Add Hermes Agent as reproducible second client
This commit is contained in:
@@ -16,7 +16,8 @@ WireGuard-Isolation.
|
|||||||
bewusst nicht standardmäßiges Uncensored-Spezialprofil
|
bewusst nicht standardmäßiges Uncensored-Spezialprofil
|
||||||
- `/ultra`: getestetes text-only 256K-Profil (IQ4_XS Pure, beide GPUs,
|
- `/ultra`: getestetes text-only 256K-Profil (IQ4_XS Pure, beide GPUs,
|
||||||
80:20); etwa 68 Token/s und erfolgreicher 220K-Prompt-Fülltest
|
80:20); etwa 68 Token/s und erfolgreicher 220K-Prompt-Fülltest
|
||||||
- Open WebUI als einzige normale Oberfläche
|
- Open WebUI als einfache Chat-Oberfläche und Hermes Agent als zweite,
|
||||||
|
agentische Oberfläche für lange, werkzeugintensive Aufgaben
|
||||||
- native OpenWebUI-Websuche für allgemeine Recherche; SearXNG/Web-MCP als
|
- native OpenWebUI-Websuche für allgemeine Recherche; SearXNG/Web-MCP als
|
||||||
manueller Spezialadapter ohne externen API-Schlüssel
|
manueller Spezialadapter ohne externen API-Schlüssel
|
||||||
- zentrale MCP-Werkzeugebene: getrennte Container für Athena-Plattformwissen,
|
- zentrale MCP-Werkzeugebene: getrennte Container für Athena-Plattformwissen,
|
||||||
@@ -51,6 +52,8 @@ Neustart an; danach wird derselbe Befehl erneut ausgeführt.
|
|||||||
| Dienst | Erreichbarkeit | Zweck |
|
| Dienst | Erreichbarkeit | Zweck |
|
||||||
|---|---|---|
|
|---|---|---|
|
||||||
| Open WebUI | `<WG-IP>:8080` | Chat und Administration |
|
| Open WebUI | `<WG-IP>:8080` | Chat und Administration |
|
||||||
|
| Hermes Dashboard | `<WG-IP>:9119` | agentischer Chat, Sitzungen, Skills und MCP-Verwaltung |
|
||||||
|
| Hermes API | `<WG-IP>:8642` | authentifizierte Agent-API |
|
||||||
| Profile Router | `<WG-IP>:8081` | OpenAI-kompatible API, Profilwahl |
|
| Profile Router | `<WG-IP>:8081` | OpenAI-kompatible API, Profilwahl |
|
||||||
| llama.cpp | nur Docker-intern | Inferenz und integrierte Vision |
|
| llama.cpp | nur Docker-intern | Inferenz und integrierte Vision |
|
||||||
| Profile Controller | nur Docker-intern | eng begrenzter Profil-/FLUX-Hot-Swap |
|
| Profile Controller | nur Docker-intern | eng begrenzter Profil-/FLUX-Hot-Swap |
|
||||||
@@ -70,6 +73,11 @@ Pi, Hermes und andere Clients verwenden die direkten WireGuard-Ports aus
|
|||||||
Infrastruktur-Secrets. Die Bildanalyse ist Bestandteil des multimodalen
|
Infrastruktur-Secrets. Die Bildanalyse ist Bestandteil des multimodalen
|
||||||
Qwen-Modells.
|
Qwen-Modells.
|
||||||
|
|
||||||
|
Hermes läuft als eigener, per OCI-Digest gepinnter Container direkt neben
|
||||||
|
OpenWebUI. Beide sprechen dieselbe Router-API und damit dieselben Qwen-Profile;
|
||||||
|
Hermes ist kein zusätzlicher Modellserver. Seine Sitzungen, Skills,
|
||||||
|
Konfiguration und isolierte Arbeitsfläche liegen unter `/data/hermes`.
