Compare commits

..

6 Commits

Author SHA1 Message Date
be9c02389a hermes: add dashboard-cathou to s6 boot bundle (auto-start on recreate)
Some checks are pending
Build Hermes agent / build (pull_request) Waiting to run
Build ollama (gfx906) / build (pull_request) Waiting to run
2026-09-18 17:12:26 -04:00
888523079f hermes: route all dashboard/honcho secrets through age-backed env (no hardcoded values for public repo); add main-dash auth env
Some checks are pending
Build Hermes agent / build (pull_request) Waiting to run
Build ollama (gfx906) / build (pull_request) Waiting to run
2026-09-18 16:23:28 -04:00
5e8d669a2c hermes: add supervised dashboard-cathou service (:9120, own identity). Second s6 service reusing the main dashboard machinery, mounted read-only; env injected in compose. Runs the command directly to dodge the with-contenv env reset that would collapse it to the main service identity. 2026-09-18 16:04:06 -04:00
9b621c0410 honcho: disable app-level auth (blank JWT secret was crash-looping; internal+Authelia-ringfenced)
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
2026-09-16 15:36:43 -04:00
3353c6fba1 hermes: fix vpn_net networks syntax (map form) for compose v5; drop dead build ssh key
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
2026-09-15 17:18:28 -04:00
gortium
d57169ad3d feat: attach hermes to vpn_net at 172.24.0.5 for desktop remote-gateway access 2026-09-15 15:28:51 -04:00
6 changed files with 158 additions and 343 deletions

