Build Hermes MCP patches into managed image

This commit is contained in:
Mikei386
2026-08-25 16:41:12 +02:00
parent 488518a5e9
commit ba12aaaac6
4 changed files with 17 additions and 3 deletions
+8
View File
@@ -0,0 +1,8 @@
FROM nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495
# Hermes 0.20.5 needs two narrowly scoped upstream workarounds. Apply them
# while the image is built as root; the managed runtime only verifies that
# the expected patch is present and never mutates the installed application.
COPY platform/hermes/patch-api-mcp-refresh.py /tmp/patch-api-mcp-refresh.py
RUN python /tmp/patch-api-mcp-refresh.py \
&& rm /tmp/patch-api-mcp-refresh.py
+2 -1
View File
@@ -68,7 +68,8 @@ grep -Eq '^[[:space:]]+base_url:[[:space:]]+["'\'']?http://router:8081/v1["'\'']
}
# Hermes 0.20.5 does not refresh the API agent from the live MCP registry.
# Apply the narrow, version-checked workaround before starting the gateway.
# The image build applies the narrow workaround as root. At runtime this is
# an idempotent, fail-closed verification and must never need to write files.
python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py
exec hermes gateway run