mirror of
https://gitverse.ru/kpa39l/hermes-webui-docker.git
synced 2026-09-29 09:15:10 +00:00
Initial commit: Hermes skill hermes-webui-docker
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
# Dashboard Systemd Service — Hermes WebUI Hybrid Deployment
|
||||
|
||||
## Full Unit File Template
|
||||
|
||||
Location: `/etc/systemd/system/hermes-dashboard.service`
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
Description=Hermes Agent Dashboard - Web Management UI
|
||||
After=network-online.target hermes-gateway.service
|
||||
Wants=network-online.target
|
||||
StartLimitIntervalSec=0
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=estorozhenko
|
||||
Group=estorozhenko
|
||||
ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1
|
||||
WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent
|
||||
Environment="HOME=/home/estorozhenko"
|
||||
Environment="USER=estorozhenko"
|
||||
Environment="LOGNAME=estorozhenko"
|
||||
Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
||||
Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv"
|
||||
Environment="HERMES_HOME=/home/estorozhenko/.hermes"
|
||||
Environment="GATEWAY_HEALTH_URL=http://localhost:8642"
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
RestartMaxDelaySec=300
|
||||
RestartSteps=5
|
||||
KillMode=mixed
|
||||
KillSignal=SIGTERM
|
||||
TimeoutStopSec=30
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
## Pitfalls
|
||||
|
||||
- **`--host 0.0.0.0` blocked** — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message:
|
||||
```
|
||||
Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds,
|
||||
but no auth providers are registered.
|
||||
Configure an auth provider before exposing the dashboard:
|
||||
• Password: set dashboard.basic_auth.username + password_hash in config.yaml
|
||||
• OAuth: run `hermes dashboard register` (Nous Portal)
|
||||
There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1
|
||||
and tunnel in (SSH / Tailscale).
|
||||
```
|
||||
|
||||
- **Solution:** bind `127.0.0.1` and access via SSH tunnel:
|
||||
```bash
|
||||
ssh -L 9119:localhost:9119 user@bigbox # from client machine
|
||||
```
|
||||
Or via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead.
|
||||
|
||||
- **No need for `--insecure` flag** — it's deprecated and ignored as of June 2026.
|
||||
Reference in New Issue
Block a user