Enabled via HERMES_DASHBOARD=1 (supervised in-container alongside the
gateway, per docs/user-guide/docker.md), bound to 0.0.0.0:9119 so Traefik
can reach it. Two independent auth layers, not one:
1. Traefik basicauth middleware in front of the whole route.
2. Hermes's own basic-auth gate (mandatory once the bind is non-loopback).
Hermes's docs explicitly call basic-auth-alone "not suitable for direct
public-internet exposure" and cite a real June 2026 incident where
internet scanners reached exposed dashboards and drove agents into
planting SSH-key backdoors — hence the extra Traefik-level gate rather
than relying on Hermes's own login page alone.
Also fixes: the htpasswd hash for Traefik's basicauth needs its literal
'$' characters escaped as '2824147' in .env, or docker compose's own variable
interpolation corrupts it (mistook '' for further
references). Also switched the hash from Python's default SHA-512
crypt ('$...') to apr1 ('$...', via openssl passwd -apr1) —
Traefik's basicauth middleware doesn't accept SHA-512-crypt.
Also re-adds Hermes's OPENAI_BASE_URL/OPENAI_API_KEY routing through the
local litellm gateway (instead of OPENROUTER_API_KEY direct) — this was
part of the now-abandoned PR #12 and never actually landed on main.
58 lines
2.6 KiB
Bash
58 lines
2.6 KiB
Bash
# Copy to .env and fill in. Never commit the real .env.
|
|
# Note: ACME_EMAIL / Traefik itself are configured separately in ~/traefik/.env —
|
|
# Traefik is shared infra, not part of this stack (see docker-compose.yml comment).
|
|
|
|
# --- domain / TLS ---
|
|
MATRIX_SERVER_NAME=matrix.apps.williamturner.eu
|
|
AGENT_HOSTNAME=agent.apps.williamturner.eu
|
|
HERMES_DASHBOARD_HOSTNAME=hermes.apps.williamturner.eu
|
|
# Set to true ONLY for the first-boot window while creating the bot account,
|
|
# then back to false (or unset) and redeploy. See README.
|
|
MATRIX_ALLOW_REGISTRATION=false
|
|
|
|
# --- gitea ---
|
|
GITEA_URL=https://gitea.apps.williamturner.eu
|
|
GITEA_TOKEN=
|
|
GITEA_WEBHOOK_SECRET=
|
|
# Image the agent runs from — built and pushed by .gitea/workflows/build.yml
|
|
GITEA_REGISTRY_IMAGE=gitea.apps.williamturner.eu/<your-gitea-username>/<repo-name>/claude-agent:latest
|
|
|
|
# --- claude ---
|
|
# Run `claude setup-token` interactively (needs a browser + Claude Pro/Max subscription)
|
|
# to generate this — it's a long-lived OAuth token, not an API key.
|
|
CLAUDE_CODE_OAUTH_TOKEN=
|
|
|
|
# --- litellm (local LLM gateway — used by Hermes, see litellm-config.yaml) ---
|
|
OPENROUTER_API_KEY=
|
|
# Any random string; also used as litellm's general_settings.master_key.
|
|
LITELLM_MASTER_KEY=
|
|
|
|
# --- hermes (the only agent with a Matrix presence — see README) ---
|
|
# Your own Matrix ID — Hermes only responds to this user, and only when @mentioned
|
|
# in a room (free-response in DMs).
|
|
MATRIX_HUMAN_USER_ID=@william:matrix.apps.williamturner.eu
|
|
# Access token for the @hermes bot account — register it on the homeserver, then log
|
|
# in as it via /_matrix/client/v3/login to get this token (see README).
|
|
HERMES_MATRIX_ACCESS_TOKEN=
|
|
# Any random string — bearer key for Hermes's own OpenAI-compatible API server
|
|
# (internal network only, not published anywhere).
|
|
HERMES_API_SERVER_KEY=
|
|
|
|
# --- hermes web dashboard (hermes.apps.williamturner.eu) ---
|
|
# Two independent auth layers: Hermes's own login (basic auth — its docs call this
|
|
# "not suitable for direct public-internet exposure" alone) plus a Traefik-level basic
|
|
# auth gate in front of it. Both required, different credentials recommended.
|
|
HERMES_DASHBOARD_USERNAME=william
|
|
HERMES_DASHBOARD_PASSWORD=
|
|
# 32+ random bytes — `openssl rand -base64 32`
|
|
HERMES_DASHBOARD_SECRET=
|
|
# htpasswd-format "user:hash" for Traefik's basicauth middleware. Generate with:
|
|
# python3 -c "import crypt; print('someuser:' + crypt.crypt('somepassword', crypt.mksalt(crypt.METHOD_SHA512)))"
|
|
TRAEFIK_HERMES_AUTH_HASH=
|
|
|
|
# --- portainer (GitOps redeploy) ---
|
|
PORTAINER_STACK_WEBHOOK_URL=
|
|
|
|
# --- gitea actions runner ---
|
|
ACT_RUNNER_REGISTRATION_TOKEN=
|