|
||||||
|
|
||||||
Open WebUI erhält über die vorgesehenen statischen Anpassungspunkte ein globales
|
Open WebUI erhält über die vorgesehenen statischen Anpassungspunkte ein globales
|
||||||
Dark-Theme namens **Midnight Aurora**. CSS und Start-Loader liegen unter
|
Dark-Theme namens **Midnight Aurora**. CSS und Start-Loader liegen unter
|
||||||
`platform/openwebui/theme/` und werden schreibgeschützt in den Container
|
`platform/openwebui/theme/` und werden schreibgeschützt in den Container
|
||||||
@@ -123,6 +131,7 @@ config/install.env.example öffentliche Konfigurationsvorlage
|
|||||||
compose.yaml produktiver Stack
|
compose.yaml produktiver Stack
|
||||||
platform/docker/llama-cpp/Dockerfile CUDA-llama.cpp-Build
|
platform/docker/llama-cpp/Dockerfile CUDA-llama.cpp-Build
|
||||||
platform/docker/profile-controller/ sichere Profilsteuerung
|
platform/docker/profile-controller/ sichere Profilsteuerung
|
||||||
|
platform/hermes/ Hermes-Konfiguration und Installer
|
||||||
router/ OpenAI-kompatibler Profile Router
|
router/ OpenAI-kompatibler Profile Router
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -784,6 +784,33 @@ services:
|
|||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
security_opt: ["no-new-privileges:true"]
|
security_opt: ["no-new-privileges:true"]
|
||||||
|
|
||||||
|
hermes:
|
||||||
|
image: ${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495}
|
||||||
|
container_name: mike-ai-hermes
|
||||||
|
restart: unless-stopped
|
||||||
|
command: [gateway, run]
|
||||||
|
env_file:
|
||||||
|
- /data/hermes/.env
|
||||||
|
volumes:
|
||||||
|
- /data/hermes:/opt/data
|
||||||
|
- /data/hermes/workspace:/workspace
|
||||||
|
environment:
|
||||||
|
HERMES_HOME: /opt/data
|
||||||
|
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||||
|
networks: [frontend, tools, tools-egress]
|
||||||
|
depends_on:
|
||||||
|
wireguard-gateway:
|
||||||
|
condition: service_healthy
|
||||||
|
router:
|
||||||
|
condition: service_healthy
|
||||||
|
security_opt: ["no-new-privileges:true"]
|
||||||
|
healthcheck:
|
||||||
|
test: [CMD, curl, -fsS, "http://127.0.0.1:8642/health"]
|
||||||
|
interval: 15s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 20
|
||||||
|
start_period: 45s
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
frontend:
|
frontend:
|
||||||
internal: false
|
internal: false
|
||||||
|
|||||||
@@ -15,6 +15,8 @@ Heimnetz / VPN-Clients
|
|||||||
|
|
|
|
||||||
<Fritz-VPN-IP>:8080 Open WebUI
|
<Fritz-VPN-IP>:8080 Open WebUI
|
||||||
<Fritz-VPN-IP>:8081 Profile Router API
|
<Fritz-VPN-IP>:8081 Profile Router API
|
||||||
|
<Fritz-VPN-IP>:9119 Hermes Dashboard
|
||||||
|
<Fritz-VPN-IP>:8642 Hermes Agent API
|
||||||
<Fritz-VPN-IP>:8201-08 direkte MCP-Endpunkte
|
<Fritz-VPN-IP>:8201-08 direkte MCP-Endpunkte
|
||||||
|
|
|
|
||||||
Docker-intern
|
Docker-intern
|
||||||
@@ -42,6 +44,7 @@ Heimnetz / VPN-Clients
|
|||||||
|---|---|---|
|
|---|---|---|
|
||||||
| WireGuard Gateway | VPN-Adresse, feste Portmatrix | Tunnel und direkte TCP-Proxys für UI, API und Werkzeuge |
|
| WireGuard Gateway | VPN-Adresse, feste Portmatrix | Tunnel und direkte TCP-Proxys für UI, API und Werkzeuge |
|
||||||
| Open WebUI | nur Docker-intern | Chat-Oberfläche |
|
| Open WebUI | nur Docker-intern | Chat-Oberfläche |
|
||||||
|
| Hermes Agent | nur Docker-intern; Dashboard/API über VPN-Gateway | agentische Oberfläche, Skills, Sitzungen und MCP-Client |
|
||||||
| Profile Router | nur Docker-intern | OpenAI-API und Profilwahl |
|
| Profile Router | nur Docker-intern | OpenAI-API und Profilwahl |
|
||||||
| Profile Controller | nein | startet ausschließlich fest erlaubte Profile |
|
| Profile Controller | nein | startet ausschließlich fest erlaubte Profile |
|
||||||
| llama.cpp Profile | nein | Inferenz, Tool Calling, integrierte Vision |
|
| llama.cpp Profile | nein | Inferenz, Tool Calling, integrierte Vision |
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ Dokumentation.
