Hermes Atlas
Security & sandboxing · works with Hermes Agent

Reef

skalenetwork/microsandbox-reef

Run Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy

In short

Reef is a Rust command-line tool that runs AI agents, including Hermes Agent and OpenClaw, in microsandbox microVMs on your own servers. A reviewable TOML role sets the image, allowed domains and host-bound secrets, and there is no daemon.

What Reef does

Reef runs AI agents in microsandbox microVMs on your own servers, with no daemon. A role is a TOML file that sets the image, resources, the domains an agent may reach and the secrets it may spend, and every agent is created from a role you approved. The README shows roles for OpenClaw and for Hermes Agent, and you can write your own.

The Hermes role needs only four policy lines: egress limited to openrouter.ai, and an OPENROUTER_API_KEY secret bound to that host, so the guest sees only a placeholder. The README credits microsandbox with the microVM, the DNS-enforced egress allowlist and the host-side secret substitution. Opening a port on the reef host requires naming it in the role, and role apply warns about every such opening. Installation is a curl script that places the binary in ~/.local/bin without sudo, on Linux x86_64 and aarch64 or Apple Silicon macOS.

Key features

  • Each agent runs in its own microsandbox microVM on your own servers
  • Roles defined in a single TOML file: image, resources, egress domains and secrets
  • Secrets bound to a host, so the guest sees a placeholder instead of the value
  • Approved role versions, with agents on older versions marked stale
  • No daemon; every mutating command reconciles inline and VMs outlive reef
  • reef role apply, reef fleet apply and reef agent get commands

When to use it

  • Limiting a Hermes agent to one domain and one API key
  • Running OpenClaw with web access while reef warns about the open egress
  • Rolling out the same approved policy to several agents at once

Who it is for: Operators who want to run AI agents on their own servers with strict network and secret boundaries.

How it fits with Hermes Agent

Supports Hermes Agent as one of the agents it can run; the repository includes a roles/hermes.toml and a Hermes fleet example alongside OpenClaw.

How to install Reef

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -fsSL https://reef.clawbits.ai/install | sh

Requirements: Linux (x86_64 or aarch64, glibc 2.39 or newer) or Apple Silicon macOS, plus the msb bundle from microsandbox

Note: It drives microsandbox rather than shipping it, so each host needs the microsandbox msb bundle.

FAQ

What is Reef?

Reef is a command-line tool that runs AI agents in microsandbox microVMs on your own servers. Each agent is created from an approved TOML role that defines its image, reachable domains and spendable secrets.

Does Reef work with Hermes Agent?

Yes. The README includes a roles/hermes.toml that limits a Hermes agent to openrouter.ai and one bound API key, and a fleet example that starts two Hermes agents with dashboards.

How do I install Reef?

Run curl -fsSL https://reef.clawbits.ai/install | sh. It installs the latest release to ~/.local/bin without sudo, and REEF_VERSION pins a specific version.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely