Add Hermes WebUI and Athena operator skill
This commit is contained in:
@@ -819,6 +819,71 @@ services:
|
||||
retries: 20
|
||||
start_period: 45s
|
||||
|
||||
# Optional, fully removable community chat surface. Chat execution goes
|
||||
# through the existing Hermes gateway. Upstream's container entrypoint
|
||||
# requires a writable Hermes home for its ownership/init checks; UI-only
|
||||
# state still remains on a separate bind mount for easy removal.
|
||||
hermes-webui:
|
||||
image: ${HERMES_WEBUI_IMAGE:-mike-ai/hermes-webui:0.52.113-hermes-source-v1}
|
||||
container_name: mike-ai-hermes-webui
|
||||
restart: unless-stopped
|
||||
profiles: [hermes-webui]
|
||||
env_file:
|
||||
- /data/hermes-webui/.env
|
||||
volumes:
|
||||
- /data/hermes:/home/hermeswebui/.hermes
|
||||
- /data/hermes-webui/state:/state
|
||||
- /data/hermes-webui/hermes-agent:/home/hermeswebui/.hermes/hermes-agent:ro
|
||||
- /data/hermes/workspace:/workspace
|
||||
environment:
|
||||
HERMES_HOME: /home/hermeswebui/.hermes
|
||||
HERMES_WEBUI_STATE_DIR: /state
|
||||
HERMES_WEBUI_HOST: 0.0.0.0
|
||||
HERMES_WEBUI_PORT: "8787"
|
||||
HERMES_WEBUI_CHAT_BACKEND: gateway
|
||||
HERMES_WEBUI_GATEWAY_BASE_URL: http://hermes:8642
|
||||
HERMES_API_URL: http://hermes:8642
|
||||
HERMES_WEBUI_AGENT_DIR: /home/hermeswebui/.hermes/hermes-agent
|
||||
HERMES_WEBUI_GATEWAY_USE_RUNS_API: "true"
|
||||
HERMES_SKIP_CHMOD: "1"
|
||||
WANTED_UID: "10000"
|
||||
WANTED_GID: "10000"
|
||||
networks: [frontend]
|
||||
depends_on:
|
||||
hermes:
|
||||
condition: service_healthy
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
healthcheck:
|
||||
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8787/health', timeout=3)"]
|
||||
interval: 15s
|
||||
timeout: 5s
|
||||
retries: 20
|
||||
start_period: 45s
|
||||
|
||||
# Persistent VPN listener for the optional WebUI. Sharing the existing
|
||||
# WireGuard network namespace avoids recreating the remote-access gateway
|
||||
# merely to add one listener.
|
||||
hermes-webui-vpn-proxy:
|
||||
image: mike-ai/wireguard-gateway:local
|
||||
container_name: mike-ai-hermes-webui-vpn-proxy
|
||||
restart: unless-stopped
|
||||
profiles: [hermes-webui]
|
||||
network_mode: "service:wireguard-gateway"
|
||||
entrypoint: [socat]
|
||||
command:
|
||||
- TCP-LISTEN:8787,bind=192.168.1.212,reuseaddr,fork
|
||||
- TCP:hermes-webui:8787
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp:size=4m,mode=1777
|
||||
cap_drop: [ALL]
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
depends_on:
|
||||
wireguard-gateway:
|
||||
condition: service_healthy
|
||||
hermes-webui:
|
||||
condition: service_healthy
|
||||
|
||||
networks:
|
||||
frontend:
|
||||
internal: false
|
||||
|
||||
Reference in New Issue
Block a user