|
|||||||
| Qwen-, Projektor- und Bildmodelle | dokumentierte URLs und SHA256 in `config/install.env.example` beziehungsweise der gesicherten Installationskonfiguration |
|
| Qwen-, Projektor- und Bildmodelle | dokumentierte URLs und SHA256 in `config/install.env.example` beziehungsweise der gesicherten Installationskonfiguration |
|
||||||
| Navidrome-MCP 2.2.0 samt llama.cpp-Schemafix | `platform/mcp/Dockerfile.navidrome` |
|
| Navidrome-MCP 2.2.0 samt llama.cpp-Schemafix | `platform/mcp/Dockerfile.navidrome` |
|
||||||
| OpenWebUI-Benutzer, Chats, Arbeitsbereichsmodelle, Filter und Verbindungen | verschlüsseltes Recovery-Bundle |
|
| OpenWebUI-Benutzer, Chats, Arbeitsbereichsmodelle, Filter und Verbindungen | verschlüsseltes Recovery-Bundle |
|
||||||
|
| Hermes-Sitzungen, Skills, Konfiguration und Arbeitsfläche | `/data/hermes` im verschlüsselten Recovery-Bundle |
|
||||||
| Router-, WireGuard-, HA-, ARR-, Unraid- und Navidrome-Zugangsdaten | verschlüsseltes Recovery-Bundle |
|
| Router-, WireGuard-, HA-, ARR-, Unraid- und Navidrome-Zugangsdaten | verschlüsseltes Recovery-Bundle |
|
||||||
| Last.fm API-Key | `/etc/mike-ai/navidrome-mcp.env` im verschlüsselten Bundle |
|
| Last.fm API-Key | `/etc/mike-ai/navidrome-mcp.env` im verschlüsselten Bundle |
|
||||||
| Navidrome-Bibliothek und Benutzer | bleiben auf dem separaten Unraid-Server |
|
| Navidrome-Bibliothek und Benutzer | bleiben auf dem separaten Unraid-Server |
|
||||||
@@ -54,6 +55,8 @@ Das Skript nimmt ausschließlich auf:
|
|||||||
- das produktive Dokumentations-Overlay unter `/opt/mike-ai/stack/docs`,
|
- das produktive Dokumentations-Overlay unter `/opt/mike-ai/stack/docs`,
|
||||||
- Vorschläge, Sicherungen und Auditstatus des Platform Context MCP unter
|
- Vorschläge, Sicherungen und Auditstatus des Platform Context MCP unter
|
||||||
`/data/mike-ai-platform-context`,
|
`/data/mike-ai-platform-context`,
|
||||||
|
- Hermes-Sitzungen, Skills, Konfiguration und Arbeitsfläche unter
|
||||||
|
`/data/hermes`,
|
||||||
- das vollständige OpenWebUI-Datenvolume,
|
- das vollständige OpenWebUI-Datenvolume,
|
||||||
- Prüfsummen und den eingesetzten Git-Commit.
|
- Prüfsummen und den eingesetzten Git-Commit.
|
||||||
|
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
| llama.cpp | ggml-org/llama.cpp, festgeschriebener Commit | Buildskript und Commit | Kern |
|
| llama.cpp | ggml-org/llama.cpp, festgeschriebener Commit | Buildskript und Commit | Kern |
|
||||||
| Qwen-Profile | `platform/profiles/` | vollständig, Modelle ausgenommen | Kern |
|
| Qwen-Profile | `platform/profiles/` | vollständig, Modelle ausgenommen | Kern |
|
||||||
| MCP-Tool-Stack | `platform/mcp/compose.yaml` | vollständig | Kern |
|
| MCP-Tool-Stack | `platform/mcp/compose.yaml` | vollständig | Kern |
|
||||||
|
| Hermes Agent | NousResearch Hermes Agent 0.20.5, OCI-Digest gepinnt | eigener Clientcontainer, Dashboard/API, persistente Daten unter `/data/hermes` | Kern |
|
||||||
| Websuche | SearXNG + TinySearch/Crawl4AI | intern, ohne veröffentlichten Port | Kern |
|
| Websuche | SearXNG + TinySearch/Crawl4AI | intern, ohne veröffentlichten Port | Kern |
|
||||||
| Allgemeines Web | OpenWebUI native Suche; TinySearch-Upstream-MCP auf VPN-Port 8203 für andere Clients | site-unabhängig; keine neue Implementierung pro Website | Kern |
|
| Allgemeines Web | OpenWebUI native Suche; TinySearch-Upstream-MCP auf VPN-Port 8203 für andere Clients | site-unabhängig; keine neue Implementierung pro Website | Kern |
|
||||||
| Frühere Web-MCP-Fassade | `platform/web-search/web_search_mcp.py` | nur Rollback-Profil `legacy-web` | Altbestand |
|
| Frühere Web-MCP-Fassade | `platform/web-search/web_search_mcp.py` | nur Rollback-Profil `legacy-web` | Altbestand |
|
||||||
|
|||||||
@@ -83,6 +83,20 @@ Der Router übernimmt:
|
|||||||
- Piper als automatischer CPU-Fallback
|
- Piper als automatischer CPU-Fallback
|
||||||
- Zustands- und Modellendpunkte
|
- Zustands- und Modellendpunkte
|
||||||
|
|
||||||
|
## Hermes Agent
|
||||||
|
|
||||||
|
- Container: `mike-ai-hermes`
|
||||||
|
- Version: 0.20.5, offizielles Image per OCI-Digest gepinnt
|
||||||
|
- Standardmodell: `qwen-medium`, 160.000 Kontext, über den Profile Router
|
||||||
|
- Dashboard: WireGuard-Port 9119 mit Basic-Auth
|
||||||
|
- Agent-API: WireGuard-Port 8642 mit eigenem Bearer-Key
|
||||||
|
- persistenter Zustand: `/data/hermes`
|
||||||
|
- lokales Terminal: ausschließlich `/data/hermes/workspace` im Container
|
||||||
|
- MCPs: Athena-Plattform, Athena-Operator, allgemeines Web, GitHub, Home
|
||||||
|
Assistant, ARR, Navidrome und ein gemeinsamer MUA-Unraid-Zugang
|
||||||
|
- kein Docker-Socket, kein Host-Root-Mount und keine Veröffentlichung auf der
|
||||||
|
Universitätsadresse
|
||||||
|
|
||||||
## Vision
|
## Vision
|
||||||
|
|
||||||
| Bereich | Referenz |
|
| Bereich | Referenz |
|
||||||
|
|||||||
@@ -63,6 +63,8 @@ werden nicht ausgegeben. Sie liegen root-only unter `/etc/mike-ai`.
|
|||||||
|
|
||||||
- Open WebUI: `http://<WIREGUARD-IP>:8080`
|
- Open WebUI: `http://<WIREGUARD-IP>:8080`
|
||||||
- Router: `http://<WIREGUARD-IP>:8081`
|
- Router: `http://<WIREGUARD-IP>:8081`
|
||||||
|
- Hermes Dashboard: `http://<WIREGUARD-IP>:9119`
|
||||||
|
- Hermes API: `http://<WIREGUARD-IP>:8642`
|
||||||
- SSH fallback: `ssh root@<WIREGUARD-IP>` (key-only, forwarded to host sshd)
|
- SSH fallback: `ssh root@<WIREGUARD-IP>` (key-only, forwarded to host sshd)
|
||||||
- llama.cpp-WebUI: absichtlich deaktiviert und nicht veröffentlicht
|
- llama.cpp-WebUI: absichtlich deaktiviert und nicht veröffentlicht
|
||||||
|
|
||||||
@@ -72,9 +74,23 @@ sudo docker inspect -f '{{.State.Health.Status}}' mike-ai-wireguard-gateway
|
|||||||
sudo docker compose --env-file /etc/mike-ai/stack.env \
|
sudo docker compose --env-file /etc/mike-ai/stack.env \
|
||||||
-f /opt/mike-ai/stack/compose.yaml ps
|
-f /opt/mike-ai/stack/compose.yaml ps
|
||||||
curl http://<WIREGUARD-IP>:8081/health
|
curl http://<WIREGUARD-IP>:8081/health
|
||||||
|
curl http://<WIREGUARD-IP>:8642/health
|
||||||
ssh -o BatchMode=yes root@<WIREGUARD-IP> true
|
ssh -o BatchMode=yes root@<WIREGUARD-IP> true
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Hermes verwendet standardmäßig `qwen-medium` mit 160K Kontext und dieselbe
|
||||||
|
Router-API wie OpenWebUI. Das Dashboard meldet sich mit Benutzer `michael` an;
|
||||||
|
das zufällig erzeugte Kennwort wird ausschließlich lokal angezeigt:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sudo cat /etc/mike-ai/hermes-dashboard-password
|
||||||
|
```
|
||||||
|
|
||||||
|
Der Schlüssel der Agent-API liegt entsprechend unter
|
||||||
|
`/etc/mike-ai/hermes-api-key`. Beide Werte gehören weder in Git noch in Chats.
|
||||||
|
Hermes' lokales Terminal sieht nur `/data/hermes/workspace` im Container. Für
|
||||||
|
Athena und Unraid verwendet es die dokumentierten Operator-/MUA-MCPs.
|
||||||
|
|
||||||
Der SSH-Fallback lauscht ausschließlich auf der IPv4-Adresse von `wg0` im
|
Der SSH-Fallback lauscht ausschließlich auf der IPv4-Adresse von `wg0` im
|
||||||
WireGuard-Gateway-Container. Er wird nicht als Docker-Port auf dem
|
WireGuard-Gateway-Container. Er wird nicht als Docker-Port auf dem
|
||||||
Standort-Interface veröffentlicht. Das Gateway leitet die Verbindung an den
|
Standort-Interface veröffentlicht. Das Gateway leitet die Verbindung an den
|
||||||
|
|||||||
@@ -7,7 +7,8 @@ operative Änderungen gilt zusätzlich `QWEN_OPERATOR_CONTEXT.md`.
|
|||||||
|
|
||||||
Athena ist ein selbst betriebener, datenschutzorientierter KI-Host. Er steht
|
Athena ist ein selbst betriebener, datenschutzorientierter KI-Host. Er steht
|
||||||
physisch an einem entfernten Standort ohne KVM und wird ausschließlich remote
|
physisch an einem entfernten Standort ohne KVM und wird ausschließlich remote
|
||||||
administriert. Open WebUI ist die Benutzeroberfläche. Ein eigener Profile
|
administriert. Open WebUI ist die einfache Benutzeroberfläche; Hermes Agent
|
||||||
|
ist der zweite Client für lange agentische Aufgaben. Ein eigener Profile
|
||||||
Router stellt eine OpenAI-kompatible API bereit und schaltet zwischen mehreren
|
Router stellt eine OpenAI-kompatible API bereit und schaltet zwischen mehreren
|
||||||
reproduzierbaren llama.cpp-Profilen um. Fachwerkzeuge laufen als getrennte MCP-
|
reproduzierbaren llama.cpp-Profilen um. Fachwerkzeuge laufen als getrennte MCP-
|
||||||
Container; Zugangsdaten gelangen weder in llama.cpp noch in Modellprompts.
|
Container; Zugangsdaten gelangen weder in llama.cpp noch in Modellprompts.
|
||||||
@@ -43,7 +44,7 @@ bezeichnen als Index 0 von `nvidia-smi` auf dem Host.
|
|||||||
## Hauptfluss
|
## Hauptfluss
|
||||||
|
|
||||||
```text
|
```text
|
||||||
Browser / API-Client
|
Browser / OpenWebUI / Hermes Agent
|
||||||
|
|
|
|
||||||
| WireGuard, ausschließlich VPN
|
| WireGuard, ausschließlich VPN
|
||||||
v
|
v
|
||||||
@@ -64,6 +65,12 @@ Open WebUI ---> Profile Router ---> Profile Controller ---> genau ein llama.cpp-
|
|||||||
+-- Unraid
|
+-- Unraid
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Hermes hängt parallel zu OpenWebUI direkt am Router und an denselben
|
||||||
|
MCP-Containern. Es betreibt kein zweites Qwen und verändert die Profilmatrix
|
||||||
|
nicht. Dashboard und Agent-API sind nur über WireGuard erreichbar; dauerhafte
|
||||||
|
Hermes-Daten liegen unter `/data/hermes` und sind Bestandteil des
|
||||||
|
verschlüsselten Recovery-Bundles.
|
||||||
|
|
||||||
Deemix läuft bereits als Container auf dem Unraid-HomeServer. Eine künftige
|
Deemix läuft bereits als Container auf dem Unraid-HomeServer. Eine künftige
|
||||||
Deemix-MCP-Integration auf Athena verwendet dieses Backend über WireGuard und
|
Deemix-MCP-Integration auf Athena verwendet dieses Backend über WireGuard und
|
||||||
erzeugt nicht ungefragt eine zweite Deemix-Instanz.
|
erzeugt nicht ungefragt eine zweite Deemix-Instanz.
|
||||||
|
|||||||
@@ -15,6 +15,8 @@ Aktuelle VPN-Adresse: `192.168.1.212`
|
|||||||
| 8085 | TTS-Gateway | `http://192.168.1.212:8085` |
|
| 8085 | TTS-Gateway | `http://192.168.1.212:8085` |
|
||||||
| 8091 | Piper direkt | `http://192.168.1.212:8091` |
|
| 8091 | Piper direkt | `http://192.168.1.212:8091` |
|
||||||
| 8092 | XTTS direkt | `http://192.168.1.212:8092` |
|
| 8092 | XTTS direkt | `http://192.168.1.212:8092` |
|
||||||
|
| 9119 | Hermes Dashboard | `http://192.168.1.212:9119` |
|
||||||
|
| 8642 | Hermes Agent API | `http://192.168.1.212:8642` |
|
||||||
| 8201 | Athena Platform Context MCP | `http://192.168.1.212:8201/mcp` |
|
| 8201 | Athena Platform Context MCP | `http://192.168.1.212:8201/mcp` |
|
||||||
| 8202 | Athena Operator MCP einschließlich Terminal | `http://192.168.1.212:8202/mcp` |
|
| 8202 | Athena Operator MCP einschließlich Terminal | `http://192.168.1.212:8202/mcp` |
|
||||||
| 8203 | Allgemeiner TinySearch-MCP | `http://192.168.1.212:8203/mcp` |
|
| 8203 | Allgemeiner TinySearch-MCP | `http://192.168.1.212:8203/mcp` |
|
||||||
|
|||||||
+4
-1
@@ -315,6 +315,7 @@ WEBUI_SECRET_KEY=$(<$SECRETS_DIR/webui-secret)
|
|||||||
OPENWEBUI_IMAGE=${OPENWEBUI_IMAGE:-mike-ai/openwebui:main-01f4282-tool-final-v3}
|
OPENWEBUI_IMAGE=${OPENWEBUI_IMAGE:-mike-ai/openwebui:main-01f4282-tool-final-v3}
|
||||||
OPENWEBUI_ENABLE_SIGNUP=${OPENWEBUI_ENABLE_SIGNUP:-false}
|
OPENWEBUI_ENABLE_SIGNUP=${OPENWEBUI_ENABLE_SIGNUP:-false}
|
||||||
OPENWEBUI_ENABLE_FOLLOW_UP_GENERATION=${OPENWEBUI_ENABLE_FOLLOW_UP_GENERATION:-false}
|
OPENWEBUI_ENABLE_FOLLOW_UP_GENERATION=${OPENWEBUI_ENABLE_FOLLOW_UP_GENERATION:-false}
|
||||||
|
HERMES_IMAGE=${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495}
|
||||||
PIPER_TTS_VERSION=${PIPER_TTS_VERSION:-1.6.0}
|
PIPER_TTS_VERSION=${PIPER_TTS_VERSION:-1.6.0}
|
||||||
PIPER_VOICE=${PIPER_VOICE:-de_DE-thorsten-high}
|
PIPER_VOICE=${PIPER_VOICE:-de_DE-thorsten-high}
|
||||||
XTTS_IMAGE=${XTTS_IMAGE:-ghcr.io/coqui-ai/xtts-streaming-server:latest-cuda121@sha256:f7fb3b1f9d4bc88af94da1b5959d8002f1e0b003c97557164034eb8a29f01b90}
|
XTTS_IMAGE=${XTTS_IMAGE:-ghcr.io/coqui-ai/xtts-streaming-server:latest-cuda121@sha256:f7fb3b1f9d4bc88af94da1b5959d8002f1e0b003c97557164034eb8a29f01b90}
|
||||||
@@ -478,11 +479,12 @@ build_and_start() {
|
|||||||
# Web search always starts; HA/ARR/Unraid only start when their root-only
|
# Web search always starts; HA/ARR/Unraid only start when their root-only
|
||||||
# secret files and required local artifacts are present.
|
# secret files and required local artifacts are present.
|
||||||
"$STACK_DIR/platform/mcp/install-tools.sh"
|
"$STACK_DIR/platform/mcp/install-tools.sh"
|
||||||
|
"$STACK_DIR/platform/hermes/install-hermes.sh"
|
||||||
docker compose --env-file "$SECRETS_DIR/stack.env" --profile inference create \
|
docker compose --env-file "$SECRETS_DIR/stack.env" --profile inference create \
|
||||||
llama-fast llama-medium llama-large llama-ultra llama-experimental
|
llama-fast llama-medium llama-large llama-ultra llama-experimental
|
||||||
docker compose --env-file "$SECRETS_DIR/stack.env" --profile image create flux-worker
|
docker compose --env-file "$SECRETS_DIR/stack.env" --profile image create flux-worker
|
||||||
docker compose --env-file "$SECRETS_DIR/stack.env" up -d --build \
|
docker compose --env-file "$SECRETS_DIR/stack.env" up -d --build \
|
||||||
xtts piper tts-gateway profile-controller router open-webui
|
xtts piper tts-gateway profile-controller router open-webui hermes
|
||||||
|
|
||||||
if [[ ${WIREGUARD_MODE:-container} == container ]]; then
|
if [[ ${WIREGUARD_MODE:-container} == container ]]; then
|
||||||
systemctl restart mike-ai-container-vpn-guard.service
|
systemctl restart mike-ai-container-vpn-guard.service
|
||||||
@@ -558,6 +560,7 @@ fi
|
|||||||
cat <<EOF
|
cat <<EOF
|
||||||
OpenWebUI: http://${vpn_address}:8080
|
OpenWebUI: http://${vpn_address}:8080
|
||||||
Router-API: http://${vpn_address}:8081
|
Router-API: http://${vpn_address}:8081
|
||||||
|
Hermes: http://${vpn_address}:9119
|
||||||
|
|
||||||
Die geheimen Schlüssel liegen ausschließlich unter $SECRETS_DIR (0600).
|
Die geheimen Schlüssel liegen ausschließlich unter $SECRETS_DIR (0600).
|
||||||
Im Container-Modus stammen Peer, Adresse und Heimrouten vollständig aus dem
|
Im Container-Modus stammen Peer, Adresse und Heimrouten vollständig aus dem
|
||||||
|
|||||||
@@ -79,6 +79,8 @@ start_proxy 8081 router:8081
|
|||||||
start_proxy 8085 tts-gateway:8085
|
start_proxy 8085 tts-gateway:8085
|
||||||
start_proxy 8091 piper:8085
|
start_proxy 8091 piper:8085
|
||||||
start_proxy 8092 xtts:80
|
start_proxy 8092 xtts:80
|
||||||
|
start_proxy 9119 hermes:9119
|
||||||
|
start_proxy 8642 hermes:8642
|
||||||
|
|
||||||
# MCP endpoints. Optional services keep their listener even while stopped and
|
# MCP endpoints. Optional services keep their listener even while stopped and
|
||||||
# begin working automatically as soon as their container is started.
|
# begin working automatically as soon as their container is started.
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
_config_version: 38
|
||||||
|
|
||||||
|
model:
|
||||||
|
default: "qwen-medium"
|
||||||
|
provider: "custom"
|
||||||
|
base_url: "http://router:8081/v1"
|
||||||
|
api_key: "${ROUTER_API_KEY}"
|
||||||
|
context_length: 160000
|
||||||
|
api_mode: "chat_completions"
|
||||||
|
|
||||||
|
# Commands run in an isolated, persistent workspace. Host and Unraid changes
|
||||||
|
# use the audited operator/MUA MCPs instead of a Docker socket or host mount.
|
||||||
|
terminal:
|
||||||
|
backend: "local"
|
||||||
|
cwd: "/workspace"
|
||||||
|
timeout: 600
|
||||||
|
home_mode: "profile"
|
||||||
|
persistent_shell: true
|
||||||
|
lifetime_seconds: 1800
|
||||||
|
|
||||||
|
web:
|
||||||
|
search_backend: "searxng"
|
||||||
|
extract_backend: "native"
|
||||||
|
extract_char_limit: 15000
|
||||||
|
keyless_fallback: true
|
||||||
|
keyless_rescue: true
|
||||||
|
|
||||||
|
agent:
|
||||||
|
max_turns: 100
|
||||||
|
gateway_timeout: 3600
|
||||||
|
session_stall_timeout: 600
|
||||||
|
|
||||||
|
skills:
|
||||||
|
creation_nudge_interval: 20
|
||||||
|
|
||||||
|
plugins:
|
||||||
|
enabled: ["web-searxng"]
|
||||||
|
|
||||||
|
timeouts:
|
||||||
|
tools:
|
||||||
|
concurrent_batch: 900
|
||||||
|
sequential_call: 900
|
||||||
|
|
||||||
|
mcp_servers:
|
||||||
|
athena-platform:
|
||||||
|
url: "http://mcp-platform-context:8000/mcp"
|
||||||
|
timeout: 180
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
athena-operator:
|
||||||
|
url: "http://mcp-athena-operator:8000/mcp"
|
||||||
|
timeout: 900
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
web-general:
|
||||||
|
url: "http://tinysearch:8000/mcp"
|
||||||
|
timeout: 180
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
github:
|
||||||
|
url: "http://mcp-github:8000/mcp"
|
||||||
|
timeout: 300
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
homeassistant:
|
||||||
|
url: "http://mcp-homeassistant:8000/mcp"
|
||||||
|
timeout: 300
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
arr:
|
||||||
|
url: "http://mcp-arr:8000/mcp"
|
||||||
|
timeout: 600
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
navidrome:
|
||||||
|
url: "http://mike-ai-mcp-navidrome:3000/mcp"
|
||||||
|
timeout: 300
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
|
unraid:
|
||||||
|
url: "${MUA_MCP_URL}"
|
||||||
|
headers:
|
||||||
|
Authorization: "Bearer ${MUA_MCP_BEARER_TOKEN}"
|
||||||
|
timeout: 900
|
||||||
|
connect_timeout: 30
|
||||||
|
supports_parallel_tool_calls: false
|
||||||
Executable
+58
@@ -0,0 +1,58 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -Eeuo pipefail
|
||||||
|
umask 077
|
||||||
|
|
||||||
|
STACK_DIR=${STACK_DIR:-/opt/mike-ai/stack}
|
||||||
|
SECRETS_DIR=${SECRETS_DIR:-/etc/mike-ai}
|
||||||
|
HERMES_DATA_DIR=${HERMES_DATA_DIR:-/data/hermes}
|
||||||
|
MUA_ENV=${MUA_ENV:-$SECRETS_DIR/mua-mcp.env}
|
||||||
|
|
||||||
|
die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; }
|
||||||
|
[[ $EUID -eq 0 ]] || die "Bitte als root ausführen."
|
||||||
|
[[ -s $SECRETS_DIR/router-api-key ]] || die "Router-API-Key fehlt."
