolver=njalla"
- "traefik.http.routers.honcho-https.middlewares=hermes-auth"
# Service Loadbalancer (nginx port)
- "traefik.http.services.honcho.loadbalancer.server.port=80"
depends_on:
- honcho-db
- honcho-redis
honcho-db:
image: pgvector/pgvector:pg15
container_name: honcho-db
restart: unless-stopped
ports:
- "127.0.0.1:5432:5432"
command: ["postgres", "-c", "max_connections=200"]
environment:
- POSTGRES_DB=honcho
- POSTGRES_USER=honcho
- POSTGRES_PASSWORD=honcho_pass
- PGDATA=/var/lib/postgresql/data/pgdata
volumes:
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data
- ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro
networks:
- ai_backend
honcho-redis:
image: redis:8
container_name: honcho-redis
restart: unless-stopped
ports:
- "127.0.0.1:6379:6379"
volumes:
- /mnt/HoardingCow_docker_data/Honcho/redis:/data
networks:
- ai_backend
networks: networks:
ai_net: ai_net:
driver: bridge external: true
name: ai_net name: ai_net
ai_backend: ai_backend:
driver: bridge driver: bridge
name: ai_backend name: ai_backend
volumes:
honcho_data:
driver: bridge
name: honcho_data
# llama_cpp_devstral: # llama_cpp_devstral:
# image: ghcr.io/ggml-org/llama.cpp:server-rocm # image: ghcr.io/ggml-org/llama.cpp:server-rocm
@@ -316,30 +264,6 @@ volumes:
# - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface # - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface
# restart: unless-stopped # restart: unless-stopped
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
# n8n: # n8n:
# image: n8nio/n8n:latest # image: n8nio/n8n:latest
# container_name: n8n # container_name: n8n

View File

@@ -9,12 +9,31 @@
# ---------- Base: official Hermes image (system deps, npm, uv, Playwright) ---------- # ---------- Base: official Hermes image (system deps, npm, uv, Playwright) ----------
FROM nousresearch/hermes-agent:latest FROM nousresearch/hermes-agent:latest
# ---------- Overlay our forked source ----------
# Uses SSH agent forwarding from the build host (no key baked into image).
# --exclude node_modules/.venv keeps the base image's pre-built layers intact.
# Only the Python source, web UI source, and config change.
RUN --mount=type=ssh \
mkdir -p /root/.ssh && \
ssh-keyscan -p 2222 code.lazyworkhorse.net >> /root/.ssh/known_hosts 2>/dev/null && \
cd /tmp && \
GIT_SSH_COMMAND='ssh -p 2222 -o StrictHostKeyChecking=no' \
git clone --depth 1 --branch main \
git@code.lazyworkhorse.net:gortium/hermes-agent.git fork && \
rm -rf fork/node_modules fork/.venv fork/.git && \
cp -a fork/. /opt/hermes/ && \
rm -rf /tmp/fork /root/.ssh/
# ---------- Reinstall Python package (editable) ----------
# Picks up source changes from our fork.
RUN . /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir --no-deps -e /opt/hermes
# ---------- Extra system deps ---------- # ---------- Extra system deps ----------
USER root USER root
RUN apt-get update && \ RUN apt-get update && \
apt-get install -y --no-install-recommends \ apt-get install -y --no-install-recommends \
libportaudio2 ca-certificates poppler-utils imagemagick \ libportaudio2 ca-certificates poppler-utils imagemagick \
libolm-dev \
texlive-latex-base texlive-latex-extra texlive-fonts-recommended \ texlive-latex-base texlive-latex-extra texlive-fonts-recommended \
texlive-xetex texlive-science \ texlive-xetex texlive-science \
qemu-user-static binfmt-support emacs-nox && \ qemu-user-static binfmt-support emacs-nox && \
@@ -23,14 +42,6 @@ RUN apt-get update && \
# ---------- UV ---------- # ---------- UV ----------
COPY --chmod=0755 --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/ COPY --chmod=0755 --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/
WORKDIR /opt/hermes
# ---------- Matrix bridge + extra pip deps ----------
# Previously installed inline at container startup and persisted via volume mount.
# Now baked into the image so the fragile venv volume mount can be removed.
RUN . /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir 'mautrix[encryption]' openai
# ---------- Piper TTS ---------- # ---------- Piper TTS ----------
RUN . /opt/hermes/.venv/bin/activate && \ RUN . /opt/hermes/.venv/bin/activate && \
uv pip install --no-cache-dir piper-tts sounddevice numpy && \ uv pip install --no-cache-dir piper-tts sounddevice numpy && \
@@ -58,15 +69,6 @@ os.remove(tgz)
print('himalaya v1.2.0 installed') print('himalaya v1.2.0 installed')
PYEOF PYEOF
# ---------- Install multi-gateway launcher ----------
# Launches one gateway process per profile (HERMES_PROFILES env var)
COPY --chmod=0755 run-multi-gateways.sh /usr/local/bin/run-multi-gateways.sh
# ---------- Install s6-overlay compatible startup script ----------
# Runs as the CMD via s6-overlay's main-program model.
# Replaces the old bash->tini->entrypoint.sh chain that caused SIGTERM crash loops.
COPY --chmod=0755 start-hermes.sh /usr/local/bin/start-hermes.sh
# ---------- Runtime ---------- # ---------- Runtime ----------
USER hermes USER hermes
ENV HERMES_HOME=/opt/data ENV HERMES_HOME=/opt/data
@@ -79,9 +81,4 @@ ENV CHROME_EXECUTABLE=/opt/hermes/.playwright/chromium/chrome-linux/chrome
USER root USER root
RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py
VOLUME [ "/opt/data" ] VOLUME [ "/opt/data" ]
# Switch to the hermes user so the container runs unprivileged.
# All child processes inherit this user — no more orphan root processes
# that escape gosu privilege drops in the entrypoint.
USER hermes

View File

@@ -1,32 +0,0 @@
#!/bin/bash
# Multi-gateway launcher for HERMES_PROFILES env var.
# Reads comma-separated profile names, spawns one gateway per profile.
# Designed to run before the main entrypoint — gateways run in background.
set -e
if [ -z "${HERMES_PROFILES}" ]; then
echo "HERMES_PROFILES not set — skipping multi-gateway launch"
exit 0
fi
# Source venv to make 'hermes' available (entrypoint.sh sources it later,
# but we need it NOW for the background gateways)
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
if [ ! -x "$HERMES_BIN" ]; then
echo "ERROR: hermes binary not found at $HERMES_BIN"
exit 1
fi
mkdir -p /opt/data/logs
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
for profile in "${PROFILES[@]}"; do
profile="$(echo "${profile}" | xargs)" # trim whitespace
[ -z "${profile}" ] && continue
echo "Starting gateway for profile: ${profile}"
nohup env API_SERVER_ENABLED=false API_SERVER_KEY= gosu hermes "$HERMES_BIN" --profile "${profile}" gateway run \
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
done
echo "All gateways launched: ${HERMES_PROFILES}"

View File

@@ -1,38 +0,0 @@
#!/bin/bash
# Multi-profile + default gateway launcher — runs as the CMD via s6-overlay.
#
# The image's default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"]
# starts the s6 supervision tree, then exec's main-wrapper.sh with the CMD args.
# main-wrapper.sh sources the venv, drops to the hermes user via s6-setuidgid,
# and exec's this script.
#
# This script:
# 1. Launches per-profile background gateways (HERMES_PROFILES env var)
# 2. Starts the default gateway in foreground (keeps the container alive)
#
# Replaces the old approach of chaining bash -> tini -g -> deprecated entrypoint.sh
# which bypassed s6-overlay and caused the SIGTERM crash loop.
set -e
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
# --- Multi-profile gateways (background) ---
if [ -n "${HERMES_PROFILES:-}" ]; then
echo "[start-hermes] Launching per-profile gateways: ${HERMES_PROFILES}"
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
for profile in "${PROFILES[@]}"; do
profile="$(echo "${profile}" | xargs)" # trim whitespace
[ -z "${profile}" ] && continue
echo "[start-hermes] -> background gateway for profile '${profile}'"
# No gosu/s6-setuidgid needed — we're already running as the hermes user
# (main-wrapper.sh drops privileges before exec'ing this script).
nohup "${HERMES_BIN}" --profile "${profile}" gateway run \
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
done
echo "[start-hermes] All profile gateways launched"
fi
# --- Default gateway (foreground — keeps container alive) ---
echo "[start-hermes] Starting default gateway (foreground)"
exec "${HERMES_BIN}" gateway run

4
ai/hermes/startup.sh Executable file
View File

@@ -0,0 +1,4 @@
#!/bin/bash
# This file was replaced by inline entrypoint logic in compose.yml
# See ai/compose.yml hermes.entrypoint for the current implementation.
echo "startup.sh is obsolete — logic is inline in compose.yml entrypoint"

View File

@@ -1,75 +0,0 @@
# build stage — fetches and builds Honcho from source
FROM python:3.13-slim-bookworm AS honcho-builder
RUN apt-get update && \
apt-get install -y --no-install-recommends git openssh-client && \
rm -rf /var/lib/apt/lists/*
COPY --from=ghcr.io/astral-sh/uv:0.9.24 /uv /bin/uv
ARG HONCHO_REPO=ssh://git@code.lazyworkhorse.net:2222/Hermes/honcho.git
ARG HONCHO_REF=main
RUN mkdir -p -m 0700 ~/.ssh && ssh-keyscan -p 2222 code.lazyworkhorse.net >> ~/.ssh/known_hosts 2>/dev/null
RUN --mount=type=ssh git clone --depth 1 --branch ${HONCHO_REF} ${HONCHO_REPO} /app
WORKDIR /app
ENV UV_COMPILE_BYTECODE=1
ENV UV_LINK_MODE=copy
ENV UV_PYTHON=/usr/local/bin/python3.13
RUN uv sync --frozen
# build stage — builds OpenConcho SPA
FROM node:22-bookworm AS openconcho-builder
ENV PNPM_HOME=/pnpm
ENV PATH=$PNPM_HOME:$PATH
RUN corepack enable && corepack prepare pnpm@latest --activate
WORKDIR /app
RUN apt-get update && apt-get install -y git && rm -rf /var/lib/apt/lists/*
ARG OPENCONCHO_SHA=3b5c3293fc18d768dbe85285264a8d66c896bd81
RUN --mount=type=ssh git clone --depth 1 ssh://git@code.lazyworkhorse.net:2222/gortium/openconcho.git /app && \
git -C /app fetch --depth 1 origin ${OPENCONCHO_SHA} && \
git -C /app checkout ${OPENCONCHO_SHA}
RUN pnpm install --frozen-lockfile
RUN pnpm --filter @openconcho/web build
# runtime stage — nginx + Honcho FastAPI
FROM python:3.13-slim-bookworm
# Install nginx and create runtime dirs before dropping permissions
RUN apt-get update && apt-get install -y --no-install-recommends nginx && \
rm -rf /var/log/nginx/* && \
rm -rf /var/lib/apt/lists/* && \
rm -f /etc/nginx/sites-enabled/default
# Patch nginx.conf: comment out "user www-data;" so nginx master stays as root
# (workers inherit root inside a container — fine for single-service isolation)
RUN sed -i 's/^user /# user /' /etc/nginx/nginx.conf
# Pre-create nginx runtime directories with proper ownership
RUN mkdir -p /var/lib/nginx/body /var/lib/nginx/proxy /var/lib/nginx/fastcgi \
/var/lib/nginx/uwsgi /var/lib/nginx/scgi /var/lib/nginx/proxy_temp \
/var/cache/nginx && \
chown -R root:root /var/lib/nginx /var/cache/nginx
# Honcho
COPY --from=honcho-builder /app /app
WORKDIR /app
ENV PATH="/app/.venv/bin:$PATH"
ENV HOME=/app
COPY config.toml /app/config.toml
# OpenConcho SPA
COPY --from=openconcho-builder /app/packages/web/dist /usr/share/nginx/html
# nginx config (proxies /v3/, /v2/ to Honcho on localhost:8000)
COPY honcho-nginx.conf /etc/nginx/conf.d/default.conf
EXPOSE 80
CMD ["bash", "-c", "nginx -g 'daemon off;' & fastapi run --host 127.0.0.1 --port 8000 src/main.py & python3 -m src.deriver & wait -n"]