View File

@@ -1,106 +1,97 @@
services:
hermes:
build:
context: ./hermes
ssh:
- default
container_name: hermes
restart: always
# Gateway run enables the internal API server on port 8642
command: gateway run
environment:
- HERMES_UID=10000
- HERMES_GID=10000
- OLLAMA_HOST=http://ollama-cpu:11434
- HERMES_DASHBOARD=1
- API_SERVER_ENABLED=true
- API_SERVER_PORT=8642
- API_SERVER_HOST=0.0.0.0
- API_SERVER_KEY=hermes_local_key
- GATEWAY_ALLOW_ALL_USERS=true
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
- OPENCODE_API_KEY=${OPENCODE_API_KEY}
# ROCm for GPU-accelerated faster-whisper STT
- HSA_OVERRIDE_GFX_VERSION=9.0.6
- HCC_AMDGPU_TARGET=gfx906
- HIP_VISIBLE_DEVICES=0,1
- ROCR_VISIBLE_DEVICES=0,1
- HSA_ENABLE_SDMA=0
- TZ=America/Montreal
- HERMES_UID=10000
- HERMES_GID=10000
- OLLAMA_HOST=http://ollama-cpu:11434
- HERMES_DASHBOARD=1
- API_SERVER_ENABLED=true
- API_SERVER_PORT=8642
- API_SERVER_HOST=0.0.0.0
- API_SERVER_KEY=hermes_local_key
- GATEWAY_ALLOW_ALL_USERS=true
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
- OPENCODE_API_KEY=${OPENCODE_API_KEY}
- HSA_OVERRIDE_GFX_VERSION=9.0.6
- HCC_AMDGPU_TARGET=gfx906
- HIP_VISIBLE_DEVICES=0,1
- ROCR_VISIBLE_DEVICES=0,1
- HSA_ENABLE_SDMA=0
- TZ=America/Montreal
- CATHOU_SERVE_PASSWORD=${CATHOU_SERVE_PASSWORD:?must be set}
- CATHOU_SERVE_SECRET=${CATHOU_SERVE_SECRET:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_USERNAME=thierry
- HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=${HERMES_DASHBOARD_BASIC_AUTH_PASSWORD:?must be set}
- HERMES_DASHBOARD_BASIC_AUTH_SECRET=${HERMES_DASHBOARD_BASIC_AUTH_SECRET:?must be set}
volumes:
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex
- /mnt/HoardingCow_docker_data/Hermes/data:/opt/data
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/opt/data/ExoKortex
- ./s6/dashboard-cathou:/etc/s6-overlay/s6-rc.d/dashboard-cathou:ro
- ./s6/user/contents.d/dashboard-cathou:/etc/s6-overlay/s6-rc.d/user/contents.d/dashboard-cathou:ro
devices:
- /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri
- /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri
group_add:
- "303"
- "26"
- '303'
- '26'
networks:
- ai_backend
- ai_net
ai_backend: null
ai_net: null
vpn_net:
ipv4_address: 172.24.0.5
depends_on:
- honcho
- honcho
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
# Router for HTTP + redirection to HTTPS
- "traefik.http.routers.hermes-web-http.rule=Host(`hermes.lazyworkhorse.net`)"
- "traefik.http.routers.hermes-web-http.entrypoints=web"
- "traefik.http.routers.hermes-web-http.middlewares=redirect-to-https"
# Router for HTTPS with TLS — protected by Authelia
- "traefik.http.routers.hermes-web-https.rule=Host(`hermes.lazyworkhorse.net`)"
- "traefik.http.routers.hermes-web-https.entrypoints=websecure"
- "traefik.http.routers.hermes-web-https.tls=true"
- "traefik.http.routers.hermes-web-https.tls.certresolver=njalla"
- "traefik.http.routers.hermes-web-https.middlewares=hermes-auth"
# Authelia forwardAuth
- "traefik.http.middlewares.hermes-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/"
- "traefik.http.middlewares.hermes-auth.forwardauth.trustforwardheader=true"
- "traefik.http.middlewares.hermes-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups"
# Service Loadbalancer (dashboard port 9119)
- "traefik.http.services.hermes-web.loadbalancer.server.port=9119"
- traefik.enable=true
- traefik.docker.network=ai_net
- traefik.http.routers.hermes-web-http.rule=Host(`hermes.lazyworkhorse.net`)
- traefik.http.routers.hermes-web-http.entrypoints=web
- traefik.http.routers.hermes-web-http.middlewares=redirect-to-https
- traefik.http.routers.hermes-web-https.rule=Host(`hermes.lazyworkhorse.net`)
- traefik.http.routers.hermes-web-https.entrypoints=websecure
- traefik.http.routers.hermes-web-https.tls=true
- traefik.http.routers.hermes-web-https.tls.certresolver=njalla
- traefik.http.routers.hermes-web-https.middlewares=hermes-auth
- traefik.http.middlewares.hermes-auth.forwardauth.address=http://authelia:9091/api/verify?rd=https://auth.lazyworkhorse.net/
- traefik.http.middlewares.hermes-auth.forwardauth.trustforwardheader=true
- traefik.http.middlewares.hermes-auth.forwardauth.authresponseheaders=X-Forwarded-User,X-Forwarded-Groups
- traefik.http.services.hermes-web.loadbalancer.server.port=9119
