docs(wiki): sarah-hermes VM107 page + ip-map row + log entry
This commit is contained in:
@@ -36,6 +36,7 @@
|
||||
- [[systems/frigate]] — NVR v0.18 CT151, Kameras, MQTT, HA Automation
|
||||
- [[systems/homeassistant]] — HAOS, MQTT, Automations, Notify
|
||||
- [[systems/paperless]] — Dokumentenmgmt, OIDC, OCR via noris AI
|
||||
- [[systems/sarah-hermes]] — VM107, zweites Hermes für Sarah (WebUI :8787, TG geplant)
|
||||
|
||||
## Concepts
|
||||
- [[concepts/network-architecture]] — 10.0.X.Y Schema, VLANs
|
||||
|
||||
@@ -1,5 +1,14 @@
|
||||
# Memory Log
|
||||
|
||||
## [2026-09-30] deployment | Sarah-Hermes VM107 — zweite Hermes-Instanz live
|
||||
- VM107 (n5pro, 10.0.30.66) via Tofu epic-8 deployed; Docker+UFW via Ansible (epic-7-Stil)
|
||||
- hermes-webui Single-Container :8787, LAN-only, Password-Auth; Secrets in 1P (sarah-hermes-webui, sarah-hermes-noris-key)
|
||||
- E2E verifiziert: Login 200, Agent-Antwort via vllm/release/glm-5-2 @ ai.noris.de
|
||||
- PITFALL: hermes-agent pyproject pinnt Core-Deps hinter python_version>='3.14'-Markers → auf Python 3.12 installiert `pip install -e .` NULL Deps ("AIAgent not available"). Fix: manuelle Pin-Installation + Missing-Import-Loop bis `import run_agent`
|
||||
- Backup: täglich 23:00 Job backup-2e8a34e3-66cb (all=1) deckt VM107; manueller Verify TASK OK 48s
|
||||
- Wiki: systems/sarah-hermes.md, ip-map.md erweitert; iac-homelab commits 0d5f017/1ce4816
|
||||
- OFFEN: Telegram-Bot blockiert auf BotFather-Token (Sarah/Dominik)
|
||||
|
||||
## [2026-09-29] bug-fix | KubeAPIErrorBudgetBurn — Ceph-CSI resize loop from missing controller-expand-secret
|
||||
- Root Cause: `ceph-flash` + `ceph-hdd-replica` StorageClasses created manually WITHOUT `controller-expand-secret-name/namespace` params
|
||||
- CNPG PVC resize (50→100Gi, 10→20Gi) triggered infinite CSI resizer retry loop ("provided secret is empty") → API server write pressure → etcd DeadlineExceeded → Handler timeout 5xx
|
||||
|
||||
+2
-1
@@ -3,7 +3,7 @@ title: IP-Map (Quick Reference)
|
||||
category: reference
|
||||
tags: [ip, network, reference, quick-lookup]
|
||||
created: "2026-07-24"
|
||||
modified: "2026-09-26"
|
||||
modified: "2026-09-30"
|
||||
---
|
||||
|
||||
# IP-Map
|
||||
@@ -47,6 +47,7 @@ modified: "2026-09-26"
|
||||
## Infrastructure VMs (10.0.30.x)
|
||||
| IP | Host | Service |
|
||||
|----|------|---------|
|
||||
| 10.0.30.66 | sarah-hermes (VM107, n5pro) | Sarahs Hermes: WebUI :8787 (LAN-only, pw) + TG-Bot (geplant) |
|
||||
| 10.0.30.99 | CT111 | Immich (n5pro), Migration zu K8s geplant |
|
||||
| 10.0.30.100 | ubuntu | Physischer Ubuntu-Node (Ceph OSDs, ZFS pool01_n2_redundant) |
|
||||
| 10.0.30.105 | — | ~~Gitea~~ CT108 GESTOPPT 2026-09-17 (Archive: /home/debian/git-archive/ct108-final/) |
|
||||
|
||||
@@ -0,0 +1,74 @@
|
||||
---
|
||||
title: Sarah-Hermes (VM107)
|
||||
category: systems
|
||||
tags: [hermes, webui, vm, sarah, telegram, backup]
|
||||
created: "2026-09-30"
|
||||
modified: "2026-09-30"
|
||||
related: [systems/rke2-kubernetes, reference/ip-map, systems/noris-ai]
|
||||
---
|
||||
|
||||
# Sarah-Hermes (VM107)
|
||||
|
||||
Zweite, vollständig isolierte Hermes-Instanz für Sarah (Allround-Assistentin:
|
||||
Erinnerungen, Planung, Smalltalk). Getrennte Memories/Sessions/Skills/Keys von
|
||||
den 5 Owner-Profilen.
