75 lines
3.2 KiB
Markdown
75 lines
3.2 KiB
Markdown
---
|
|
title: Sarah-Hermes (VM107)
|
|
category: systems
|
|
tags: [hermes, webui, vm, sarah, telegram, backup]
|
|
created: "2026-09-30"
|
|
modified: "2026-09-30"
|
|
related: [systems/rke2-kubernetes, reference/ip-map, systems/noris-ai]
|
|
---
|
|
|
|
# Sarah-Hermes (VM107)
|
|
|
|
Zweite, vollständig isolierte Hermes-Instanz für Sarah (Allround-Assistentin:
|
|
Erinnerungen, Planung, Smalltalk). Getrennte Memories/Sessions/Skills/Keys von
|
|
den 5 Owner-Profilen.
|
|
|
|
## Eckdaten
|
|
|
|
| Attribut | Wert |
|
|
|----------|------|
|
|
| VM-ID | 107 (auto-allokiert) |
|
|
| Node | n5pro (Template 9000 debian-12-cloudinit) |
|
|
| IP | 10.0.30.66/24 (static via DHCP reservation) |
|
|
| Specs | 2 vCPU / 4 GB RAM / 32 GB Disk (vm_disks/RBD) |
|
|
| Access | SSH `debian@10.0.30.66` mit `~/.ssh/id_ed25519_cloudinit` |
|
|
| Tofu | `iac-homelab/epic-8-sarah-hermes/tofu/` |
|
|
| Ansible | `iac-homelab/epic-8-sarah-hermes/ansible/` |
|
|
| Plan | `iac-homelab/docs/plans/2026-09-30-sarah-hermes-vm.md` |
|
|
|
|
## Stack
|
|
|
|
- **hermes-webui** (ghcr.io/nesquena/hermes-webui:latest), Single-Container,
|
|
Port 8787 (0.0.0.0 gebunden, UFW erlaubt nur LAN), Password-Auth.
|
|
Compose: `/home/debian/hermes-webui/docker-compose.yml` auf der VM.
|
|
- **Agent-Runtime:** nousresearch/hermes-agent geklont nach
|
|
`~/.hermes/hermes-agent` auf der VM; installiert in `/app/venv` im Container
|
|
(editable). **Wichtig:** Core-Deps im pyproject sind hinter
|
|
`python_version >= '3.14'`-Markern gepinnt → auf Python 3.12 installiert
|
|
`-e .` NULL Deps. Manual-Dep-Bootstrapping nötig (siehe Pitfalls).
|
|
- **LLM:** noris-Provider (`https://ai.noris.de/v1`, Default-Modell
|
|
`vllm/release/glm-5-2`), Key via `HERMES_CUSTOM_NORIS_API_KEY` aus
|
|
`.env` (Compose mapped explizit in den Container).
|
|
- **Telegram:** geplant (blockiert auf BotFather-Token von Sarah/Dominik).
|
|
Bei Aktivierung: `gateway.telegram_enabled: true` + Token in `.env`;
|
|
Webhook/API-Server-Ports bleiben disabled (Konfliktvermeidung).
|
|
|
|
## Secrets (1Password, Vault: Hermes)
|
|
|
|
- `sarah-hermes-webui` → HERMES_WEBUI_PASSWORD
|
|
- `sarah-hermes-noris-key` → HERMES_CUSTOM_NORIS_API_KEY
|
|
|
|
## Backup
|
|
|
|
- Daily vzdump-Job `backup-2e8a34e3-66cb` (23:00, `all=1`, exclude 301,302,310,311,137,147,501)
|
|
→ **deckt VM107 ab** (Storage `noris_v4` = PBS Datastore `noris` @ 10.0.30.119).
|
|
- Manueller Verify-Lauf am 30.09.: TASK OK in 48s (inkrementell, 88% reuse).
|
|
- Offsite: folgt dem regulären `push-offsite` Sync-Job (Pull↔Push-Korrektur
|
|
vom 19.09.).
|
|
|
|
## Known Issues / Pitfalls
|
|
|
|
1. **Python-Version-Mismatch:** hermes-agent pyproject pins Core-Deps an
|
|
`python_version >= '3.14'`; WebUI-Container läuft auf 3.12 → `-e .`
|
|
installiert keine Deps. Fix: manuell `pip install` der gepinschten Pakete
|
|
+ iterativer Missing-Import-Loop bis `import run_agent` klappt.
|
|
2. **hermes update Ownership-Konflikt:** `hermes update`-Completion beschwert
|
|
sich über uid 0 vs. uid 1000 auf `/app/venv/bin/hermes-acp`. Kosmetisch,
|
|
Betriebsbetrieb unbeeinträchtigt. Fix-Idee: `chown` im Entry-Point.
|
|
3. **telegram-bridge Notify-Target defekt** (seit 19.09., Connection refused):
|
|
betrifft vzdump-Notifications clusterweit, nicht nur VM107. Separater Fix.
|
|
|
|
## Verification History
|
|
|
|
- 2026-09-30: Deploy + E2E-Test (Login 200, Agent-Antwort "HALLO" via glm-5-2).
|
|
- 2026-09-30: Manueller vzdump → TASK OK (48s, inkrementell).
|