Upgrade to Hermes 0.16: pinned releases + bump-PR workflow, drop CF Tunnel for native gated auth - #14
Merged
Merged
Conversation
- Pin ARG HERMES_REF=v2026.6.5 (0.16.0); drop the resolve-latest ADD trick - start.sh: remove dashboard --tui (flag removed upstream in 0.16, #38591 — unrecognized arg would crash-loop the container); log hermes --version at boot - Add .github/workflows/hermes-bump.yml: daily release check that opens a draft PR with upstream release notes when a new tag lands - README: document the upgrade flow
0.16's dashboard auth makes the tunnel layer unnecessary: - Non-loopback bind without --insecure engages the fail-closed auth gate (login page, scrypt verify, 10/min per-IP rate limit, HMAC sessions) - uvicorn proxy_headers flips on in gated mode, so Secure cookies and WS origin checks work behind Railway's TLS edge - Basic-auth provider configured entirely via env vars (Railway Variables) Changes: - Dockerfile: remove cloudflared install - start.sh: drop TUNNEL_TOKEN + cloudflared; bind dashboard 0.0.0.0:$PORT; fail fast on missing auth vars (gate would otherwise lock everyone out) - .env.example: TUNNEL_TOKEN -> HERMES_DASHBOARD_BASIC_AUTH_* trio; document Railway-Variables-vs-dashboard key precedence (volume .env wins) - README: rewrite for the tunnel-less architecture; replace custom-admin-era feature copy (one-page /setup, stat cards) with the actual 0.16 dashboard
tomfuertes
marked this pull request as ready for review
June 6, 2026 17:01
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Deployed image is Hermes 0.14.0 (built May 17 against
v2026.5.16); latest is 0.16.0 (v2026.6.5). Two structural problems fixed alongside the upgrade:--tuifromhermes dashboard(feat(dashboard): always enable embedded chat; remove dashboard --tui flag NousResearch/hermes-agent#38591) andstart.shpassed it.What
Commit 1 — pin + bump workflow (
7bbb3d4)ARG HERMES_REF=v2026.6.5; drop theADD releases/latestcache-buststart.sh: remove--tui; loghermes --versionat boothermes-bump.yml: daily release check → draft PR with upstream release notesCommit 2 — drop the tunnel (
041d928)TUNNEL_TOKEN0.0.0.0:$PORTwithout--insecure→ Hermes' fail-closed auth gate engages: login page, scrypt-verified credentials, 10/min per-IP rate limit, HMAC session cookiesproxy_headersflips on automatically in gated mode (verified in v2026.6.5 source) —Securecookies + WS origin checks work behind Railway's TLS edgestart.shfails fast ifHERMES_DASHBOARD_BASIC_AUTH_USERNAME/_PASSWORD[_HASH]are missing (gate would otherwise lock everyone out silently)Pre-merge Railway setup (or first boot crash-loops by design)
In Railway → Variables:
HERMES_DASHBOARD_BASIC_AUTH_USERNAMEHERMES_DASHBOARD_BASIC_AUTH_PASSWORD(or..._PASSWORD_HASH)HERMES_DASHBOARD_BASIC_AUTH_SECRET(openssl rand -base64 32)TUNNEL_TOKENIn Railway → Settings → Networking: generate a public domain for the service.
Post-merge
hermes-railwaytunnel, and any leftoverhermes.CNAMEVerification
actionlint+shellcheckcleandashboardflags (--tuigone),gateway run --replaceintact, web dist athermes_cli/web_dist/,should_require_auth()truth table, basic-auth env vars, login rate limiter, cookieSecure-behind-proxy handling