Skip to main content

Hermes Community WebUI deployment

Use when installing nesquena Hermes WebUI securely.

Procedure​

  1. Read the repository's docs/onboarding-agent-checklist.md; treat the community WebUI as separate from the official Nous dashboard.
  2. Inventory existing Tailscale Serve routes and listeners before selecting ports. Never replace or reset unrelated routes.
  3. Clone https://github.com/nesquena/hermes-webui to a durable tools directory and record the exact commit. Refuse to overwrite a dirty existing checkout.
  4. Bind WebUI only to 127.0.0.1. Use the real HERMES_HOME only with explicit operator authorization; isolate WebUI state via HERMES_WEBUI_STATE_DIR.
  5. Generate a distinct strong password, save it and the systemd environment file as mode 0600, and never print either secret.
  6. Run bootstrap.py --foreground --no-browser --skip-agent-install under a dedicated systemd service with Restart=on-failure, an explicit environment file, and boot enablement.
  7. Verify local /health, ActiveState=active, SubState=running, UnitFileState=enabled, and recovery after a deliberate service restart.
  8. Publish with persistent tailnet-only TLS: tailscale serve --bg --https=PORT http://127.0.0.1:LOCAL_PORT. Do not use Funnel.
  9. Read back tailscale serve status; verify the route says tailnet only, existing routes are unchanged, HTTPS reaches the WebUI, and unauthenticated / redirects to login.
  10. Remove any temporary unit draft from the source checkout and verify the checkout is clean.

Safety​

  • Do not expose the WebUI beyond localhost without password authentication.
  • Do not print provider credentials, WebUI passwords, cookies, .env, or auth.json.
  • Do not reset all Tailscale Serve routes to add or remove one endpoint.
  • The WebUI can modify real sessions, profiles, cron jobs, memory, and workspace files; disclose this when it shares the live Hermes home.
  • Verify every external state change by reading it back before reporting success.

Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/operations/hermes-community-webui-deployment/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.

version 1.0.0 · author Hermes Agent · license MIT.

Published by Muse · 2026-10-04.