diff --git a/platform/hermes/install-hermes.sh b/platform/hermes/install-hermes.sh index 2ca2fbb..25a0949 100755 --- a/platform/hermes/install-hermes.sh +++ b/platform/hermes/install-hermes.sh @@ -57,6 +57,21 @@ if [[ -s $HERMES_DATA_DIR/config.yaml ]] && \ "$HERMES_DATA_DIR/config.yaml.before-managed-update-$(date +%Y%m%d-%H%M%S)" fi install -m 0600 "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml" +# Hermes expands environment variables in some runtime paths, but model.api_key +# is persisted and reloaded literally when a client changes the model. Render +# this one managed placeholder before the configuration becomes live. +ROUTER_API_KEY="$router_key" python3 - "$HERMES_DATA_DIR/config.yaml" <<'PY' +import os +import pathlib +import sys + +path = pathlib.Path(sys.argv[1]) +text = path.read_text() +placeholder = "${ROUTER_API_KEY}" +if placeholder not in text: + raise SystemExit("ROUTER_API_KEY placeholder missing from managed Hermes config") +path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1)) +PY install -m 0600 "$STACK_DIR/platform/hermes/SOUL.md" "$HERMES_DATA_DIR/SOUL.md" chown -R 10000:10000 "$HERMES_DATA_DIR" "$STACK_DIR/platform/hermes/install-skills.sh" diff --git a/platform/hermes/install-profiles.sh b/platform/hermes/install-profiles.sh index 88085ba..2fb6620 100755 --- a/platform/hermes/install-profiles.sh +++ b/platform/hermes/install-profiles.sh @@ -2,6 +2,8 @@ set -Eeuo pipefail HERMES_CONTAINER=${HERMES_CONTAINER:-mike-ai-hermes} +SECRETS_DIR=${SECRETS_DIR:-/etc/mike-ai} +HERMES_DATA_DIR=${HERMES_DATA_DIR:-/data/hermes} die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; } docker inspect "$HERMES_CONTAINER" >/dev/null 2>&1 || \ @@ -39,6 +41,23 @@ create_profile ultra qwen-ultra 262144 \ create_profile uncensored qwen-uncensored 80000 \ "Unzensiertes Qwen3.8-27B-Profil mit 80K Kontext fuer spezielle Anfragen." +# Existing profiles may predate managed secret rendering and therefore contain +# the literal ${ROUTER_API_KEY}. Repair only that exact placeholder; never log +# or commit the secret itself. +[[ -s $SECRETS_DIR/router-api-key ]] || die "Router-API-Key fehlt." +router_key=$(<"$SECRETS_DIR/router-api-key") +ROUTER_API_KEY="$router_key" HERMES_DATA_DIR="$HERMES_DATA_DIR" python3 <<'PY' +import os +import pathlib + +root = pathlib.Path(os.environ["HERMES_DATA_DIR"]) / "profiles" +placeholder = "${ROUTER_API_KEY}" +for path in sorted(root.glob("*/config.yaml")): + text = path.read_text() + if placeholder in text: + path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1)) +PY + "${STACK_DIR:-/opt/mike-ai/stack}/platform/hermes/install-skills.sh" docker exec "$HERMES_CONTAINER" hermes profile list printf 'HERMES_PROFILES_OK\n'