mirror of
https://gitverse.ru/kpa39l/hermes-webui-docker.git
synced 2026-09-29 09:15:10 +00:00
2.2 KiB
2.2 KiB
Dashboard Systemd Service — Hermes WebUI Hybrid Deployment
Full Unit File Template
Location: /etc/systemd/system/hermes-dashboard.service
[Unit]
Description=Hermes Agent Dashboard - Web Management UI
After=network-online.target hermes-gateway.service
Wants=network-online.target
StartLimitIntervalSec=0
[Service]
Type=simple
User=estorozhenko
Group=estorozhenko
ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1
WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent
Environment="HOME=/home/estorozhenko"
Environment="USER=estorozhenko"
Environment="LOGNAME=estorozhenko"
Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv"
Environment="HERMES_HOME=/home/estorozhenko/.hermes"
Environment="GATEWAY_HEALTH_URL=http://localhost:8642"
Restart=always
RestartSec=5
RestartMaxDelaySec=300
RestartSteps=5
KillMode=mixed
KillSignal=SIGTERM
TimeoutStopSec=30
StandardOutput=journal
StandardError=journal
[Install]
WantedBy=multi-user.target
Pitfalls
-
--host 0.0.0.0blocked — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message:Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds, but no auth providers are registered. Configure an auth provider before exposing the dashboard: • Password: set dashboard.basic_auth.username + password_hash in config.yaml • OAuth: run `hermes dashboard register` (Nous Portal) There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1 and tunnel in (SSH / Tailscale). -
Solution: bind
127.0.0.1and access via SSH tunnel:ssh -L 9119:localhost:9119 user@bigbox # from client machineOr via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead.
-
No need for
--insecureflag — it's deprecated and ignored as of June 2026.