Hermes Atlas
Deployment & hosting

Hermes Operator

stubbi/hermes-operator

Kubernetes operator for Hermes Agent with security defaults, S3 backups and OCI auto-update

In short

Hermes Operator is a Kubernetes operator for Hermes Agent that runs an agent from a single HermesInstance resource, with security defaults, S3 backups, OCI-registry auto-update and GitOps-friendly server-side apply. It also provides a migration path from openclaw-operator.

What Hermes Operator does

A single HermesInstance custom resource drives the whole stack: a StatefulSet (one replica by default), Service, PVC, default-deny NetworkPolicy, ConfigMap, PDB, HPA, ServiceMonitor, a Honcho profile store deployment and a backup CronJob. The agent runs the upstream NousResearch/hermes-agent s6 image with the gateway and an OpenAI-compatible API server, with /health on port 8443 and the /v1 API authenticated by a gateway tokens Secret.

HermesClusterDefaults, a cluster-scoped singleton named cluster, fills unset fields only, so explicit values on an instance win. HermesSelfConfig allows audited, agent-initiated changes using Server-Side Apply under the field manager hermes.agent/selfconfig, gated by spec.selfConfigure.protectedKeys, which lets FluxCD or Argo own the parent resource without conflicts. The operator polls an OCI registry for new hermes-agent tags to drive auto-update with rollback. It ships as v1.0.0 with v1 stability commitments and was inspired by openclaw-operator.

Key features

  • Single HermesInstance resource that reconciles the StatefulSet, Service, PVC, NetworkPolicy, ConfigMap, PDB, HPA and ServiceMonitor
  • Cluster-wide defaults through the HermesClusterDefaults singleton
  • Audited agent-initiated changes via HermesSelfConfig and Server-Side Apply
  • OCI-registry auto-update with rollback
  • S3-compatible backups through a CronJob
  • Migration path from openclaw-operator

When to use it

  • Running Hermes Agent on a Kubernetes cluster from declarative configuration
  • Managing agents under FluxCD or Argo without field conflicts
  • Moving an OpenClaw deployment managed by openclaw-operator to Hermes

Who it is for: Platform and DevOps engineers who deploy Hermes Agent on Kubernetes.

How it fits with Hermes Agent

Built to deploy and manage NousResearch/hermes-agent on Kubernetes, running the upstream s6 image with its gateway and API server.

How to install Hermes Operator

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

helm install hermes-operator \
  oci://ghcr.io/paperclipinc/charts/hermes-operator \
  -n hermes-operator --create-namespace

Requirements: A Kubernetes cluster and Helm 3.8 or later (OCI chart); an S3-compatible target if you want backups

FAQ

What is Hermes Operator?

Hermes Operator is a Kubernetes operator for Hermes Agent. It manages the agent through a declarative HermesInstance resource with security defaults, S3 backups and OCI-registry auto-update.

How do I install Hermes Operator?

Install the CRDs and operator with the Helm OCI chart: helm install hermes-operator oci://ghcr.io/paperclipinc/charts/hermes-operator -n hermes-operator --create-namespace. Then apply a minimal HermesInstance. Helm 3.8 or later is required.

Is Hermes Operator free and open source?

Yes, it is released under the Apache-2.0 license.

Similar deployment for Hermes Agent

All deployment

Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop