diff --git a/compose.yaml b/compose.yaml index 9570bd3..9fee75e 100644 --- a/compose.yaml +++ b/compose.yaml @@ -793,7 +793,10 @@ services: security_opt: ["no-new-privileges:true"] hermes: - image: ${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495} + build: + context: . + dockerfile: platform/hermes/Dockerfile + image: ${HERMES_IMAGE:-mike-ai/hermes-agent:0.20.5-mcpfix1} container_name: mike-ai-hermes restart: unless-stopped command: [/usr/local/bin/start-hermes-managed] diff --git a/docs/CURRENT_REFERENCE.md b/docs/CURRENT_REFERENCE.md index dd30be8..9a5cee3 100644 --- a/docs/CURRENT_REFERENCE.md +++ b/docs/CURRENT_REFERENCE.md @@ -122,7 +122,9 @@ Der Router übernimmt: - Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im internen Docker-Netz erreichbar sind. -- Version: 0.20.5, offizielles Image per OCI-Digest gepinnt +- Version: 0.20.5, lokales abgeleitetes Image + `mike-ai/hermes-agent:0.20.5-mcpfix1`; dessen Basis ist das offizielle + Hermes-Image per OCI-Digest gepinnt. - Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale Upstream-Workarounds: API-Agenten übernehmen den live registrierten MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch diff --git a/platform/hermes/Dockerfile b/platform/hermes/Dockerfile new file mode 100644 index 0000000..124c7d7 --- /dev/null +++ b/platform/hermes/Dockerfile @@ -0,0 +1,8 @@ +FROM nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495 + +# Hermes 0.20.5 needs two narrowly scoped upstream workarounds. Apply them +# while the image is built as root; the managed runtime only verifies that +# the expected patch is present and never mutates the installed application. +COPY platform/hermes/patch-api-mcp-refresh.py /tmp/patch-api-mcp-refresh.py +RUN python /tmp/patch-api-mcp-refresh.py \ + && rm /tmp/patch-api-mcp-refresh.py diff --git a/platform/hermes/start-hermes-managed.sh b/platform/hermes/start-hermes-managed.sh index 1d4c638..8e1a752 100755 --- a/platform/hermes/start-hermes-managed.sh +++ b/platform/hermes/start-hermes-managed.sh @@ -68,7 +68,8 @@ grep -Eq '^[[:space:]]+base_url:[[:space:]]+["'\'']?http://router:8081/v1["'\''] } # Hermes 0.20.5 does not refresh the API agent from the live MCP registry. -# Apply the narrow, version-checked workaround before starting the gateway. +# The image build applies the narrow workaround as root. At runtime this is +# an idempotent, fail-closed verification and must never need to write files. python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py exec hermes gateway run