# Dashboard Systemd Service — Hermes WebUI Hybrid Deployment ## Full Unit File Template Location: `/etc/systemd/system/hermes-dashboard.service` ```ini [Unit] Description=Hermes Agent Dashboard - Web Management UI After=network-online.target hermes-gateway.service Wants=network-online.target StartLimitIntervalSec=0 [Service] Type=simple User=estorozhenko Group=estorozhenko ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1 WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent Environment="HOME=/home/estorozhenko" Environment="USER=estorozhenko" Environment="LOGNAME=estorozhenko" Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv" Environment="HERMES_HOME=/home/estorozhenko/.hermes" Environment="GATEWAY_HEALTH_URL=http://localhost:8642" Restart=always RestartSec=5 RestartMaxDelaySec=300 RestartSteps=5 KillMode=mixed KillSignal=SIGTERM TimeoutStopSec=30 StandardOutput=journal StandardError=journal [Install] WantedBy=multi-user.target ``` ## Pitfalls - **`--host 0.0.0.0` blocked** — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message: ``` Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds, but no auth providers are registered. Configure an auth provider before exposing the dashboard: • Password: set dashboard.basic_auth.username + password_hash in config.yaml • OAuth: run `hermes dashboard register` (Nous Portal) There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1 and tunnel in (SSH / Tailscale). ``` - **Solution:** bind `127.0.0.1` and access via SSH tunnel: ```bash ssh -L 9119:localhost:9119 user@bigbox # from client machine ``` Or via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead. - **No need for `--insecure` flag** — it's deprecated and ignored as of June 2026.