Add Hermes WebUI and Athena operator skill

This commit is contained in:
Mikei386
2026-08-24 21:50:23 +02:00
parent 335c9a8501
commit 71775891b4
15 changed files with 446 additions and 0 deletions
+65
View File
@@ -819,6 +819,71 @@ services:
retries: 20
start_period: 45s
# Optional, fully removable community chat surface. Chat execution goes
# through the existing Hermes gateway. Upstream's container entrypoint
# requires a writable Hermes home for its ownership/init checks; UI-only
# state still remains on a separate bind mount for easy removal.
hermes-webui:
image: ${HERMES_WEBUI_IMAGE:-mike-ai/hermes-webui:0.52.113-hermes-source-v1}
container_name: mike-ai-hermes-webui
restart: unless-stopped
profiles: [hermes-webui]
env_file:
- /data/hermes-webui/.env
volumes:
- /data/hermes:/home/hermeswebui/.hermes
- /data/hermes-webui/state:/state
- /data/hermes-webui/hermes-agent:/home/hermeswebui/.hermes/hermes-agent:ro
- /data/hermes/workspace:/workspace
environment:
HERMES_HOME: /home/hermeswebui/.hermes
HERMES_WEBUI_STATE_DIR: /state
HERMES_WEBUI_HOST: 0.0.0.0
HERMES_WEBUI_PORT: "8787"
HERMES_WEBUI_CHAT_BACKEND: gateway
HERMES_WEBUI_GATEWAY_BASE_URL: http://hermes:8642
HERMES_API_URL: http://hermes:8642
HERMES_WEBUI_AGENT_DIR: /home/hermeswebui/.hermes/hermes-agent
HERMES_WEBUI_GATEWAY_USE_RUNS_API: "true"
HERMES_SKIP_CHMOD: "1"
WANTED_UID: "10000"
WANTED_GID: "10000"
networks: [frontend]
depends_on:
hermes:
condition: service_healthy
security_opt: ["no-new-privileges:true"]
healthcheck:
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8787/health', timeout=3)"]
interval: 15s
timeout: 5s
retries: 20
start_period: 45s
# Persistent VPN listener for the optional WebUI. Sharing the existing
# WireGuard network namespace avoids recreating the remote-access gateway
# merely to add one listener.
hermes-webui-vpn-proxy:
image: mike-ai/wireguard-gateway:local
container_name: mike-ai-hermes-webui-vpn-proxy
restart: unless-stopped
profiles: [hermes-webui]
network_mode: "service:wireguard-gateway"
entrypoint: [socat]
command:
- TCP-LISTEN:8787,bind=192.168.1.212,reuseaddr,fork
- TCP:hermes-webui:8787
read_only: true
tmpfs:
- /tmp:size=4m,mode=1777
cap_drop: [ALL]
security_opt: ["no-new-privileges:true"]
depends_on:
wireguard-gateway:
condition: service_healthy
hermes-webui:
condition: service_healthy
networks:
frontend:
internal: false