Hermes Atlas
Deployment & hosting

Hermes Agent Fly.io Template

mattppal/hermes-agent-template

Deploy a private Hermes Agent gateway on Fly.io behind Open WebUI, Cloudflare Access and Modal sandboxes

In short

Hermes Agent Fly.io Template is a deployment template that puts a private Hermes Agent gateway on Fly.io behind a public Open WebUI frontend protected by Cloudflare Access and OIDC.

What Hermes Agent Fly.io Template does

The production deployment creates a private Hermes app on Fly.io with no public HTTP service, and a public Open WebUI app in front of it. Cloudflare Access protects the custom Open WebUI hostname, and Open WebUI OIDC is backed by Cloudflare Access, so requests that reach the Fly origin directly still need app-level SSO. Open WebUI reaches Hermes over a private .internal address on port 8642, and Hermes runs terminal commands in Modal Sandboxes.

Setup is driven by a Makefile and a .env file, with targets such as create-apps, create-volumes, check-oidc, sync-secrets, deploy and smoke, and a separate TUTORIAL.md for the first-time walkthrough. Stable defaults live in openwebui/fly.toml, including SSO-only login and no local signup. The README warns that Slack, Telegram or custom webhook clients do not inherit the browser-path protection, so each new inbound client should be reviewed as its own public entry point. For local testing, make local-up starts Open WebUI on port 8080 and Hermes on port 8642.

Key features

  • Private Hermes app on Fly.io with no public HTTP service
  • Public Open WebUI frontend with Cloudflare Access and OIDC
  • Modal Sandboxes for Hermes terminal commands
  • Makefile targets for creating apps, syncing secrets, deploying and smoke checks
  • SSO-only Open WebUI defaults kept in openwebui/fly.toml
  • Local container setup with make local-up

When to use it

  • Hosting a private Hermes agent with a browser chat interface behind SSO
  • Running agent terminal commands in remote sandboxes instead of the Fly machine
  • Testing the same stack locally in containers before deploying

Who it is for: Developers who want a documented, security-minded way to host Hermes Agent on Fly.io.

How it fits with Hermes Agent

Built for Hermes Agent: it deploys the Hermes gateway API on port 8642 and connects Open WebUI to it as the chat front end.

How to install Hermes Agent Fly.io Template

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

brew install flyctl docker
fly auth login
cp .env.example .env
make check-tools

Requirements: flyctl and Docker, a Fly.io account, Cloudflare Access with OIDC, Modal credentials for sandboxed terminal execution, and a model-provider API key

Note: It needs Fly.io, Cloudflare and Modal accounts, and the repository has no license file.

FAQ

What is Hermes Agent Fly.io Template?

Hermes Agent Fly.io Template is a deployment template that runs a private Hermes Agent gateway on Fly.io with a public Open WebUI frontend. Cloudflare Access, OIDC and Modal Sandboxes handle access and execution.

How do I run Hermes Agent Fly.io Template locally?

Copy .env.example to .env, set the model-provider secrets you need such as OPENROUTER_API_KEY, then run make local-up. Open WebUI runs at http://localhost:8080 and Hermes listens at http://localhost:8642.

What do I need to run Hermes Agent Fly.io Template?

You need flyctl, Docker and a Fly.io account for deployment, plus Cloudflare Access with OIDC, Modal credentials for sandboxes and a model-provider API key. The README points to TUTORIAL.md for the full first-time setup.

Similar deployment for Hermes Agent

All deployment

Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop