Hermzner
scicco/hermzner
Provision a hardened Hermes Agent on Hetzner with rootless Podman and Tailscale
Hermzner is a Terraform and Ansible project that provisions a hardened Hermes Agent server on Hetzner Cloud, running in rootless Podman and reached over Tailscale. It gives Hermes Agent users a repeatable, locked-down VPS deployment.
What Hermzner does
deploy.sh runs Terraform to create a Hetzner cx23 VPS with Ubuntu 24.04, then Ansible to configure it, connecting first over the public IPv4 because Tailscale is not available until its role runs. Hermes Agent runs in a rootless Podman container, with Quadlet as the default and Compose as a fallback, and exposes its gateway, API and optional dashboard. The Ansible variable hermes_image_ref must be set to a pinned image digest, and the deployment fails closed if it is missing.
Security controls include dropped capabilities, no-new-privileges, all ports bound to 127.0.0.1, UFW default deny with only tailscale0 allowed, a read-only root filesystem with tmpfs for /tmp and /run, and an auto-generated API key in a 0600 .env file. Daily local backups go to /home/hermes/backups/, optionally encrypted with age. An optional Mnemosyne memory backend using SQLite-vec can be switched on with hermes_mnemosyne_enabled. The dashboard is reached through an SSH tunnel to port 9119.
Key features
- Terraform provisioning of a Hetzner cx23 VPS on Ubuntu 24.04
- Ansible configuration of rootless Podman, using Quadlet with a Compose fallback
- Tailscale SSH access with UFW allowing only tailscale0
- Required image digest pinning that fails closed
- Daily backups with optional age encryption
- Optional Mnemosyne SQLite-vec memory backend
When to use it
- Stand up a locked-down always-on Hermes Agent on a Hetzner VPS
- Reach the Hermes dashboard only through an SSH tunnel over Tailscale
- Test the deployment first on a disposable VPS using the smoke test procedure
Who it is for: Operators who want a security-conscious, scripted way to host Hermes Agent on Hetzner.
How it fits with Hermes Agent
Built for Hermes Agent: it deploys the official nousresearch/hermes-agent image with the gateway, API and optional dashboard.
How to install Hermzner
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
cp terraform/terraform.tfvars.example terraform/terraform.tfvars
vim terraform/terraform.tfvars
vim ansible/inventory/group_vars/all.yml
HCLOUD_TOKEN=your_token TAILSCALE_AUTH_KEY=tskey-auth-... ./deploy.shRequirements: Terraform 1.5 or newer, Ansible 2.15 or newer, a Hetzner Cloud API token and a Tailscale pre-auth key.
FAQ
What is Hermzner?
Hermzner is a Terraform and Ansible deployment that provisions a hardened Hermes Agent on a Hetzner VPS, using rootless Podman and Tailscale for access.
What do I need to run Hermzner?
You need Terraform 1.5 or newer, Ansible 2.15 or newer, a Hetzner Cloud API token and a Tailscale pre-auth key. You must also set hermes_image_ref to a pinned image digest.
Is Hermzner free and open source?
Yes. The repository is published under the MIT license.
Similar deployment for Hermes Agent
All deploymentDeploy Hermes Agent on Hugging Face Spaces with data persistence through a Hugging Face Dataset
mrobinson2 AzureAgentForgeTerraform-deployed multi-agent platform on Azure combining PaperClip, Hermes and Honcho
niyazmft Droid AI ToolkitTermux toolkit for running OpenClaw, Hermes, Ollama, n8n and other AI tools on Android
UndermountainCC hermes-operatorKubernetes operator that deploys and manages Hermes Agent instances from a HermesAgent resource
fly-apps Hermes Agent on Fly.ioExample deployment of Hermes Agent as a Fly.io Machines app with messaging access
orailnoor Pi DuckyRaspberry Pi Zero USB keyboard gadget that deploys Hermes Agent, Tailscale and RustDesk on a computer
Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop