Hermes Agent VPS and Tailscale Hardening Guide
nemanjadotcom/hermes-agent-setup
Step-by-step guide to locking down a VPS so it is reachable only over Tailscale, with SSH keys and UFW
Hermes Agent VPS and Tailscale Hardening Guide is a step-by-step guide to setting up a locked-down VPS for Hermes agents that is reachable only through Tailscale. It covers SSH keys, a dedicated user, UFW and a Hetzner firewall.
What Hermes Agent VPS and Tailscale Hardening Guide does
Hermes Agent VPS and Tailscale Hardening Guide is a written walkthrough for building a VPS that is not exposed to the public internet. The goal stated in the guide is to remove SSH from the internet entirely rather than only securing it, so the server is reachable only over a private Tailscale network and only with SSH keys. It names Hermes agents, scraping nodes and automation servers as the intended hosts.
The guide runs through phases. It generates an ed25519 SSH key, creates an Ubuntu 24.04 LTS server, adds a non-root user named hermes, installs Tailscale, and copies the authorized key to the new user. It then disables password login and root login in sshd_config, sets UFW to deny incoming traffic while allowing port 22 only on the tailscale0 interface, and finishes with a Hetzner Cloud firewall that allows only UDP 41641 for Tailscale. It does not cover installing Hermes Agent itself.
Key features
- SSH key generation with ed25519 and key-only login
- Dedicated non-root user with sudo access
- Tailscale install so SSH is reachable only on the private 100.x.x.x address
- sshd settings that disable password login and root login
- UFW rules that deny incoming traffic except SSH on the tailscale0 interface
- Hetzner Cloud firewall rule that allows only UDP 41641 inbound
When to use it
- Prepare a private Ubuntu VPS before installing Hermes Agent on it
- Close public port 22 on an agent or scraping server
- Verify the setup by confirming SSH to the public IP fails and the Tailscale IP works
Who it is for: Hermes Agent users renting a VPS who want it reachable only through a private Tailscale network.
How it fits with Hermes Agent
The guide is titled for Hermes and agent setups and names Hermes agents as the ideal use, but it covers server hardening only and does not install Hermes Agent.
Requirements: An Ubuntu 24.04 LTS VPS, an SSH key pair, Tailscale, and a Hetzner Cloud firewall for the network-level step
Note: The firewall phase is written specifically for the Hetzner Cloud console.
FAQ
What is Hermes Agent VPS and Tailscale Hardening Guide?
It is a written guide for setting up a VPS that is reachable only through Tailscale and only with SSH keys. It is aimed at servers that host Hermes agents, scraping nodes and automation.
What do I need to follow Hermes Agent VPS and Tailscale Hardening Guide?
You need an Ubuntu 24.04 LTS VPS, an SSH key pair and Tailscale. The final network-level step is written for the Hetzner Cloud firewall.
How do I connect to the server after hardening it?
Connect with ssh hermes@ followed by the server's Tailscale 100.x.x.x address. An attempt to SSH to the public IP should fail, which confirms the lockdown worked.
Similar resources for Hermes Agent
All resourcesFull Russian translation of the Hermes Agent Desktop interface with 2218 keys and a PowerShell installer
teknium1 Hermes Starter ProfileBeginner Hermes profile that leaves terminal, file and automation tools off while you learn the agent
xiaonancs Hermes Agent StudyChinese-language source-level study of Hermes Agent, with comparisons to OpenClaw and related projects
BkashJEE Hermes Agent ArchiveIndependent static archive of Hermes Agent use cases, skills, prompts and community projects
sisyphusse1-ops Claude Code Pro Pack12-rule CLAUDE.md and AGENTS.md behavior files plus skill templates for coding agents
avenoxai Avenox Hermes NotesTurkish notes on running an AI operator around the clock on your own server, from a Hermes Agent video
Related guides: SOUL.md for Hermes Agent: what it is and how to write one · What is Hermes Agent?