slim-shim: replace /setup with Caddy + native dashboard - #8
Merged
Merged
Conversation
Drop the 1500-line Python admin server and the hand-rolled Alpine.js SPA. Replace with: - Caddy at $PORT terminating basic_auth → reverse_proxy to the native hermes dashboard on 127.0.0.1:9119. - start.sh as a tiny supervisor: runs hermes dashboard in background, caddy in background, hermes gateway in foreground (under tini). - `hermes gateway run --replace` supersedes the manual stale-PID cleanup the old setup needed; it's also why the in-memory gateway state machine in server.py existed in the first place. Operator surface area moves to the native dashboard plus the upstream CLI: `hermes pairing`, `hermes config`, `hermes status` via railway ssh. The /setup curated channel UI is gone — channels are configured in the native dashboard's config tab. -2682 net lines.
The native dashboard's web_server enforces a Host check unless
launched with --insecure (which we don't want — it disables every
binding-related guard). Caddy's default reverse_proxy preserves the
original public Host (e.g. your-app.up.railway.app), which the
dashboard rejects with "Invalid Host header. Dashboard requests must
use the hostname the server was bound to."
`header_up Host {upstream_hostport}` rewrites Host to 127.0.0.1:9119
on the upstream hop so the dashboard sees what it expects.
X-Forwarded-Host preserves the original for any downstream code that
wants it (link generation, redirects).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
/setup\$PORTterminates basic auth and reverse-proxies to the native hermes dashboard on127.0.0.1:9119start.shbecomes a 40-line supervisor: dashboard + caddy in background,hermes gateway run --replacein foreground (under tini)Why
hermesCLI already provides everything/setupwas wrapping:hermes pairing,hermes config,hermes status,hermes dashboard. The/setupUI was a parallel implementation over the same JSON files and.env.hermes gateway run --replace(upstream) supersedes the manual stale-PID cleanup + in-memory state machine that caused the recurring "Gateway State: error" desync.Operator surface area after this PR
/(already proxied today, just no longer wrapped by/setup)railway ssh→hermes config set …, or Railway variables (no more.env-shadows-os.environinversion)railway ssh→hermes pairing list/approve/deny, or the native dashboard's pairing UIrailway logsrailway redeployor stop the gateway via SSH (hermes gateway run --replacehandles re-entry)Test plan
railway up(or switch service's deploy branch toslim-shim) and confirm the container bootsGET /healthreturns 200 without authGET /prompts for basic auth, then loads the native hermes dashboard/api/pty,/api/ws,/api/events) work through the proxy — open the embedded Chat tabLLM_MODEL+ a provider key viahermes config setover SSH; gateway starts cleanlyhermes pairing listshows the request →hermes pairing approve <code>→ bot replies--replacepath)/setupreturns 404 (it should — that route is gone)Rollback
Revert by switching the service back to
mainin Railway and redeploying. Branch is non-destructive tomain.