Compare commits

...
Author SHA1 Message Date
william f4f785e0bb Re-add the claude-subscription LiteLLM route — confirmed working for the real CLI
Earlier this session I removed this route after a curl-based test got
rejected by Anthropic and concluded OAuth subscription forwarding doesn't
work through a proxy at all. That conclusion was wrong: the real `claude`
CLI binary, with ANTHROPIC_BASE_URL pointed at litellm, successfully
completed a request billed against the subscription. The earlier curl test
just didn't replicate whatever header/fingerprint Anthropic requires from
genuine Claude Code CLI traffic — LiteLLM relays that fine when the real
CLI is the caller, but a hand-built request from any other client (Hermes
included) still gets rejected the same way curl did.
2026-08-23 16:08:26 +00:00
william c88fdcc2ea Merge pull request 'Fix Hermes: gateway command + disable network-reachable API server' (#11) from fix/hermes-gateway-command-and-api-server into main
Reviewed-on: #11
2026-08-23 15:52:35 +00:00
william 98762e764a Fix Hermes container: add gateway command, disable network-reachable API server
Without an explicit command the image launches the interactive CLI by
default, which immediately exits with 'Input is not a terminal' in a
detached container — it was doing nothing on every restart. Also disables
API_SERVER_ENABLED: Hermes itself warns at startup that a network-reachable
API server combined with the default unsandboxed 'local' terminal backend
gives any caller on the network full terminal/file access. Not needed yet
(Matrix is the actual interface) — can re-enable properly (with a sandboxed
terminal backend) if claude-agent ever needs to call Hermes programmatically.
2026-08-23 15:52:08 +00:00
william 5507192ee6 Merge pull request 'Add Hermes Agent as a second native Matrix presence' (#10) from feat/hermes-matrix into main
build-agent / build-and-push (push) Successful in 11s
Reviewed-on: #10
2026-08-23 15:49:05 +00:00
2 changed files with 23 additions and 12 deletions
+10 -5
View File
@@ -78,15 +78,20 @@ services:
MATRIX_ALLOWED_USERS: ${MATRIX_HUMAN_USER_ID}
MATRIX_REQUIRE_MENTION: "true"
OPENROUTER_API_KEY: ${OPENROUTER_API_KEY}
# Exposed on the internal network only (see claude-agent's LITELLM_BASE_URL-style
# usage pattern) — nothing publishes this port externally.
API_SERVER_ENABLED: "true"
API_SERVER_HOST: 0.0.0.0
API_SERVER_KEY: ${HERMES_API_SERVER_KEY}
# Left disabled: Hermes itself warns that a network-reachable API server combined
# with the default unsandboxed ('local') terminal backend gives any caller full
# terminal/file access within the container. Matrix is the actual interface in use;
# re-enable (API_SERVER_HOST: 0.0.0.0) only alongside terminal.backend: docker if
# claude-agent ever needs to call Hermes programmatically.
API_SERVER_ENABLED: "false"
volumes:
- /home/william/hermes-data:/opt/data
networks:
- web
# Without this the image's default command launches the interactive CLI, which
# immediately exits ("Input is not a terminal") since a detached container has no
# stdin — the container then just sits there having done nothing, every restart.
command: ["gateway", "run"]
claude-agent:
image: ${GITEA_REGISTRY_IMAGE}
+13 -7
View File
@@ -11,13 +11,19 @@ model_list:
model: openrouter/openai/gpt-4o-mini
api_key: os.environ/OPENROUTER_API_KEY
# NOT included: a "claude-subscription" route forwarding the Claude Pro/Max OAuth token
# (from `claude setup-token`) through to Anthropic's raw API. Tested and confirmed
# non-functional — Anthropic returns a generic rate_limit_error for ANY direct API call
# using this token type outside the real Claude Code CLI client (reproduced with plain
# curl straight to api.anthropic.com, bypassing LiteLLM entirely, same result). The
# subscription token only works through the actual Claude Code CLI, which is what
# claude-agent already uses directly for code tasks — it was never routed through here.
# Routes to Anthropic using the CALLER's forwarded Authorization header (the Claude
# Pro/Max subscription OAuth token) instead of a LiteLLM-held API key — billed against
# the subscription, not per-token. CONFIRMED WORKING, but only for the real `claude`
# CLI binary as caller (tested: `claude -p` with ANTHROPIC_BASE_URL pointed here
# returned a real completion). An earlier test with plain curl replicating the same
# request shape failed — Anthropic apparently requires header/fingerprint details only
# the real CLI sends, which LiteLLM faithfully relays but a hand-built request won't
# have. Do NOT expect this to work for other callers (Hermes, generic HTTP clients) —
# they aren't the real CLI and can't reproduce that fingerprint.
- model_name: anthropic-claude
litellm_params:
model: anthropic/claude-sonnet-5
general_settings:
forward_client_headers_to_llm_api: true
master_key: os.environ/LITELLM_MASTER_KEY