Files
hermes-webui-docker/references/dashboard-systemd-service.md
T
2026-09-06 13:50:57 +00:00

2.2 KiB

Dashboard Systemd Service — Hermes WebUI Hybrid Deployment

Full Unit File Template

Location: /etc/systemd/system/hermes-dashboard.service

[Unit]
Description=Hermes Agent Dashboard - Web Management UI
After=network-online.target hermes-gateway.service
Wants=network-online.target
StartLimitIntervalSec=0

[Service]
Type=simple
User=estorozhenko
Group=estorozhenko
ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1
WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent
Environment="HOME=/home/estorozhenko"
Environment="USER=estorozhenko"
Environment="LOGNAME=estorozhenko"
Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv"
Environment="HERMES_HOME=/home/estorozhenko/.hermes"
Environment="GATEWAY_HEALTH_URL=http://localhost:8642"
Restart=always
RestartSec=5
RestartMaxDelaySec=300
RestartSteps=5
KillMode=mixed
KillSignal=SIGTERM
TimeoutStopSec=30
StandardOutput=journal
StandardError=journal

[Install]
WantedBy=multi-user.target

Pitfalls

  • --host 0.0.0.0 blocked — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message:

    Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds,
    but no auth providers are registered.
    Configure an auth provider before exposing the dashboard:
      • Password: set dashboard.basic_auth.username + password_hash in config.yaml
      • OAuth: run `hermes dashboard register` (Nous Portal)
    There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1
    and tunnel in (SSH / Tailscale).
    
  • Solution: bind 127.0.0.1 and access via SSH tunnel:

    ssh -L 9119:localhost:9119 user@bigbox  # from client machine
    

    Or via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead.

  • No need for --insecure flag — it's deprecated and ignored as of June 2026.