By request: one auth layer, not two. Note this isn't really removing a layer I added on top of nothing — Hermes's own gate is mandatory and can't be disabled while the dashboard is reachable through a separate Traefik container (it fails closed at startup on any non-loopback bind without a configured auth provider). The only thing actually optional was the Traefik-level middleware, so that's what comes out; Traefik now just does TLS termination + routing.
55 lines
2.3 KiB
Bash
55 lines
2.3 KiB
Bash
# Copy to .env and fill in. Never commit the real .env.
|
|
# Note: ACME_EMAIL / Traefik itself are configured separately in ~/traefik/.env —
|
|
# Traefik is shared infra, not part of this stack (see docker-compose.yml comment).
|
|
|
|
# --- domain / TLS ---
|
|
MATRIX_SERVER_NAME=matrix.apps.williamturner.eu
|
|
AGENT_HOSTNAME=agent.apps.williamturner.eu
|
|
HERMES_DASHBOARD_HOSTNAME=hermes.apps.williamturner.eu
|
|
# Set to true ONLY for the first-boot window while creating the bot account,
|
|
# then back to false (or unset) and redeploy. See README.
|
|
MATRIX_ALLOW_REGISTRATION=false
|
|
|
|
# --- gitea ---
|
|
GITEA_URL=https://gitea.apps.williamturner.eu
|
|
GITEA_TOKEN=
|
|
GITEA_WEBHOOK_SECRET=
|
|
# Image the agent runs from — built and pushed by .gitea/workflows/build.yml
|
|
GITEA_REGISTRY_IMAGE=gitea.apps.williamturner.eu/<your-gitea-username>/<repo-name>/claude-agent:latest
|
|
|
|
# --- claude ---
|
|
# Run `claude setup-token` interactively (needs a browser + Claude Pro/Max subscription)
|
|
# to generate this — it's a long-lived OAuth token, not an API key.
|
|
CLAUDE_CODE_OAUTH_TOKEN=
|
|
|
|
# --- litellm (local LLM gateway — used by Hermes, see litellm-config.yaml) ---
|
|
OPENROUTER_API_KEY=
|
|
# Any random string; also used as litellm's general_settings.master_key.
|
|
LITELLM_MASTER_KEY=
|
|
|
|
# --- hermes (the only agent with a Matrix presence — see README) ---
|
|
# Your own Matrix ID — Hermes only responds to this user, and only when @mentioned
|
|
# in a room (free-response in DMs).
|
|
MATRIX_HUMAN_USER_ID=@william:matrix.apps.williamturner.eu
|
|
# Access token for the @hermes bot account — register it on the homeserver, then log
|
|
# in as it via /_matrix/client/v3/login to get this token (see README).
|
|
HERMES_MATRIX_ACCESS_TOKEN=
|
|
# Any random string — bearer key for Hermes's own OpenAI-compatible API server
|
|
# (internal network only, not published anywhere).
|
|
HERMES_API_SERVER_KEY=
|
|
|
|
# --- hermes web dashboard (hermes.apps.williamturner.eu) ---
|
|
# Hermes's own login gate — mandatory once its dashboard is bound non-loopback (needed
|
|
# for Traefik, a separate container, to reach it at all), so this can't be turned off
|
|
# while the dashboard is reachable through Traefik.
|
|
HERMES_DASHBOARD_USERNAME=william
|
|
HERMES_DASHBOARD_PASSWORD=
|
|
# 32+ random bytes — `openssl rand -base64 32`
|
|
HERMES_DASHBOARD_SECRET=
|
|
|
|
# --- portainer (GitOps redeploy) ---
|
|
PORTAINER_STACK_WEBHOOK_URL=
|
|
|
|
# --- gitea actions runner ---
|
|
ACT_RUNNER_REGISTRATION_TOKEN=
|