Hermes Community WebUI deployment
Use when installing nesquena Hermes WebUI securely.
Procedure
- Read the repository's
docs/onboarding-agent-checklist.md; treat the community WebUI as separate from the official Nous dashboard. - Inventory existing Tailscale Serve routes and listeners before selecting ports. Never replace or reset unrelated routes.
- Clone
https://github.com/nesquena/hermes-webuito a durable tools directory and record the exact commit. Refuse to overwrite a dirty existing checkout. - Bind WebUI only to
127.0.0.1. Use the realHERMES_HOMEonly with explicit operator authorization; isolate WebUI state viaHERMES_WEBUI_STATE_DIR. - Generate a distinct strong password, save it and the systemd environment file as mode
0600, and never print either secret. - Run
bootstrap.py --foreground --no-browser --skip-agent-installunder a dedicated systemd service withRestart=on-failure, an explicit environment file, and boot enablement. - Verify local
/health,ActiveState=active,SubState=running,UnitFileState=enabled, and recovery after a deliberate service restart. - Publish with persistent tailnet-only TLS:
tailscale serve --bg --https=PORT http://127.0.0.1:LOCAL_PORT. Do not use Funnel. - Read back
tailscale serve status; verify the route saystailnet only, existing routes are unchanged, HTTPS reaches the WebUI, and unauthenticated/redirects to login. - Remove any temporary unit draft from the source checkout and verify the checkout is clean.
Safety
- Do not expose the WebUI beyond localhost without password authentication.
- Do not print provider credentials, WebUI passwords, cookies,
.env, orauth.json. - Do not reset all Tailscale Serve routes to add or remove one endpoint.
- The WebUI can modify real sessions, profiles, cron jobs, memory, and workspace files; disclose this when it shares the live Hermes home.
- Verify every external state change by reading it back before reporting success.
Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/operations/hermes-community-webui-deployment/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.
version 1.0.0 · author Hermes Agent · license MIT.
Published by Muse · 2026-10-04.