Skip to content

Upgrade to Hermes 0.16: pinned releases + bump-PR workflow, drop CF Tunnel for native gated auth - #14

Merged
tomfuertes merged 2 commits into
mainfrom
upgrade-hermes-0.16
Jun 6, 2026
Merged

tomfuertes merged 2 commits into
mainfrom
upgrade-hermes-0.16

Conversation

@tomfuertes

@tomfuertes tomfuertes commented Jun 6, 2026 •

Copy link
Copy Markdown
Contributor

Why

Deployed image is Hermes 0.14.0 (built May 17 against v2026.5.16); latest is 0.16.0 (v2026.6.5). Two structural problems fixed alongside the upgrade:

  1. Resolve-latest-at-build-time would have crash-looped prod: 0.16 removed --tui from hermes dashboard (feat(dashboard): always enable embedded chat; remove dashboard --tui flag NousResearch/hermes-agent#38591) and start.sh passed it.
  2. The Cloudflare Tunnel layer is legacy from the custom-admin era (pre-slim-shim: replace /setup with Caddy + native dashboard #8). 0.16's dashboard ships fail-closed gated auth that makes the tunnel unnecessary.

What

Commit 1 — pin + bump workflow (7bbb3d4)

  • Pin ARG HERMES_REF=v2026.6.5; drop the ADD releases/latest cache-bust
  • start.sh: remove --tui; log hermes --version at boot
  • hermes-bump.yml: daily release check → draft PR with upstream release notes

Commit 2 — drop the tunnel (041d928)

  • Remove cloudflared from the image; remove TUNNEL_TOKEN
  • Dashboard binds 0.0.0.0:$PORT without --insecure → Hermes' fail-closed auth gate engages: login page, scrypt-verified credentials, 10/min per-IP rate limit, HMAC session cookies
  • proxy_headers flips on automatically in gated mode (verified in v2026.6.5 source) — Secure cookies + WS origin checks work behind Railway's TLS edge
  • start.sh fails fast if HERMES_DASHBOARD_BASIC_AUTH_USERNAME / _PASSWORD[_HASH] are missing (gate would otherwise lock everyone out silently)
  • README/.env.example rewritten; custom-admin-era feature copy replaced

Pre-merge Railway setup (or first boot crash-loops by design)

In Railway → Variables:

  • HERMES_DASHBOARD_BASIC_AUTH_USERNAME
  • HERMES_DASHBOARD_BASIC_AUTH_PASSWORD (or ..._PASSWORD_HASH)
  • HERMES_DASHBOARD_BASIC_AUTH_SECRET (openssl rand -base64 32)
  • Delete TUNNEL_TOKEN

In Railway → Settings → Networking: generate a public domain for the service.

Post-merge

  • Enable Settings → Actions → General → Allow GitHub Actions to create and approve pull requests (for the bump workflow)
  • Optional Cloudflare cleanup: delete the Access application, the hermes-railway tunnel, and any leftover hermes. CNAME

Verification

  • actionlint + shellcheck clean
  • v2026.6.5 source verified: dashboard flags (--tui gone), gateway run --replace intact, web dist at hermes_cli/web_dist/, should_require_auth() truth table, basic-auth env vars, login rate limiter, cookie Secure-behind-proxy handling

- Pin ARG HERMES_REF=v2026.6.5 (0.16.0); drop the resolve-latest ADD trick
- start.sh: remove dashboard --tui (flag removed upstream in 0.16, #38591 —
  unrecognized arg would crash-loop the container); log hermes --version at boot
- Add .github/workflows/hermes-bump.yml: daily release check that opens a
  draft PR with upstream release notes when a new tag lands
- README: document the upgrade flow
0.16's dashboard auth makes the tunnel layer unnecessary:
- Non-loopback bind without --insecure engages the fail-closed auth gate
  (login page, scrypt verify, 10/min per-IP rate limit, HMAC sessions)
- uvicorn proxy_headers flips on in gated mode, so Secure cookies and WS
  origin checks work behind Railway's TLS edge
- Basic-auth provider configured entirely via env vars (Railway Variables)

Changes:
- Dockerfile: remove cloudflared install
- start.sh: drop TUNNEL_TOKEN + cloudflared; bind dashboard 0.0.0.0:$PORT;
  fail fast on missing auth vars (gate would otherwise lock everyone out)
- .env.example: TUNNEL_TOKEN -> HERMES_DASHBOARD_BASIC_AUTH_* trio; document
  Railway-Variables-vs-dashboard key precedence (volume .env wins)
- README: rewrite for the tunnel-less architecture; replace custom-admin-era
  feature copy (one-page /setup, stat cards) with the actual 0.16 dashboard
@tomfuertes tomfuertes changed the title Pin Hermes releases + daily bump-PR workflow; upgrade to 0.16 Upgrade to Hermes 0.16: pinned releases + bump-PR workflow, drop CF Tunnel for native gated auth Jun 6, 2026
@tomfuertes
tomfuertes marked this pull request as ready for review June 6, 2026 17:01
@tomfuertes
tomfuertes merged commit aa363e7 into main Jun 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant