mirror of
https://gitverse.ru/kpa39l/hermes-webui-docker.git
synced 2026-09-29 09:15:10 +00:00
60 lines
2.2 KiB
Markdown
60 lines
2.2 KiB
Markdown
# Dashboard Systemd Service — Hermes WebUI Hybrid Deployment
|
|
|
|
## Full Unit File Template
|
|
|
|
Location: `/etc/systemd/system/hermes-dashboard.service`
|
|
|
|
```ini
|
|
[Unit]
|
|
Description=Hermes Agent Dashboard - Web Management UI
|
|
After=network-online.target hermes-gateway.service
|
|
Wants=network-online.target
|
|
StartLimitIntervalSec=0
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=estorozhenko
|
|
Group=estorozhenko
|
|
ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1
|
|
WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent
|
|
Environment="HOME=/home/estorozhenko"
|
|
Environment="USER=estorozhenko"
|
|
Environment="LOGNAME=estorozhenko"
|
|
Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
|
|
Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv"
|
|
Environment="HERMES_HOME=/home/estorozhenko/.hermes"
|
|
Environment="GATEWAY_HEALTH_URL=http://localhost:8642"
|
|
Restart=always
|
|
RestartSec=5
|
|
RestartMaxDelaySec=300
|
|
RestartSteps=5
|
|
KillMode=mixed
|
|
KillSignal=SIGTERM
|
|
TimeoutStopSec=30
|
|
StandardOutput=journal
|
|
StandardError=journal
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
```
|
|
|
|
## Pitfalls
|
|
|
|
- **`--host 0.0.0.0` blocked** — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message:
|
|
```
|
|
Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds,
|
|
but no auth providers are registered.
|
|
Configure an auth provider before exposing the dashboard:
|
|
• Password: set dashboard.basic_auth.username + password_hash in config.yaml
|
|
• OAuth: run `hermes dashboard register` (Nous Portal)
|
|
There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1
|
|
and tunnel in (SSH / Tailscale).
|
|
```
|
|
|
|
- **Solution:** bind `127.0.0.1` and access via SSH tunnel:
|
|
```bash
|
|
ssh -L 9119:localhost:9119 user@bigbox # from client machine
|
|
```
|
|
Or via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead.
|
|
|
|
- **No need for `--insecure` flag** — it's deprecated and ignored as of June 2026. |