Build Hermes MCP patches into managed image
This commit is contained in:
+4
-1
@@ -793,7 +793,10 @@ services:
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
|
||||
hermes:
|
||||
image: ${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495}
|
||||
build:
|
||||
context: .
|
||||
dockerfile: platform/hermes/Dockerfile
|
||||
image: ${HERMES_IMAGE:-mike-ai/hermes-agent:0.20.5-mcpfix1}
|
||||
container_name: mike-ai-hermes
|
||||
restart: unless-stopped
|
||||
command: [/usr/local/bin/start-hermes-managed]
|
||||
|
||||
@@ -122,7 +122,9 @@ Der Router übernimmt:
|
||||
- Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das
|
||||
Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im
|
||||
internen Docker-Netz erreichbar sind.
|
||||
- Version: 0.20.5, offizielles Image per OCI-Digest gepinnt
|
||||
- Version: 0.20.5, lokales abgeleitetes Image
|
||||
`mike-ai/hermes-agent:0.20.5-mcpfix1`; dessen Basis ist das offizielle
|
||||
Hermes-Image per OCI-Digest gepinnt.
|
||||
- Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale
|
||||
Upstream-Workarounds: API-Agenten übernehmen den live registrierten
|
||||
MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
FROM nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495
|
||||
|
||||
# Hermes 0.20.5 needs two narrowly scoped upstream workarounds. Apply them
|
||||
# while the image is built as root; the managed runtime only verifies that
|
||||
# the expected patch is present and never mutates the installed application.
|
||||
COPY platform/hermes/patch-api-mcp-refresh.py /tmp/patch-api-mcp-refresh.py
|
||||
RUN python /tmp/patch-api-mcp-refresh.py \
|
||||
&& rm /tmp/patch-api-mcp-refresh.py
|
||||
@@ -68,7 +68,8 @@ grep -Eq '^[[:space:]]+base_url:[[:space:]]+["'\'']?http://router:8081/v1["'\'']
|
||||
}
|
||||
|
||||
# Hermes 0.20.5 does not refresh the API agent from the live MCP registry.
|
||||
# Apply the narrow, version-checked workaround before starting the gateway.
|
||||
# The image build applies the narrow workaround as root. At runtime this is
|
||||
# an idempotent, fail-closed verification and must never need to write files.
|
||||
python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py
|
||||
|
||||
exec hermes gateway run
|
||||
|
||||
Reference in New Issue
Block a user