Hermes Atlas
Security & sandboxing

Hermes Agent Hardening Patterns

wnstify/hermes-agent

Hardened Docker Compose and SSH sandbox patterns for self-hosting Hermes Agent with Honcho

In short

Hermes Agent Hardening Patterns is a set of reference files for running Hermes Agent and Honcho on company servers without exposing production. It covers a locked-down execution sandbox, an SSH entry script and a hardened Honcho stack.

What Hermes Agent Hardening Patterns does

The repository holds three reference files. sandbox/compose.yml defines a single-purpose execution container with rootless Docker, cap_drop ALL with narrow add-backs, no-new-privileges, pids, memory and CPU limits, tmpfs for /tmp and /run and a bind-mounted /workspace, plus a headless Chrome reachable over CDP only on a private interface. sandbox/sandbox-entry.sh is an SSH ForceCommand target that pipes the gateway's session into docker exec with an explicit environment variable allowlist.

gateway/honcho-stack/compose.yml hardens a self-hosted Honcho stack made of the API, Postgres with pgvector, Redis and a deriver worker, using internal-only networks, bind-mounted data directories with explicit UID ownership and per-service resource and capability limits. The files are heavily commented and published as companion code to a Webnestify blog post on secure AI agent infrastructure. Real secret values, the agent itself and the wider architecture are intentionally left out. Docker Hardened Images are an optional swap that needs a paid Docker subscription.

Key features

  • Hardened execution container: rootless Docker, dropped capabilities, resource limits
  • Headless Chrome over CDP bound to a private interface only
  • SSH ForceCommand entry script with an environment variable allowlist
  • Hardened self-hosted Honcho stack with Postgres, Redis and a deriver worker
  • Internal-only database networks and auditable bind mounts
  • Heavily commented files that map each choice to a threat

When to use it

  • Separating a Hermes gateway from the sandbox where commands run
  • Copying hardening settings into your own Compose files
  • Self-hosting Honcho for Hermes with tighter container limits

Who it is for: Operators who run Hermes Agent for a company and want concrete container and SSH hardening examples to adapt.

How it fits with Hermes Agent

The patterns are written around Hermes Agent and Honcho deployments, splitting a gateway from a sandbox where agent commands run.

Requirements: Docker Compose, with secrets such as POSTGRES_PASSWORD and LLM API keys supplied through environment variables from a secrets manager

Note: These are reference patterns, not a turnkey install: real secret values, the agent itself and most of the surrounding architecture are intentionally left out.

FAQ

What is Hermes Agent Hardening Patterns?

It is a set of reference files for securing a self-hosted Hermes Agent and Honcho stack. They show a hardened sandbox container, an SSH entry script and a hardened Honcho Compose stack.

Does Hermes Agent Hardening Patterns work with Hermes Agent?

Yes. The files are written for Hermes Agent deployments, but they contain neither the agent itself nor real secrets, so you install Hermes and Honcho from upstream.

Is Hermes Agent Hardening Patterns free and open source?

The repository is public, but it has no license file, so default copyright applies. Check with the author before reusing the files.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely