Compare commits
16 Commits
fix/remove
...
merge/drop
| Author | SHA1 | Date | |
|---|---|---|---|
| 0ec0471603 | |||
| 72757b9c3c | |||
| d1ba93fd38 | |||
| 317a5b23af | |||
| 3d90f57e7f | |||
| c1cd9d31e9 | |||
| 5765dc6004 | |||
| e8075fb71b | |||
| 645d519030 | |||
| 146add2a64 | |||
| eb3795d9e3 | |||
| ef6e0e57b6 | |||
| 45a224eb7f | |||
| 46f3b23a3f | |||
| bce336c4fd | |||
| e4117cd3d5 |
@@ -28,11 +28,11 @@ services:
|
||||
hermes:
|
||||
build:
|
||||
context: ./hermes
|
||||
ssh:
|
||||
- default
|
||||
args:
|
||||
HERMES_PLUGIN_URLS: "git+https://code.lazyworkhorse.net/gortium/hermes-piper-plugin.git;git+https://code.lazyworkhorse.net/gortium/hermes-identity-plugin.git"
|
||||
container_name: hermes
|
||||
entrypoint: ["/bin/bash", "-c",
|
||||
"bash /opt/data/hermes-tools/install.sh && bash /opt/data/hermes-tools/run-multi-gateways.sh && exec /usr/bin/tini -g -- /opt/hermes/docker/entrypoint.sh \"$@\"",
|
||||
"bash /opt/data/hermes-tools/install.sh && bash /usr/local/bin/run-multi-gateways.sh && exec /usr/bin/tini -g -- /opt/hermes/docker/entrypoint.sh \"$@\"",
|
||||
"hermes-entrypoint"]
|
||||
restart: always
|
||||
# Gateway run enables the internal API server on port 8642
|
||||
|
||||
@@ -1,33 +1,15 @@
|
||||
# syntax=docker/dockerfile:1
|
||||
# Hermes Agent -- custom fork build
|
||||
# Builds on top of official image + overlays our forked source from Gitea.
|
||||
# Requires Docker BuildKit. Pass SSH agent for git clone:
|
||||
# Hermes Agent -- official image + custom plugins layered on top.
|
||||
# No fork needed — customizations are pip-installable plugins from Gitea.
|
||||
# docker compose build hermes
|
||||
# Or manually:
|
||||
# DOCKER_BUILDKIT=1 docker build --ssh default -t hermes-agent:custom .
|
||||
# DOCKER_BUILDKIT=1 docker build --build-arg HERMES_PLUGIN_URLS="url1 url2" -t hermes-agent:custom .
|
||||
|
||||
# ---------- Base: official Hermes image (system deps, npm, uv, Playwright) ----------
|
||||
FROM nousresearch/hermes-agent:latest
|
||||
|
||||
# ---------- Overlay our forked source ----------
|
||||
# Uses SSH agent forwarding from the build host (no key baked into image).
|
||||
# --exclude node_modules/.venv keeps the base image's pre-built layers intact.
|
||||
# Only the Python source, web UI source, and config change.
|
||||
RUN --mount=type=ssh \
|
||||
mkdir -p /root/.ssh && \
|
||||
ssh-keyscan -p 2222 code.lazyworkhorse.net >> /root/.ssh/known_hosts 2>/dev/null && \
|
||||
cd /tmp && \
|
||||
GIT_SSH_COMMAND='ssh -p 2222 -o StrictHostKeyChecking=no' \
|
||||
git clone --depth 1 --branch main \
|
||||
git@code.lazyworkhorse.net:gortium/hermes-agent.git fork && \
|
||||
rm -rf fork/node_modules fork/.venv fork/.git && \
|
||||
cp -a fork/. /opt/hermes/ && \
|
||||
rm -rf /tmp/fork /root/.ssh/
|
||||
|
||||
# ---------- Reinstall Python package (editable) ----------
|
||||
# Picks up source changes from our fork.
|
||||
RUN . /opt/hermes/.venv/bin/activate && \
|
||||
uv pip install --no-cache-dir --no-deps -e /opt/hermes
|
||||
# ---------- Plugin URLs (semicolon-separated, set via compose.yml build args) ----------
|
||||
ARG HERMES_PLUGIN_URLS=""