syncthing:
image: syncthing/syncthing:latest
container_name: syncthing
hostname: syncthing
restart: always
ports:
- "8384:8384"
- "22000:22000"
- "21027:21027/udp"
- 8384:8384
- 22000:22000
- 21027:21027/udp
environment:
- TZ=America/Montreal
- PUID=10000
- PGID=10000
- TZ=America/Montreal
- PUID=10000
- PGID=10000
volumes:
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/config:/var/syncthing/config
- /mnt/HoardingCow_docker_data/Hermes/Syncthing/ExoKortex:/ExoKortex
networks:
- ai_backend
- ai_net
- ai_backend
- ai_net
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
- "traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-http.entrypoints=web"
- "traefik.http.routers.syncthing-http.middlewares=redirect-to-https"
- "traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)"
- "traefik.http.routers.syncthing-https.entrypoints=websecure"
- "traefik.http.routers.syncthing-https.tls=true"
- "traefik.http.routers.syncthing-https.tls.certresolver=njalla"
- "traefik.http.routers.syncthing-https.middlewares=hermes-auth"
- "traefik.http.services.syncthing.loadbalancer.server.port=8384"
- traefik.enable=true
- traefik.docker.network=ai_net
- traefik.http.routers.syncthing-http.rule=Host(`syncthing.lazyworkhorse.net`)
- traefik.http.routers.syncthing-http.entrypoints=web
- traefik.http.routers.syncthing-http.middlewares=redirect-to-https
- traefik.http.routers.syncthing-https.rule=Host(`syncthing.lazyworkhorse.net`)
- traefik.http.routers.syncthing-https.entrypoints=websecure
- traefik.http.routers.syncthing-https.tls=true
- traefik.http.routers.syncthing-https.tls.certresolver=njalla
- traefik.http.routers.syncthing-https.middlewares=hermes-auth
- traefik.http.services.syncthing.loadbalancer.server.port=8384
ollama-cpu:
build:
context: ./ollama
@@ -108,126 +99,110 @@ services:
image: ollama/ollama:rocm-gfx906
container_name: ollama-cpu
tty: true
restart: always
restart: always
ports:
- "127.0.0.1:11434:11434"
- 127.0.0.1:11434:11434
networks:
- ai_backend
- ai_backend
volumes:
- /mnt/HoardingCow_docker_data/Ollama/ollama:/root/.ollama
- /mnt/HoardingCow_docker_data/Ollama/ollama:/root/.ollama
environment:
- OLLAMA_VULKAN=0
- OLLAMA_HOST=0.0.0.0
- OLLAMA_VULKAN=0
- OLLAMA_HOST=0.0.0.0
llama-cpp-hermes:
image: llama-cpp:rocm-gfx906
container_name: llama-cpp-hermes
restart: unless-stopped
networks:
- ai_backend
- ai_backend
ports:
- "127.0.0.1:8300:8080"
- 127.0.0.1:8300:8080
ipc: host
devices:
- /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri
- /dev/kfd:/dev/kfd
- /dev/dri:/dev/dri
group_add:
- "303"
- "26"
- '303'
- '26'
environment:
- HSA_OVERRIDE_GFX_VERSION=9.0.6
- HSA_ENABLE_SDMA=0
- HIP_VISIBLE_DEVICES=0,1
- LLAMA_CACHE=/models
- HSA_OVERRIDE_GFX_VERSION=9.0.6
- HSA_ENABLE_SDMA=0
- HIP_VISIBLE_DEVICES=0,1
- LLAMA_CACHE=/models
volumes:
- /mnt/HoardingCow_docker_data/Llama_cpp/models:/models
- /mnt/HoardingCow_docker_data/Ollama/ollama/models/blobs/sha256-17823599694fa3503ef54bf748d5078c6ce881f4d01616cafa255dc05d215a08:/model.gguf:ro
command: >
-m /model.gguf
--host 0.0.0.0
--port 8080
--gpu-layers 99
--ctx-size 163840
-ctk f16 -ctv f16
--flash-attn on
--split-mode layer
--no-mmap
--n-predict -1
- /mnt/HoardingCow_docker_data/Llama_cpp/models:/models
- /mnt/HoardingCow_docker_data/Ollama/ollama/models/blobs/sha256-17823599694fa3503ef54bf748d5078c6ce881f4d01616cafa255dc05d215a08:/model.gguf:ro
command: '-m /model.gguf --host 0.0.0.0 --port 8080 --gpu-layers 99 --ctx-size
163840 -ctk f16 -ctv f16 --flash-attn on --split-mode layer --no-mmap --n-predict
-1
# --- Honcho + OpenConcho combiné: API + Web UI nginx/FastAPI ---
'
honcho:
build:
context: ./honcho
ssh:
- default
- default
container_name: honcho
restart: unless-stopped
environment:
- DB_CONNECTION_URI=postgresql+psycopg://honcho:honcho_pass@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024
- AUTH_USE_AUTH=true
- AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET}
# Needed by deriver/dream to make LLM calls (api_key_env = "HONCHO_OPENAI_API_KEY" in config.toml)
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY}
- DB_CONNECTION_URI=postgresql+psycopg://honcho:${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}@honcho-db:5432/honcho
- CACHE_URL=redis://honcho-redis:6379/0
- CACHE_ENABLED=true
- EMBEDDING_VECTOR_DIMENSIONS=1024
- AUTH_USE_AUTH=false
- AUTH_JWT_SECRET=${HONCHO_AUTH_JWT_SECRET}
- HONCHO_OPENAI_API_KEY=${HONCHO_OPENAI_API_KEY}
volumes:
- /mnt/HoardingCow_docker_data/Honcho/data:/app/data
- /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro
- /mnt/HoardingCow_docker_data/Honcho/data:/app/data
- /mnt/HoardingCow_docker_data/Honcho/config.toml:/app/config.toml:ro
networks:
- ai_backend
- ai_net
- ai_backend
- ai_net
labels:
- "traefik.enable=true"
- "traefik.docker.network=ai_net"
# Router for HTTP + redirect to HTTPS
- "traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-http.entrypoints=web"
- "traefik.http.routers.honcho-http.middlewares=redirect-to-https"
# Router for HTTPS with TLS — protected by Authelia
- "traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`)"
- "traefik.http.routers.honcho-https.entrypoints=websecure"
- "traefik.http.routers.honcho-https.tls=true"
- "traefik.http.routers.honcho-https.tls.certresolver=njalla"
- "traefik.http.routers.honcho-https.middlewares=hermes-auth"
# Service Loadbalancer (nginx port)
- "traefik.http.services.honcho.loadbalancer.server.port=80"
- traefik.enable=true
- traefik.docker.network=ai_net
- traefik.http.routers.honcho-http.rule=Host(`honcho.lazyworkhorse.net`)
- traefik.http.routers.honcho-http.entrypoints=web
- traefik.http.routers.honcho-http.middlewares=redirect-to-https
- traefik.http.routers.honcho-https.rule=Host(`honcho.lazyworkhorse.net`)
- traefik.http.routers.honcho-https.entrypoints=websecure
- traefik.http.routers.honcho-https.tls=true
- traefik.http.routers.honcho-https.tls.certresolver=njalla
- traefik.http.routers.honcho-https.middlewares=hermes-auth
- traefik.http.services.honcho.loadbalancer.server.port=80
depends_on:
- honcho-db
- honcho-redis
- honcho-db
- honcho-redis
honcho-db:
image: pgvector/pgvector:pg15
container_name: honcho-db
restart: unless-stopped
ports:
- "127.0.0.1:5432:5432"
command: ["postgres", "-c", "max_connections=200"]
- 127.0.0.1:5432:5432
command:
- postgres
- -c
- max_connections=200
environment:
- POSTGRES_DB=honcho
- POSTGRES_USER=honcho
- POSTGRES_PASSWORD=honcho_pass
- PGDATA=/var/lib/postgresql/data/pgdata
- POSTGRES_DB=honcho
- POSTGRES_USER=honcho
- POSTGRES_PASSWORD=${HONCHO_DB_PASSWORD:?HONCHO_DB_PASSWORD must be set}
- PGDATA=/var/lib/postgresql/data/pgdata
volumes:
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data
- ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro
- /mnt/HoardingCow_docker_data/Honcho/postgres:/var/lib/postgresql/data
- ./honcho/init-db.sql:/docker-entrypoint-initdb.d/init.sql:ro
networks:
- ai_backend
- ai_backend
honcho-redis:
image: redis:8
container_name: honcho-redis
restart: unless-stopped
ports:
- "127.0.0.1:6379:6379"
- 127.0.0.1:6379:6379
volumes:
- /mnt/HoardingCow_docker_data/Honcho/redis:/data
- /mnt/HoardingCow_docker_data/Honcho/redis:/data
networks:
- ai_backend
- ai_backend
networks:
ai_net:
driver: bridge
@@ -235,193 +210,10 @@ networks:
ai_backend:
driver: bridge
name: ai_backend
vpn_net:
external: true
name: vpn_net
volumes:
honcho_data:
driver: bridge
name: honcho_data
# vllm:
# image: nalanzeyu/vllm-gfx906:v0.9.0-rocm6.3
# container_name: vllm
# # Required for multi-GPU communication (NCCL)
# ipc: host
# init: true
# shm_size: '2g'
# networks:
# - ai_backend
# ports:
# - "8300:8000"
# devices:
# - "/dev/kfd:/dev/kfd"
# - "/dev/dri:/dev/dri"
# group_add:
# - "303"
# - "26"
# environment:
# HSA_OVERRIDE_GFX_VERSION: 9.0.6
# HSA_ENABLE_SDMA: 0
# HIP_VISIBLE_DEVICES: 0,1
# NCCL_P2P_DISABLE: 1
# VLLM_WORKER_MULTIPROC_METHOD: spawn
# VLLM_USE_TRITON_FLASH_ATTN: 0
# VLLM_USE_ROCM_CUSTOM_PAGED_ATTN: 0
# VLLM_ATTENTION_BACKEND: ROPE_NAIVE
# VLLM_SKIP_WARMUP: 1
# VLLM_USE_V1: 0
# HF_TOKEN: ${HF_TOKEN}
# command: >
# vllm serve "mistralai/Devstral-Small-2-24B-Instruct-2512"
# --tensor-parallel-size 2
# --max-model-len 8192
# --gpu-memory-utilization 0.90
# --tokenizer_mode mistral
# --config_format auto
# --load-format auto
# --enforce-eager
# --disable-custom-all-reduce
# --trust-remote-code
# --task generate
# --block-size 16
# volumes:
# - /mnt/HoardingCow_docker_data/vllm/models:/root/.cache/huggingface
# restart: unless-stopped
# webui:
# image: ghcr.io/open-webui/open-webui:main
# volumes:
# - /mnt/HoardingCow_docker_data/Ollama/open-webui:/app/backend/data
# restart: always
# environment:
# - OLLAMA_API_BASE_URL=http://ollama:11434/api
# networks:
# - ai_net
# - ai_backend
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.webui-http.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-http.entrypoints=web"
# - "traefik.http.routers.webui-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.webui-https.rule=Host(`ai.lazyworkhorse.net`)"
# - "traefik.http.routers.webui-https.entrypoints=websecure"
# - "traefik.http.routers.webui-https.tls=true"
# - "traefik.http.routers.webui-https.tls.certresolver=njalla"
# n8n:
# image: n8nio/n8n:latest
# container_name: n8n
# restart: unless-stopped
# networks:
# - ai_net
# environment:
# - N8N_HOST=n8n.lazyworkhorse.net
# - N8N_PORT=5678
# - N8N_PROTOCOL=https
# - NODE_ENV=production
# - N8N_ENCRYPTION_KEY=${N8N_ENCRYPTION_KEY}
# - WEBHOOK_URL=https://n8n.lazyworkhorse.net/
# - GENERIC_TIMEZONE=America/New_York # Adjust to your timezone
# - N8N_BLOCK_EXTERNAL_STORAGE_ACCESS=false
# - N8N_NODES_PYTHON_CAN_IMPORT_MODULES=true
# - N8N_NATIVE_PYTHON_RUNNER=true
# - N8N_PYTHON_ALLOW_STDLIB=uuid,re,os,json
# - N8N_PYTHON_ALLOW_EXTERNAL=requests,pandas
# - NODE_FUNCTION_ALLOW_EXTERNAL=uuid,requests
# volumes:
# - /mnt/HoardingCow_docker_data/n8n:/home/node/.n8n
# labels:
# - "traefik.enable=true"
# # Router for HTTP + redirection to HTTPS
# - "traefik.http.routers.n8n-http.rule=Host(`n8n.lazyworkhorse.net`)"
# - "traefik.http.routers.n8n-http.entrypoints=web"
# - "traefik.http.routers.n8n-http.middlewares=redirect-to-https"
# # Router for HTTPS with TLS
# - "traefik.http.routers.n8n-https.rule=Host(`n8n.lazyworkhorse.net`)"
# - "traefik.http.routers.n8n-https.entrypoints=websecure"
# - "traefik.http.routers.n8n-https.tls=true"
# - "traefik.http.routers.n8n-https.tls.certresolver=njalla"
# # Service Loadbalancer (n8n default port)
# - "traefik.http.services.n8n.loadbalancer.server.port=5678"
# openclaw:
# image: coollabsio/openclaw:latest
# container_name: openclaw
# restart: unless-stopped
# expose:
# - "8080" # WebUI
# - "18789" # Gateway/WebSocket
# - "8788" # Nextcloud Webhook
# networks:
# - ai_net
# - ai_backend
# volumes:
# - /mnt/HoardingCow_docker_data/openclaw/data:/data
# - /home/gortium/infra:/data/workspace/infra
# environment:
# - TZ=America/Toronto
# - OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN}
# - OPENROUTER_API_KEY=${OPENROUTER_API_KEY}
# # Point to the sidecar browser
# - BROWSER_CDP_URL=http://openclaw-browser:9222
# - BROWSER_EVALUATE_ENABLED=true
# - OPENCLAW_GATEWAY_HOST=0.0.0.0
# - OPENCLAW_ALLOWED_ORIGINS=https://claw.lazyworkhorse.net
# labels:
# - "traefik.enable=true"
# - "traefik.http.routers.openclaw-http.rule=Host(`claw.lazyworkhorse.net`)"
# - "traefik.http.routers.openclaw-http.entrypoints=web"
# - "traefik.http.routers.openclaw-http.middlewares=redirect-to-https"
# - "traefik.http.routers.openclaw-https.rule=Host(`claw.lazyworkhorse.net`)"
# - "traefik.http.routers.openclaw-https.priority=50"
# - "traefik.http.routers.openclaw-https.entrypoints=websecure"
# - "traefik.http.routers.openclaw-https.tls=true"
# - "traefik.http.routers.openclaw-https.tls.certresolver=njalla"
# - "traefik.http.services.openclaw.loadbalancer.server.port=8080"
# depends_on:
# - openclaw-browser
# openclaw-browser:
# image: ghcr.io/browserless/chromium:latest
# restart: always
# expose:
# - "3000"
# environment:
# - MAX_CONCURRENT_SESSIONS=10
# - CONNECTION_TIMEOUT=300000
# - PREBOOT_CHROME=true
# - DEMO_MODE=false
# networks:
# ai_backend:
# aliases:
# - browser
# openclaw-ssh:
# image: linuxserver/openssh-server:latest
# container_name: openclaw-ssh
# environment:
# - PUID=1000
# - PGID=1000
# - PUBLIC_KEY_FILE=/config/ssh/authorized_keys
# - SUDO_ACCESS=false
# - PASSWORD_ACCESS=false
# volumes:
# - /mnt/HoardingCow_docker_data/openclaw/ssh-config:/config
# - /home/gortium/infra:/data/workspace/infra:ro
# restart: unless-stopped
# networks:
# - ai_backend
# labels:
# - "traefik.enable=true"
# - "traefik.tcp.routers.openclaw-ssh.rule=HostSNI(*)"
# - "traefik.tcp.routers.openclaw-ssh.entrypoints=sshnode"
# - "traefik.tcp.routers.openclaw-ssh.tls.passthrough=false"
# - "traefik.tcp.services.openclaw-ssh.loadbalancer.server.port=2222"

