Hermes Atlas
Deployment & hosting

hermes-agent-operator

hermeum/hermes-agent-operator

Kubernetes operator that manages Hermes Agent instances from declarative HermesAgent manifests

In short

hermes-agent-operator is a Kubernetes operator for self-hosting Hermes Agent in a declarative, reproducible way. It treats each agent as a custom resource and keeps the running agent in sync with its manifest.

What hermes-agent-operator does

hermes-agent-operator manages Hermes Agent instances on Kubernetes as custom resources. You declare an agent's config, workspace files, skills, crons and bundles in a single HermesAgent manifest, and the operator keeps the running agent in sync with that declaration. The README frames this around teams: Hermes Agent is designed for personal use, and when several people run it, configurations drift and skills fall out of sync.

The operator is installed from a Helm chart published on ghcr.io. Optional settings include a built-in gateway API, port 8642 by default, with an operator-generated Secret holding a random API_SERVER_KEY, and a webhook ingress on port 8644 protected by an HMAC secret. Persistent storage mounts at /opt/data with a 10Gi default, and can use a chosen storage class, an existing claim or a snapshot. Profiles can be set per agent under hermes.profiles, and reconciliation failures are reported on the Ready condition. A separate project, Hermeum, builds on the operator and adds a dashboard, templates and shared credentials.

Key features

  • HermesAgent custom resource covering config, workspace files, skills, crons and bundles
  • Helm chart installation from an OCI registry on ghcr.io
  • Optional gateway API with an operator-generated API_SERVER_KEY Secret
  • Optional webhook ingress with an HMAC secret
  • Persistent volume at /opt/data with size, storage class, existing claim and snapshot options
  • Per-agent profiles and reconciliation status on the Ready condition

When to use it

  • Running several Hermes agents for a team with one source of truth for each agent's setup
  • Keeping skills and cron jobs identical across environments through manifests
  • Exposing the Hermes gateway API or a webhook endpoint from a cluster
  • Restoring an agent's data volume from a snapshot

Who it is for: Platform and DevOps engineers who run Hermes Agent on Kubernetes and want declarative, reproducible agent setups.

How it fits with Hermes Agent

Built around Hermes Agent as a deployment tool: it runs Hermes agents in pods and configures their gateway API, webhook ingress, profiles and skills.

How to install hermes-agent-operator

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

helm upgrade hermes-agent-operator oci://ghcr.io/hermeum/charts/hermes-agent-operator \
  --install --namespace hermes-agent --create-namespace
kubectl create secret generic my-hermes-secret \
  --from-literal=ANTHROPIC_API_KEY=sk-ant-...

Requirements: A Kubernetes cluster and Helm v3, plus a Secret holding your model provider API key (the example uses ANTHROPIC_API_KEY).

FAQ

What is hermes-agent-operator?

hermes-agent-operator is a Kubernetes operator written in Go that manages Hermes Agent instances. You describe each agent in a HermesAgent manifest and the operator keeps the running agent matching it.

How do I install hermes-agent-operator?

Install the Helm chart with helm upgrade --install from oci://ghcr.io/hermeum/charts/hermes-agent-operator, then create a Secret with your API key. After that you deploy a HermesAgent resource with kubectl apply.

What do I need to run hermes-agent-operator?

You need a Kubernetes cluster and Helm v3. The agent also needs a Secret with a model provider key, and persistence is optional but data is lost on pod restart without it.

Similar deployment for Hermes Agent

All deployment

Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop