f0e21d95e4b9734be0101b0dd68f8a0d906f1603
Remove infra repo bind mount and sudo access from ai-worker user. Now ai-worker can only: - SSH into host from Hermes container - Run docker commands via docker group membership - Execute ollama benchmarks via docker exec Results saved to /opt/data/ai-optimizer/ in Hermes container.
Description
My whole infra configuration
Languages
Nix
91.8%
Dockerfile
8.2%