Render Hermes router API key safely

This commit is contained in:
Mikei386
2026-08-24 22:40:02 +02:00
parent 53f10d1d3f
commit a8ae77dbc3
2 changed files with 34 additions and 0 deletions
+15
View File
@@ -57,6 +57,21 @@ if [[ -s $HERMES_DATA_DIR/config.yaml ]] && \
"$HERMES_DATA_DIR/config.yaml.before-managed-update-$(date +%Y%m%d-%H%M%S)"
fi
install -m 0600 "$STACK_DIR/platform/hermes/config.yaml" "$HERMES_DATA_DIR/config.yaml"
# Hermes expands environment variables in some runtime paths, but model.api_key
# is persisted and reloaded literally when a client changes the model. Render
# this one managed placeholder before the configuration becomes live.
ROUTER_API_KEY="$router_key" python3 - "$HERMES_DATA_DIR/config.yaml" <<'PY'
import os
import pathlib
import sys
path = pathlib.Path(sys.argv[1])
text = path.read_text()
placeholder = "${ROUTER_API_KEY}"
if placeholder not in text:
raise SystemExit("ROUTER_API_KEY placeholder missing from managed Hermes config")
path.write_text(text.replace(placeholder, os.environ["ROUTER_API_KEY"], 1))
PY
install -m 0600 "$STACK_DIR/platform/hermes/SOUL.md" "$HERMES_DATA_DIR/SOUL.md"
chown -R 10000:10000 "$HERMES_DATA_DIR"
"$STACK_DIR/platform/hermes/install-skills.sh"