Hermes Atlas
Guides, templates & lists

Hermes Agent VPS and Tailscale Hardening Guide

nemanjadotcom/hermes-agent-setup

Step-by-step guide to locking down a VPS so it is reachable only over Tailscale, with SSH keys and UFW

In short

Hermes Agent VPS and Tailscale Hardening Guide is a step-by-step guide to setting up a locked-down VPS for Hermes agents that is reachable only through Tailscale. It covers SSH keys, a dedicated user, UFW and a Hetzner firewall.

What Hermes Agent VPS and Tailscale Hardening Guide does

Hermes Agent VPS and Tailscale Hardening Guide is a written walkthrough for building a VPS that is not exposed to the public internet. The goal stated in the guide is to remove SSH from the internet entirely rather than only securing it, so the server is reachable only over a private Tailscale network and only with SSH keys. It names Hermes agents, scraping nodes and automation servers as the intended hosts.

The guide runs through phases. It generates an ed25519 SSH key, creates an Ubuntu 24.04 LTS server, adds a non-root user named hermes, installs Tailscale, and copies the authorized key to the new user. It then disables password login and root login in sshd_config, sets UFW to deny incoming traffic while allowing port 22 only on the tailscale0 interface, and finishes with a Hetzner Cloud firewall that allows only UDP 41641 for Tailscale. It does not cover installing Hermes Agent itself.

Key features

  • SSH key generation with ed25519 and key-only login
  • Dedicated non-root user with sudo access
  • Tailscale install so SSH is reachable only on the private 100.x.x.x address
  • sshd settings that disable password login and root login
  • UFW rules that deny incoming traffic except SSH on the tailscale0 interface
  • Hetzner Cloud firewall rule that allows only UDP 41641 inbound

When to use it

  • Prepare a private Ubuntu VPS before installing Hermes Agent on it
  • Close public port 22 on an agent or scraping server
  • Verify the setup by confirming SSH to the public IP fails and the Tailscale IP works

Who it is for: Hermes Agent users renting a VPS who want it reachable only through a private Tailscale network.

How it fits with Hermes Agent

The guide is titled for Hermes and agent setups and names Hermes agents as the ideal use, but it covers server hardening only and does not install Hermes Agent.

Requirements: An Ubuntu 24.04 LTS VPS, an SSH key pair, Tailscale, and a Hetzner Cloud firewall for the network-level step

Note: The firewall phase is written specifically for the Hetzner Cloud console.

FAQ

What is Hermes Agent VPS and Tailscale Hardening Guide?

It is a written guide for setting up a VPS that is reachable only through Tailscale and only with SSH keys. It is aimed at servers that host Hermes agents, scraping nodes and automation.

What do I need to follow Hermes Agent VPS and Tailscale Hardening Guide?

You need an Ubuntu 24.04 LTS VPS, an SSH key pair and Tailscale. The final network-level step is written for the Hetzner Cloud firewall.

How do I connect to the server after hardening it?

Connect with ssh hermes@ followed by the server's Tailscale 100.x.x.x address. An attempt to SSH to the public IP should fail, which confirms the lockdown worked.

Similar resources for Hermes Agent

All resources

Related guides: SOUL.md for Hermes Agent: what it is and how to write one · What is Hermes Agent?