Build Hermes MCP patches into managed image

This commit is contained in:
Mikei386
2026-08-25 16:41:12 +02:00
parent 488518a5e9
commit ba12aaaac6
4 changed files with 17 additions and 3 deletions
+4 -1
View File
@@ -793,7 +793,10 @@ services:
security_opt: ["no-new-privileges:true"] security_opt: ["no-new-privileges:true"]
hermes: hermes:
image: ${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495} build:
context: .
dockerfile: platform/hermes/Dockerfile
image: ${HERMES_IMAGE:-mike-ai/hermes-agent:0.20.5-mcpfix1}
container_name: mike-ai-hermes container_name: mike-ai-hermes
restart: unless-stopped restart: unless-stopped
command: [/usr/local/bin/start-hermes-managed] command: [/usr/local/bin/start-hermes-managed]
+3 -1
View File
@@ -122,7 +122,9 @@ Der Router übernimmt:
- Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das - Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das
Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im
internen Docker-Netz erreichbar sind. internen Docker-Netz erreichbar sind.
- Version: 0.20.5, offizielles Image per OCI-Digest gepinnt - Version: 0.20.5, lokales abgeleitetes Image
`mike-ai/hermes-agent:0.20.5-mcpfix1`; dessen Basis ist das offizielle
Hermes-Image per OCI-Digest gepinnt.
- Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale - Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale
Upstream-Workarounds: API-Agenten übernehmen den live registrierten Upstream-Workarounds: API-Agenten übernehmen den live registrierten
MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch
+8
View File
@@ -0,0 +1,8 @@
FROM nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495
# Hermes 0.20.5 needs two narrowly scoped upstream workarounds. Apply them
# while the image is built as root; the managed runtime only verifies that
# the expected patch is present and never mutates the installed application.
COPY platform/hermes/patch-api-mcp-refresh.py /tmp/patch-api-mcp-refresh.py
RUN python /tmp/patch-api-mcp-refresh.py \
&& rm /tmp/patch-api-mcp-refresh.py
+2 -1
View File
@@ -68,7 +68,8 @@ grep -Eq '^[[:space:]]+base_url:[[:space:]]+["'\'']?http://router:8081/v1["'\'']
} }
# Hermes 0.20.5 does not refresh the API agent from the live MCP registry. # Hermes 0.20.5 does not refresh the API agent from the live MCP registry.
# Apply the narrow, version-checked workaround before starting the gateway. # The image build applies the narrow workaround as root. At runtime this is
# an idempotent, fail-closed verification and must never need to write files.
python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py
exec hermes gateway run exec hermes gateway run