Files
hermes-webui-docker/references/dashboard-systemd-service.md
T
2026-09-06 13:50:57 +00:00

60 lines
2.2 KiB
Markdown

# Dashboard Systemd Service — Hermes WebUI Hybrid Deployment
## Full Unit File Template
Location: `/etc/systemd/system/hermes-dashboard.service`
```ini
[Unit]
Description=Hermes Agent Dashboard - Web Management UI
After=network-online.target hermes-gateway.service
Wants=network-online.target
StartLimitIntervalSec=0
[Service]
Type=simple
User=estorozhenko
Group=estorozhenko
ExecStart=/home/estorozhenko/.hermes/hermes-agent/venv/bin/python -m hermes_cli.main dashboard --host 127.0.0.1
WorkingDirectory=/home/estorozhenko/.hermes/hermes-agent
Environment="HOME=/home/estorozhenko"
Environment="USER=estorozhenko"
Environment="LOGNAME=estorozhenko"
Environment="PATH=/home/estorozhenko/.hermes/hermes-agent/venv/bin:/home/estorozhenko/.hermes/hermes-agent/node_modules/.bin:/home/estorozhenko/.local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
Environment="VIRTUAL_ENV=/home/estorozhenko/.hermes/hermes-agent/venv"
Environment="HERMES_HOME=/home/estorozhenko/.hermes"
Environment="GATEWAY_HEALTH_URL=http://localhost:8642"
Restart=always
RestartSec=5
RestartMaxDelaySec=300
RestartSteps=5
KillMode=mixed
KillSignal=SIGTERM
TimeoutStopSec=30
StandardOutput=journal
StandardError=journal
[Install]
WantedBy=multi-user.target
```
## Pitfalls
- **`--host 0.0.0.0` blocked** — as of June 2026 hardening, Hermes dashboard refuses to bind on a non-loopback interface without a configured auth provider. Error message:
```
Refusing to bind dashboard to 0.0.0.0 — the auth gate engages on non-loopback binds,
but no auth providers are registered.
Configure an auth provider before exposing the dashboard:
• Password: set dashboard.basic_auth.username + password_hash in config.yaml
• OAuth: run `hermes dashboard register` (Nous Portal)
There is no unauthenticated public-bind option — to keep it local, bind 127.0.0.1
and tunnel in (SSH / Tailscale).
```
- **Solution:** bind `127.0.0.1` and access via SSH tunnel:
```bash
ssh -L 9119:localhost:9119 user@bigbox # from client machine
```
Or via WireGuard: if the client IP can reach the host's loopback is impossible — bind on the WireGuard interface IP instead.
- **No need for `--insecure` flag** — it's deprecated and ignored as of June 2026.