Deployed as its own service (pinned nousresearch/hermes-agent:v2026.8.19), own Matrix bot account (@hermes), own OpenRouter-backed model config, and its own OpenAI-compatible API server (internal network only, for possible future use by claude-agent). Joins the same control room but only responds when explicitly @mentioned, restricted to the human user — no conflict with claude-bot's default no-prefix chat routing. claude-agent's router now ignores messages addressed to @hermes so both bots don't answer the same message. Bridge networking (the 'web' network), not the image's default host mode — no reason for an agent container to share the host's network namespace when everything it needs (the homeserver, OpenRouter) is reachable over the existing bridge.
59 lines
2.6 KiB
Bash
59 lines
2.6 KiB
Bash
# Copy to .env and fill in. Never commit the real .env.
|
|
# Note: ACME_EMAIL / Traefik itself are configured separately in ~/traefik/.env —
|
|
# Traefik is shared infra, not part of this stack (see docker-compose.yml comment).
|
|
|
|
# --- domain / TLS ---
|
|
MATRIX_SERVER_NAME=matrix.apps.williamturner.eu
|
|
AGENT_HOSTNAME=agent.apps.williamturner.eu
|
|
# Set to true ONLY for the first-boot window while creating the bot account,
|
|
# then back to false (or unset) and redeploy. See README.
|
|
MATRIX_ALLOW_REGISTRATION=false
|
|
|
|
# --- gitea ---
|
|
GITEA_URL=https://gitea.apps.williamturner.eu
|
|
GITEA_TOKEN=
|
|
GITEA_WEBHOOK_SECRET=
|
|
# Image the agent runs from — built and pushed by .gitea/workflows/build.yml
|
|
GITEA_REGISTRY_IMAGE=gitea.apps.williamturner.eu/<your-gitea-username>/<repo-name>/claude-agent:latest
|
|
|
|
# --- claude ---
|
|
# Run `claude setup-token` interactively (needs a browser + Claude Pro/Max subscription)
|
|
# to generate this — it's a long-lived OAuth token, not an API key.
|
|
CLAUDE_CODE_OAUTH_TOKEN=
|
|
|
|
# --- matrix bot ---
|
|
MATRIX_HOMESERVER_URL=https://matrix.apps.williamturner.eu
|
|
MATRIX_BOT_TOKEN=
|
|
MATRIX_CONTROL_ROOM_ID=
|
|
# The bot's own Matrix ID (@username:server), e.g. @claude-bot:matrix.apps.williamturner.eu
|
|
# — set explicitly rather than fetched via the API (that call 404s against Continuwuity).
|
|
# Required: without it the bot can't tell its own messages apart from real ones and would
|
|
# reply to itself in a loop, so it refuses to start.
|
|
MATRIX_BOT_USER_ID=
|
|
# Comma-separated "owner/repo" list the chat router is allowed to open code-change PRs
|
|
# against. A plain chat message mentioning a repo NOT in this list is treated as chat,
|
|
# never as a code task — the router only matches confidently against known repos.
|
|
KNOWN_REPOS=william/gitops-automation
|
|
|
|
# --- litellm (local LLM gateway — see litellm-config.yaml) ---
|
|
OPENROUTER_API_KEY=
|
|
# Any random string; also used as litellm's general_settings.master_key.
|
|
LITELLM_MASTER_KEY=
|
|
|
|
# --- hermes (autonomous agent with its own native Matrix presence) ---
|
|
# Your own Matrix ID — Hermes only responds to this user, and only when @mentioned
|
|
# in a shared room (e.g. "@hermes <task>" in the control room).
|
|
MATRIX_HUMAN_USER_ID=@william:matrix.apps.williamturner.eu
|
|
# Access token for the @hermes bot account (register it the same way as claude-bot —
|
|
# see README — then log in as it via /_matrix/client/v3/login to get this token).
|
|
HERMES_MATRIX_ACCESS_TOKEN=
|
|
# Any random string — bearer key for Hermes's own OpenAI-compatible API server
|
|
# (internal network only, not published anywhere).
|
|
HERMES_API_SERVER_KEY=
|
|
|
|
# --- portainer (GitOps redeploy) ---
|
|
PORTAINER_STACK_WEBHOOK_URL=
|
|
|
|
# --- gitea actions runner ---
|
|
ACT_RUNNER_REGISTRATION_TOKEN=
|