|
||||
|
||||
## Eckdaten
|
||||
|
||||
| Attribut | Wert |
|
||||
|----------|------|
|
||||
| VM-ID | 107 (auto-allokiert) |
|
||||
| Node | n5pro (Template 9000 debian-12-cloudinit) |
|
||||
| IP | 10.0.30.66/24 (static via DHCP reservation) |
|
||||
| Specs | 2 vCPU / 4 GB RAM / 32 GB Disk (vm_disks/RBD) |
|
||||
| Access | SSH `debian@10.0.30.66` mit `~/.ssh/id_ed25519_cloudinit` |
|
||||
| Tofu | `iac-homelab/epic-8-sarah-hermes/tofu/` |
|
||||
| Ansible | `iac-homelab/epic-8-sarah-hermes/ansible/` |
|
||||
| Plan | `iac-homelab/docs/plans/2026-09-30-sarah-hermes-vm.md` |
|
||||
|
||||
## Stack
|
||||
|
||||
- **hermes-webui** (ghcr.io/nesquena/hermes-webui:latest), Single-Container,
|
||||
Port 8787 (0.0.0.0 gebunden, UFW erlaubt nur LAN), Password-Auth.
|
||||
Compose: `/home/debian/hermes-webui/docker-compose.yml` auf der VM.
|
||||
- **Agent-Runtime:** nousresearch/hermes-agent geklont nach
|
||||
`~/.hermes/hermes-agent` auf der VM; installiert in `/app/venv` im Container
|
||||
(editable). **Wichtig:** Core-Deps im pyproject sind hinter
|
||||
`python_version >= '3.14'`-Markern gepinnt → auf Python 3.12 installiert
|
||||
`-e .` NULL Deps. Manual-Dep-Bootstrapping nötig (siehe Pitfalls).
|
||||
- **LLM:** noris-Provider (`https://ai.noris.de/v1`, Default-Modell
|
||||
`vllm/release/glm-5-2`), Key via `HERMES_CUSTOM_NORIS_API_KEY` aus
|
||||
`.env` (Compose mapped explizit in den Container).
|
||||
- **Telegram:** geplant (blockiert auf BotFather-Token von Sarah/Dominik).
|
||||
Bei Aktivierung: `gateway.telegram_enabled: true` + Token in `.env`;
|
||||
Webhook/API-Server-Ports bleiben disabled (Konfliktvermeidung).
|
||||
|
||||
## Secrets (1Password, Vault: Hermes)
|
||||
|
||||
- `sarah-hermes-webui` → HERMES_WEBUI_PASSWORD
|
||||
- `sarah-hermes-noris-key` → HERMES_CUSTOM_NORIS_API_KEY
|
||||
|
||||
## Backup
|
||||
|
||||
- Daily vzdump-Job `backup-2e8a34e3-66cb` (23:00, `all=1`, exclude 301,302,310,311,137,147,501)
|
||||
→ **deckt VM107 ab** (Storage `noris_v4` = PBS Datastore `noris` @ 10.0.30.119).
|
||||
- Manueller Verify-Lauf am 30.09.: TASK OK in 48s (inkrementell, 88% reuse).
|
||||
- Offsite: folgt dem regulären `push-offsite` Sync-Job (Pull↔Push-Korrektur
|
||||
vom 19.09.).
|
||||
|
||||
## Known Issues / Pitfalls
|
||||
|
||||
1. **Python-Version-Mismatch:** hermes-agent pyproject pins Core-Deps an
|
||||
`python_version >= '3.14'`; WebUI-Container läuft auf 3.12 → `-e .`
|
||||
installiert keine Deps. Fix: manuell `pip install` der gepinschten Pakete
|
||||
+ iterativer Missing-Import-Loop bis `import run_agent` klappt.
|
||||
2. **hermes update Ownership-Konflikt:** `hermes update`-Completion beschwert
|
||||
sich über uid 0 vs. uid 1000 auf `/app/venv/bin/hermes-acp`. Kosmetisch,
|
||||
Betriebsbetrieb unbeeinträchtigt. Fix-Idee: `chown` im Entry-Point.
|
||||
3. **telegram-bridge Notify-Target defekt** (seit 19.09., Connection refused):
|
||||
betrifft vzdump-Notifications clusterweit, nicht nur VM107. Separater Fix.
|
||||
|
||||
## Verification History
|
||||
|
||||
- 2026-09-30: Deploy + E2E-Test (Login 200, Agent-Antwort "HALLO" via glm-5-2).
|
||||
- 2026-09-30: Manueller vzdump → TASK OK (48s, inkrementell).
|
||||
Reference in New Issue
Block a user