View File

@@ -1,132 +0,0 @@
[app]
LOG_LEVEL = "INFO"
MAX_MESSAGE_SIZE = 25000
EMBED_MESSAGES = true
NAMESPACE = "honcho"
[db]
CONNECTION_URI = "postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho"
SCHEMA = "public"
POOL_SIZE = 10
MAX_OVERFLOW = 20
[auth]
USE_AUTH = false
[sentry]
ENABLED = false
[telemetry]
ENABLED = false
[webhook]
ENABLED = false
[cache]
ENABLED = true
URL = "redis://honcho-redis:6379/0"
[llm]
DEFAULT_MAX_TOKENS = 4096
# Embeddings via Ollama — bge-m3 provides 1024-dim
[embedding]
VECTOR_DIMENSIONS = 1024
MAX_INPUT_TOKENS = 8192
[embedding.model_config]
transport = "openai"
model = "bge-m3"
overrides = {base_url = "http://ollama:11434/v1", api_key = "ollama"}
# --- Deriver ---
[deriver]
ENABLED = true
WORKERS = 1
POLLING_SLEEP_INTERVAL_SECONDS = 5.0
FLUSH_ENABLED = true
[deriver.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
# --- Dialectic ---
[dialectic]
MAX_INPUT_TOKENS = 4096
SESSION_HISTORY_MAX_TOKENS = 8192
[dialectic.levels.minimal]
MAX_TOOL_ITERATIONS = 1
MAX_OUTPUT_TOKENS = 512
[dialectic.levels.minimal.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dialectic.levels.low]
MAX_TOOL_ITERATIONS = 3
[dialectic.levels.low.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dialectic.levels.medium]
MAX_TOOL_ITERATIONS = 2
[dialectic.levels.medium.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dialectic.levels.high]
MAX_TOOL_ITERATIONS = 4
[dialectic.levels.high.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dialectic.levels.max]
MAX_TOOL_ITERATIONS = 10
[dialectic.levels.max.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
# --- Summary ---
[summary]
ENABLED = true
MESSAGES_PER_SHORT_SUMMARY = 20
MESSAGES_PER_LONG_SUMMARY = 60
[summary.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
# --- Dream ---
[dream]
ENABLED = true
[dream.model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dream.deduction_model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
[dream.induction_model_config]
overrides = {base_url = "https://opencode.ai/zen/go/v1", api_key_env = "HONCHO_OPENAI_API_KEY"}
transport = "openai"
model = "deepseek-v4-flash"
# --- Peer Card ---
[peer_card]
ENABLED = true
# --- Vector Store ---
[vector_store]
TYPE = "pgvector"
# DIMENSIONS is deprecated — EMBEDDING.VECTOR_DIMENSIONS is authoritative

View File

@@ -1,52 +0,0 @@
server {
listen 80 default_server;
listen [::]:80 default_server;
server_name _;
root /usr/share/nginx/html;
index index.html;
# Honcho API proxy
location /v3/ {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location /v2/ {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# Honcho health
location /health {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# OpenAPI docs
location /openapi.json {
proxy_pass http://127.0.0.1:8000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# SPA: fallback to index.html for client-side routing
location / {
try_files $uri $uri/ /index.html;
}
}

View File

@@ -1 +0,0 @@
CREATE EXTENSION IF NOT EXISTS vector;

View File

@@ -32,5 +32,5 @@ services:
networks: networks:
auth_net: auth_net:
driver: bridge external: true
name: auth_net name: auth_net

View File

@@ -68,33 +68,33 @@ services:
labels: labels:
- "traefik.enable=false" # Internal only, accessed by restic-browser - "traefik.enable=false" # Internal only, accessed by restic-browser
# restic-browser: restic-browser:
# image: mazzolino/restic-browser:latest image: embergarage/restic-browser:latest
# container_name: restic-browser container_name: restic-browser
# restart: always restart: always
# environment: environment:
# - TZ=America/Montreal - TZ=America/Montreal
# - RESTIC_REPOSITORY=http://restic-server:8080 - RESTIC_REPOSITORY=http://restic-server:8080
# - RESTIC_PASSWORD=${RESTIC_PASSWORD} - RESTIC_PASSWORD=${RESTIC_PASSWORD}
# networks: networks:
# - backup_net - backup_net
# labels: labels:
# - "traefik.enable=true" - "traefik.enable=true"
# # 1. HTTP to HTTPS Redirect # 1. HTTP to HTTPS Redirect
# - "traefik.http.routers.restic-browser-http.rule=Host(`backup.lazyworkhorse.net`)" - "traefik.http.routers.restic-browser-http.rule=Host(`backup.lazyworkhorse.net`)"
# - "traefik.http.routers.restic-browser-http.entrypoints=web" - "traefik.http.routers.restic-browser-http.entrypoints=web"
# - "traefik.http.routers.restic-browser-http.middlewares=redirect-to-https@docker" - "traefik.http.routers.restic-browser-http.middlewares=redirect-to-https@docker"
#
# # 2. HTTPS Configuration # 2. HTTPS Configuration
# - "traefik.http.routers.restic-browser.rule=Host(`backup.lazyworkhorse.net`)" - "traefik.http.routers.restic-browser.rule=Host(`backup.lazyworkhorse.net`)"
# - "traefik.http.routers.restic-browser.entrypoints=websecure" - "traefik.http.routers.restic-browser.entrypoints=websecure"
# - "traefik.http.routers.restic-browser.tls=true" - "traefik.http.routers.restic-browser.tls=true"
# - "traefik.http.routers.restic-browser.tls.certresolver=njalla" - "traefik.http.routers.restic-browser.tls.certresolver=njalla"
#
# # 3. Backend Service Config # 3. Backend Service Config
# - "traefik.http.services.restic-browser.loadbalancer.server.port=8000" - "traefik.http.services.restic-browser.loadbalancer.server.port=8000"
networks: networks:
backup_net: backup_net:
driver: bridge external: true
name: backup_net name: backup_net

View File

@@ -6,7 +6,6 @@ services:
restart: always restart: always
networks: networks:
- cloud_net - cloud_net
- cloud_internal
environment: environment:
- PUID=1000 - PUID=1000
- PGID=1000 - PGID=1000
@@ -52,7 +51,7 @@ services:
container_name: nextcloud_cron container_name: nextcloud_cron
restart: always restart: always
networks: networks:
- cloud_internal - cloud_net
entrypoint: /cron.sh entrypoint: /cron.sh
volumes: volumes:
- /mnt/HoardingCow_docker_data/NextCloud/data:/var/www/html:rw - /mnt/HoardingCow_docker_data/NextCloud/data:/var/www/html:rw
@@ -76,7 +75,7 @@ services:
networks: networks:
cloud_net: cloud_net:
driver: bridge external: true
name: cloud_net name: cloud_net
cloud_internal: cloud_internal:
driver: bridge driver: bridge

View File

@@ -103,7 +103,7 @@ services:
networks: networks:
coms_net: coms_net:
driver: bridge external: true
name: coms_net name: coms_net
coms_backend: coms_backend:
driver: bridge driver: bridge

View File

@@ -37,5 +37,4 @@ services:
networks: networks:
finance_net: finance_net:
driver: bridge external: true
name: finance_net

View File

@@ -12,8 +12,8 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/Home_Assistant:/config:rw - /mnt/HoardingCow_docker_data/Home_Assistant:/config:rw
networks: networks:
- home_net - home_auto_net
- home_backend - home_auto_backend
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
@@ -34,7 +34,7 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/Mosquitto:/mosquitto - /mnt/HoardingCow_docker_data/Mosquitto:/mosquitto
networks: networks:
- home_backend - home_auto_backend
# ports: # ports:
# - 1883:1883 # - 1883:1883
# - 9001:9001 # - 9001:9001
@@ -43,7 +43,7 @@ services:
image: registry.gitlab.com/hydroqc/hydroqc2mqtt:1.3.0 image: registry.gitlab.com/hydroqc/hydroqc2mqtt:1.3.0
restart: always restart: always
networks: networks:
- home_backend - home_auto_backend
environment: environment:
MQTT_USERNAME: hass MQTT_USERNAME: hass
MQTT_PASSWORD: ${MQTT_PASSWORD} MQTT_PASSWORD: ${MQTT_PASSWORD}
@@ -88,9 +88,8 @@ services:
# restart: unless-stopped # restart: unless-stopped
networks: networks:
home_net: home_auto_net:
external: true
home_auto_backend:
driver: bridge driver: bridge
name: home_net name: home_auto_backend
home_backend:
driver: bridge
name: home_backend

View File

@@ -38,5 +38,4 @@ services:
networks: networks:
homepage_net: homepage_net:
driver: bridge external: true
name: homepage_net

View File

@@ -36,9 +36,9 @@ services:
- cloud_net - cloud_net
- coms_net - coms_net
- finance_net - finance_net
- home_net - home_auto_net
- homepage_net - homepage_net
- pass_net - passman_net
- tak_net - tak_net
- vc_net - vc_net
@@ -82,37 +82,37 @@ networks:
driver: bridge driver: bridge
name: traefik_backend name: traefik_backend
ai_net: ai_net:
driver: bridge external: true
name: ai_net name: ai_net
auth_net: auth_net:
driver: bridge external: true
name: auth_net name: auth_net
backup_net: backup_net:
driver: bridge external: true
name: backup_net name: backup_net
cloud_net: cloud_net:
driver: bridge external: true
name: cloud_net name: cloud_net
coms_net: coms_net:
driver: bridge external: true
name: coms_net name: coms_net
finance_net: finance_net:
driver: bridge external: true
name: finance_net name: finance_net
home_net: home_auto_net:
driver: bridge external: true
name: home_net name: home_auto_net
homepage_net: homepage_net:
driver: bridge external: true
name: homepage_net name: homepage_net
pass_net: passman_net:
driver: bridge external: true
name: pass_net name: passman_net
tak_net: tak_net:
driver: bridge external: true
name: tak_net name: tak_net
vc_net: vc_net:
driver: bridge external: true
name: vc_net name: vc_net
# duckdns: # duckdns:

View File

@@ -13,7 +13,7 @@ services:
volumes: volumes:
- /mnt/HoardingCow_docker_data/BitWarden/data:/data:rw - /mnt/HoardingCow_docker_data/BitWarden/data:/data:rw
networks: networks:
- pass_net - passman_net
restart: always restart: always
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
@@ -32,6 +32,5 @@ services:
# Internal service # Internal service
- "traefik.http.services.pass.loadbalancer.server.port=80" - "traefik.http.services.pass.loadbalancer.server.port=80"
networks: networks:
pass_net: passman_net:
driver: bridge external: true
name: pass_net

View File

@@ -92,8 +92,7 @@ services:
networks: networks:
tak_net: tak_net:
driver: bridge external: true
name: tak_net
tak_backend: tak_backend:
driver: bridge driver: bridge
name: tak_backend name: tak_backend

View File

@@ -61,5 +61,4 @@ services:
networks: networks:
vc_net: vc_net:
driver: bridge external: true
name: vc_net

View File

@@ -12,7 +12,7 @@ services:
- SYS_MODULE - SYS_MODULE
environment: environment:
- WG_HOST=vpn.lazyworkhorse.net - WG_HOST=vpn.lazyworkhorse.net
- PASSWORD_HASH=${WG_PASSWORD_HASH} - PASSWORD=${WG_PASSWORD}
- WG_PORT=51820 - WG_PORT=51820
- WG_DEFAULT_ADDRESS=10.8.0.x - WG_DEFAULT_ADDRESS=10.8.0.x
- WG_DEFAULT_DNS=1.1.1.1,8.8.8.8 - WG_DEFAULT_DNS=1.1.1.1,8.8.8.8
@@ -22,6 +22,7 @@ services:
- UI_CHART_TYPE=0 - UI_CHART_TYPE=0
ports: ports:
- "51820:51820/udp" - "51820:51820/udp"
- "51821:51821/tcp"
volumes: volumes:
- /mnt/HoardingCow_docker_data/WireGuard:/etc/wireguard:rw - /mnt/HoardingCow_docker_data/WireGuard:/etc/wireguard:rw
sysctls: sysctls:
@@ -30,31 +31,8 @@ services:
restart: unless-stopped restart: unless-stopped
networks: networks:
- vpn_net - vpn_net
labels:
- "traefik.enable=true"
# HTTP → HTTPS redirect
- "traefik.http.routers.wireguard-http.rule=Host(vpn.lazyworkhorse.net)"
- "traefik.http.routers.wireguard-http.entrypoints=web"
- "traefik.http.routers.wireguard-http.middlewares=redirect-to-https"
- "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https"
# HTTPS router — protégé par Authelia
- "traefik.http.routers.wireguard-https.rule=Host(vpn.lazyworkhorse.net)"
- "traefik.http.routers.wireguard-https.entrypoints=websecure"
- "traefik.http.routers.wireguard-https.tls=true"
- "traefik.http.routers.wireguard-https.tls.certresolver=njalla"
- "traefik.http.routers.wireguard-https.middlewares=wireguard-auth"
# Authelia forwardAuth
- "traefik.http.middlewares.wireguard-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/"
- "traefik.http.middlewares.wireguard-auth.forwardauth.trustforwardheader=true"
- "traefik.http.middlewares.wireguard-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups"
# Port interne du web UI wg-easy
- "traefik.http.services.wireguard.loadbalancer.server.port=51821"
networks: networks:
vpn_net: vpn_net:
driver: bridge external: true
name: vpn_net name: vpn_net