|
||||||
|
[[ -s $STACK_DIR/platform/hermes/config.yaml ]] || die "Hermes-Konfiguration fehlt im Stack."
|
||||||
|
|
||||||
|
install -d -m 0700 "$HERMES_DATA_DIR"
|
||||||
|
install -d -m 0750 "$HERMES_DATA_DIR/workspace"
|
||||||
|
[[ -s $SECRETS_DIR/hermes-api-key ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-api-key"
|
||||||
|
[[ -s $SECRETS_DIR/hermes-dashboard-password ]] || openssl rand -base64 24 >"$SECRETS_DIR/hermes-dashboard-password"
|
||||||
|
[[ -s $SECRETS_DIR/hermes-dashboard-secret ]] || openssl rand -base64 48 >"$SECRETS_DIR/hermes-dashboard-secret"
|
||||||
|
chmod 0600 "$SECRETS_DIR/hermes-api-key" \
|
||||||
|
"$SECRETS_DIR/hermes-dashboard-password" \
|
||||||
|
"$SECRETS_DIR/hermes-dashboard-secret"
|
||||||
|
|
||||||
|
router_key=$(<"$SECRETS_DIR/router-api-key")
|
||||||
|
mua_url=http://127.0.0.1:9/mcp
|
||||||
|
mua_token=not-configured
|
||||||
|
if [[ -s $MUA_ENV ]]; then
|
||||||
|
mua_url=$(sed -n 's/^MUA_MCP_URL=//p' "$MUA_ENV" | head -n 1)
|
||||||
|
mua_token=$(sed -n 's/^MUA_MCP_BEARER_TOKEN=//p' "$MUA_ENV" | head -n 1)
|
||||||
|
[[ -n $mua_url && -n $mua_token ]] || die "MUA URL oder Token fehlt."
|
||||||
|
fi
|
||||||
|
|
||||||
|
cat >"$HERMES_DATA_DIR/.env" <<EOF
|
||||||
|
ROUTER_API_KEY=$router_key
|
||||||
|
MUA_MCP_URL=$mua_url
|
||||||
|
MUA_MCP_BEARER_TOKEN=$mua_token
|
||||||
|
SEARXNG_URL=http://searxng:8080
|
||||||
|
API_SERVER_ENABLED=true
|
||||||
|
API_SERVER_HOST=0.0.0.0
|
||||||
|
API_SERVER_PORT=8642
|
||||||
|
API_SERVER_KEY=$(<"$SECRETS_DIR/hermes-api-key")
|
||||||
|
API_SERVER_MODEL_NAME=MikeAI-Hermes
|
||||||
|
HERMES_DASHBOARD=1
|
||||||
|
HERMES_DASHBOARD_HOST=0.0.0.0
|
||||||
|
HERMES_DASHBOARD_PORT=9119
|
||||||
|
HERMES_DASHBOARD_BASIC_AUTH_USERNAME=michael
|
||||||
|
HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=$(<"$SECRETS_DIR/hermes-dashboard-password")
|
||||||
|
HERMES_DASHBOARD_BASIC_AUTH_SECRET=$(<"$SECRETS_DIR/hermes-dashboard-secret")
|
||||||
|
EOF
|
||||||
|
chmod 0600 "$HERMES_DATA_DIR/.env"
|
||||||
|
|
||||||
|
if [[ -s $HERMES_DATA_DIR/config.yaml ]] && \
|
||||||
|
! cmp -s "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml"; then
|
||||||
|
cp -a "$HERMES_DATA_DIR/config.yaml" \
|
||||||
|
"$HERMES_DATA_DIR/config.yaml.before-managed-update-$(date +%Y%m%d-%H%M%S)"
|
||||||
|
fi
|
||||||
|
install -m 0600 "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml"
|
||||||
|
printf 'HERMES_CONFIG_OK %s\n' "$HERMES_DATA_DIR"
|
||||||
@@ -33,7 +33,8 @@ for source in \
|
|||||||
/etc/mike-ai \
|
/etc/mike-ai \
|
||||||
/root/mike-ai-install.env \
|
/root/mike-ai-install.env \
|
||||||
/opt/mike-ai/stack/docs \
|
/opt/mike-ai/stack/docs \
|
||||||
/data/mike-ai-platform-context; do
|
/data/mike-ai-platform-context \
|
||||||
|
/data/hermes; do
|
||||||
[[ -e $source ]] || continue
|
[[ -e $source ]] || continue
|
||||||
rsync -aR "$source" "$stage/rootfs/"
|
rsync -aR "$source" "$stage/rootfs/"
|
||||||
done
|
done
|
||||||
|
|||||||
Reference in New Issue
Block a user