View File

@@ -0,0 +1 @@
base

View File

@@ -0,0 +1,4 @@
#!/command/with-contenv sh
# Always restart on exit (exit != 125). Crash-loop with a bad auth
# config is the intended fail-closed signal.
exit 0

View File

@@ -0,0 +1,17 @@
#!/command/with-contenv sh
# Personal dashboard serve (:9120) for cathou — same machinery as the
# main dashboard service, but runs the command directly so its OWN
# with-contenv shebang can't wipe our env (a second with-contenv reset
# would drop the port + auth variables). Supervised by s6: restarts on crash.
export HERMES_DASHBOARD_PORT=9120
export HERMES_DASHBOARD_BASIC_AUTH_USERNAME=cathou
export HERMES_DASHBOARD_BASIC_AUTH_PASSWORD="${CATHOU_SERVE_PASSWORD:-}"
export HERMES_DASHBOARD_BASIC_AUTH_SECRET="${CATHOU_SERVE_SECRET:-}"
export HOME=/opt/data
cd /opt/data
# shellcheck disable=SC1091
. /opt/hermes/.venv/bin/activate
# Fail-closed: missing password => provider won't register => serve fails
# => s6 crash-loop surfaces it, never a silent unauthenticated bind.
[ "$(id -u)" = 0 ] || exec hermes dashboard --host 0.0.0.0 --port 9120 --no-open
exec s6-setuidgid hermes hermes dashboard --host 0.0.0.0 --port 9120 --no-open

View File

@@ -0,0 +1 @@
longrun

View File