|
||||
|
||||
# ---------- Extra system deps ----------
|
||||
USER root
|
||||
@@ -44,8 +26,6 @@ RUN apt-get update && \
|
||||
COPY --chmod=0755 --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/
|
||||
|
||||
# ---------- Matrix bridge + extra pip deps ----------
|
||||
# Previously installed inline at container startup and persisted via volume mount.
|
||||
# Now baked into the image so the fragile venv volume mount can be removed.
|
||||
RUN . /opt/hermes/.venv/bin/activate && \
|
||||
uv pip install --no-cache-dir 'mautrix[encryption]' openai
|
||||
|
||||
@@ -76,6 +56,23 @@ os.remove(tgz)
|
||||
print('himalaya v1.2.0 installed')
|
||||
PYEOF
|
||||
|
||||
# ---------- Install custom plugins from URLs ----------
|
||||
# HERMES_PLUGIN_URLS is a semicolon-separated list of pip-installable
|
||||
# package URLs (e.g. git+https:// or direct .tar.gz archives from Gitea).
|
||||
# Each plugin is installed into the Hermes venv.
|
||||
RUN if [ -n "$HERMES_PLUGIN_URLS" ]; then \
|
||||
. /opt/hermes/.venv/bin/activate && \
|
||||
IFS=';' read -ra URLS <<< "$HERMES_PLUGIN_URLS" && \
|
||||
for url in "${URLS[@]}"; do \
|
||||
echo "Installing plugin: $url" && \
|
||||
uv pip install --no-cache-dir "$url"; \
|
||||
done; \
|
||||
fi
|
||||
|
||||
# ---------- Install multi-gateway launcher ----------
|
||||
# Launches one gateway process per profile (HERMES_PROFILES env var)
|
||||
COPY --chmod=0755 run-multi-gateways.sh /usr/local/bin/run-multi-gateways.sh
|
||||
|
||||
# ---------- Runtime ----------
|
||||
USER hermes
|
||||
ENV HERMES_HOME=/opt/data
|
||||
@@ -88,4 +85,4 @@ ENV CHROME_EXECUTABLE=/opt/hermes/.playwright/chromium/chrome-linux/chrome
|
||||
USER root
|
||||
RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py
|
||||
|
||||
VOLUME [ "/opt/data" ]
|
||||
VOLUME [ "/opt/data" ]
|
||||
|
||||
32
ai/hermes/run-multi-gateways.sh
Executable file
32
ai/hermes/run-multi-gateways.sh
Executable file
@@ -0,0 +1,32 @@
|
||||
#!/bin/bash
|
||||
# Multi-gateway launcher for HERMES_PROFILES env var.
|
||||
# Reads comma-separated profile names, spawns one gateway per profile.
|
||||
# Designed to run before the main entrypoint — gateways run in background.
|
||||
set -e
|
||||
|
||||
if [ -z "${HERMES_PROFILES}" ]; then
|
||||
echo "HERMES_PROFILES not set — skipping multi-gateway launch"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Source venv to make 'hermes' available (entrypoint.sh sources it later,
|
||||
# but we need it NOW for the background gateways)
|
||||
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
|
||||
if [ ! -x "$HERMES_BIN" ]; then
|
||||
echo "ERROR: hermes binary not found at $HERMES_BIN"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
mkdir -p /opt/data/logs
|
||||
|
||||
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
|
||||
for profile in "${PROFILES[@]}"; do
|
||||
profile="$(echo "${profile}" | xargs)" # trim whitespace
|
||||
[ -z "${profile}" ] && continue
|
||||
|
||||
echo "Starting gateway for profile: ${profile}"
|
||||
nohup env API_SERVER_ENABLED=false API_SERVER_KEY= gosu hermes "$HERMES_BIN" --profile "${profile}" gateway run \
|
||||
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
|
||||
done
|
||||
|
||||
echo "All gateways launched: ${HERMES_PROFILES}"
|
||||
@@ -36,6 +36,32 @@ services:
|
||||
# Internal port
|
||||
- "traefik.http.services.homer.loadbalancer.server.port=8080"
|
||||
|
||||
telos:
|
||||
image: nginx:alpine
|
||||
container_name: telos
|
||||
volumes:
|
||||
- /mnt/HoardingCow_docker_data/Telos/site:/usr/share/nginx/html:ro
|
||||
restart: always
|
||||
networks:
|
||||
- homepage_net
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
|
||||
# HTTP → HTTPS redirect
|
||||
- "traefik.http.routers.telos-http.rule=Host(`telos.lazyworkhorse.net`)"
|
||||
- "traefik.http.routers.telos-http.entrypoints=web"
|
||||
- "traefik.http.routers.telos-http.middlewares=redirect-to-https"
|
||||
- "traefik.http.middlewares.redirect-to-https.redirectscheme.scheme=https"
|
||||
|
||||
# HTTPS router
|
||||
- "traefik.http.routers.telos-https.rule=Host(`telos.lazyworkhorse.net`)"
|
||||
- "traefik.http.routers.telos-https.entrypoints=websecure"
|
||||
- "traefik.http.routers.telos-https.tls=true"
|
||||
- "traefik.http.routers.telos-https.tls.certresolver=njalla"
|
||||
|
||||
# Internal port
|
||||
- "traefik.http.services.telos.loadbalancer.server.port=80"
|
||||
|
||||
networks:
|
||||
homepage_net:
|
||||
external: true
|
||||
|
||||
Reference in New Issue
Block a user