Build Hermes MCP patches into managed image
This commit is contained in:
+4
-1
@@ -793,7 +793,10 @@ services:
|
|||||||
security_opt: ["no-new-privileges:true"]
|
security_opt: ["no-new-privileges:true"]
|
||||||
|
|
||||||
hermes:
|
hermes:
|
||||||
image: ${HERMES_IMAGE:-nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495}
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: platform/hermes/Dockerfile
|
||||||
|
image: ${HERMES_IMAGE:-mike-ai/hermes-agent:0.20.5-mcpfix1}
|
||||||
container_name: mike-ai-hermes
|
container_name: mike-ai-hermes
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
command: [/usr/local/bin/start-hermes-managed]
|
command: [/usr/local/bin/start-hermes-managed]
|
||||||
|
|||||||
@@ -122,7 +122,9 @@ Der Router übernimmt:
|
|||||||
- Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das
|
- Bei einer entfernten Hermes-Desktop-App läuft Audio bewusst über das
|
||||||
Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im
|
Hermes-Backend (`voice.client_direct: false`), weil Router und TTS nur im
|
||||||
internen Docker-Netz erreichbar sind.
|
internen Docker-Netz erreichbar sind.
|
||||||
- Version: 0.20.5, offizielles Image per OCI-Digest gepinnt
|
- Version: 0.20.5, lokales abgeleitetes Image
|
||||||
|
`mike-ai/hermes-agent:0.20.5-mcpfix1`; dessen Basis ist das offizielle
|
||||||
|
Hermes-Image per OCI-Digest gepinnt.
|
||||||
- Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale
|
- Die gepinnte Version trägt beim Containerstart zwei eng geprüfte lokale
|
||||||
Upstream-Workarounds: API-Agenten übernehmen den live registrierten
|
Upstream-Workarounds: API-Agenten übernehmen den live registrierten
|
||||||
MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch
|
MCP-Katalog (Hermes-Issue 69746), und `tool_search` veröffentlicht auch
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
FROM nousresearch/hermes-agent@sha256:143bdb9086bb2db645346179f11091e621ef6b7f4f9e5049ae7454bfeb3a0495
|
||||||
|
|
||||||
|
# Hermes 0.20.5 needs two narrowly scoped upstream workarounds. Apply them
|
||||||
|
# while the image is built as root; the managed runtime only verifies that
|
||||||
|
# the expected patch is present and never mutates the installed application.
|
||||||
|
COPY platform/hermes/patch-api-mcp-refresh.py /tmp/patch-api-mcp-refresh.py
|
||||||
|
RUN python /tmp/patch-api-mcp-refresh.py \
|
||||||
|
&& rm /tmp/patch-api-mcp-refresh.py
|
||||||
@@ -68,7 +68,8 @@ grep -Eq '^[[:space:]]+base_url:[[:space:]]+["'\'']?http://router:8081/v1["'\'']
|
|||||||
}
|
}
|
||||||
|
|
||||||
# Hermes 0.20.5 does not refresh the API agent from the live MCP registry.
|
# Hermes 0.20.5 does not refresh the API agent from the live MCP registry.
|
||||||
# Apply the narrow, version-checked workaround before starting the gateway.
|
# The image build applies the narrow workaround as root. At runtime this is
|
||||||
|
# an idempotent, fail-closed verification and must never need to write files.
|
||||||
python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py
|
python /usr/local/lib/mike-ai/patch-api-mcp-refresh.py
|
||||||
|
|
||||||
exec hermes gateway run
|
exec hermes gateway run
|
||||||
|
|||||||
Reference in New Issue
Block a user