hermes-webui / README.md
Acrabohan's picture
Run initial Hermes backup sooner
2f37df2
|
Raw
History Blame Contribute Delete
2.83 kB
---
title: Hermes Agent WebUI
emoji: ๐Ÿ‘
colorFrom: blue
colorTo: gray
sdk: docker
app_port: 8787
pinned: false
license: mit
---
# Hermes Agent WebUI Space
This Space runs the community Hermes WebUI with Hermes Agent source available in
the container.
## Required Space secrets
Set these in Hugging Face Space settings before exposing the app:
- `HERMES_WEBUI_PASSWORD`: password for the browser UI.
Optional provider secrets:
- `DEEPSEEK_API_KEY`
- `OPENAI_API_KEY`
- `OPENROUTER_API_KEY`
- `ANTHROPIC_API_KEY`
- `GOOGLE_API_KEY`
- `HF_TOKEN`
Optional runtime secret:
- `HERMES_WEBUI_USER_PASSWORD`: sets the `hermeswebui` Linux user password and
enables password-based `sudo` inside the container. Use only when you need it.
Optional backup settings:
- `HERMES_BACKUP_REPO`: private Dataset repo used for Hermes state backups, for
example `Acrabohan/hermes-webui-backup`.
- `HF_BACKUP_TOKEN`: fine-grained Hugging Face token with read/write access to
the private backup Dataset. Set this as a Space secret, not a public variable.
- `HERMES_BACKUP_INTERVAL_SECONDS`: backup interval, default `1800`.
- `HERMES_BACKUP_INITIAL_DELAY_SECONDS`: first backup delay after container
start, default `300`.
- `HERMES_RESTORE_ON_START`: set to `0` to disable automatic restore on boot.
- `HERMES_FORCE_RESTORE`: set to `1` once if you want to overwrite local state
from the backup archive on the next boot.
## Workspace and state
The default workspace is `/workspace`.
Hermes reads and writes its state at `/home/hermeswebui/.hermes`. In this Space
that path is a symlink to `/data/.hermes`, so Hermes Agent and Hermes WebUI use
one shared home directory. On a free Space this is ephemeral and can be lost
after rebuilds. Enable Hugging Face persistent storage if you want Hermes memory,
sessions, and profile configuration to survive rebuilds.
If `HERMES_BACKUP_REPO` and `HF_BACKUP_TOKEN` are set, the container also backs
up Hermes state to the private Dataset as `hermes-state.tar.gz`. On startup, it
restores from that archive only when the local Hermes state is empty, unless
`HERMES_FORCE_RESTORE=1` is set.
## Security notes
Use a private or protected Space. This app can inspect files and run agent tools,
so do not publish it without `HERMES_WEBUI_PASSWORD`.
If you set `HERMES_WEBUI_USER_PASSWORD`, anyone who can control the WebUI may be
able to run privileged commands inside the container. Prefer baking system
packages into the Dockerfile instead of using sudo at runtime.
Keep the backup Dataset private. Hermes state can include memories, sessions,
provider configuration, and secrets. Do not set `HERMES_BACKUP_REPO` to this
public Space repo.
This repo intentionally does not include keep-alive automation. Free Spaces can
sleep; for always-on usage, use paid hardware or accept cold starts.