Hermes Atlas
Deployment & hosting

Hermzner

scicco/hermzner

Provision a hardened Hermes Agent on Hetzner with rootless Podman and Tailscale

In short

Hermzner is a Terraform and Ansible project that provisions a hardened Hermes Agent server on Hetzner Cloud, running in rootless Podman and reached over Tailscale. It gives Hermes Agent users a repeatable, locked-down VPS deployment.

What Hermzner does

deploy.sh runs Terraform to create a Hetzner cx23 VPS with Ubuntu 24.04, then Ansible to configure it, connecting first over the public IPv4 because Tailscale is not available until its role runs. Hermes Agent runs in a rootless Podman container, with Quadlet as the default and Compose as a fallback, and exposes its gateway, API and optional dashboard. The Ansible variable hermes_image_ref must be set to a pinned image digest, and the deployment fails closed if it is missing.

Security controls include dropped capabilities, no-new-privileges, all ports bound to 127.0.0.1, UFW default deny with only tailscale0 allowed, a read-only root filesystem with tmpfs for /tmp and /run, and an auto-generated API key in a 0600 .env file. Daily local backups go to /home/hermes/backups/, optionally encrypted with age. An optional Mnemosyne memory backend using SQLite-vec can be switched on with hermes_mnemosyne_enabled. The dashboard is reached through an SSH tunnel to port 9119.

Key features

  • Terraform provisioning of a Hetzner cx23 VPS on Ubuntu 24.04
  • Ansible configuration of rootless Podman, using Quadlet with a Compose fallback
  • Tailscale SSH access with UFW allowing only tailscale0
  • Required image digest pinning that fails closed
  • Daily backups with optional age encryption
  • Optional Mnemosyne SQLite-vec memory backend

When to use it

  • Stand up a locked-down always-on Hermes Agent on a Hetzner VPS
  • Reach the Hermes dashboard only through an SSH tunnel over Tailscale
  • Test the deployment first on a disposable VPS using the smoke test procedure

Who it is for: Operators who want a security-conscious, scripted way to host Hermes Agent on Hetzner.

How it fits with Hermes Agent

Built for Hermes Agent: it deploys the official nousresearch/hermes-agent image with the gateway, API and optional dashboard.

How to install Hermzner

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

cp terraform/terraform.tfvars.example terraform/terraform.tfvars
vim terraform/terraform.tfvars
vim ansible/inventory/group_vars/all.yml
HCLOUD_TOKEN=your_token TAILSCALE_AUTH_KEY=tskey-auth-... ./deploy.sh

Requirements: Terraform 1.5 or newer, Ansible 2.15 or newer, a Hetzner Cloud API token and a Tailscale pre-auth key.

FAQ

What is Hermzner?

Hermzner is a Terraform and Ansible deployment that provisions a hardened Hermes Agent on a Hetzner VPS, using rootless Podman and Tailscale for access.

What do I need to run Hermzner?

You need Terraform 1.5 or newer, Ansible 2.15 or newer, a Hetzner Cloud API token and a Tailscale pre-auth key. You must also set hermes_image_ref to a pinned image digest.

Is Hermzner free and open source?

Yes. The repository is published under the MIT license.

Similar deployment for Hermes Agent

All deployment

Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop