Hermes Agent Hardening Patterns
wnstify/hermes-agent
Hardened Docker Compose and SSH sandbox patterns for self-hosting Hermes Agent with Honcho
Hermes Agent Hardening Patterns is a set of reference files for running Hermes Agent and Honcho on company servers without exposing production. It covers a locked-down execution sandbox, an SSH entry script and a hardened Honcho stack.
What Hermes Agent Hardening Patterns does
The repository holds three reference files. sandbox/compose.yml defines a single-purpose execution container with rootless Docker, cap_drop ALL with narrow add-backs, no-new-privileges, pids, memory and CPU limits, tmpfs for /tmp and /run and a bind-mounted /workspace, plus a headless Chrome reachable over CDP only on a private interface. sandbox/sandbox-entry.sh is an SSH ForceCommand target that pipes the gateway's session into docker exec with an explicit environment variable allowlist.
gateway/honcho-stack/compose.yml hardens a self-hosted Honcho stack made of the API, Postgres with pgvector, Redis and a deriver worker, using internal-only networks, bind-mounted data directories with explicit UID ownership and per-service resource and capability limits. The files are heavily commented and published as companion code to a Webnestify blog post on secure AI agent infrastructure. Real secret values, the agent itself and the wider architecture are intentionally left out. Docker Hardened Images are an optional swap that needs a paid Docker subscription.
Key features
- Hardened execution container: rootless Docker, dropped capabilities, resource limits
- Headless Chrome over CDP bound to a private interface only
- SSH ForceCommand entry script with an environment variable allowlist
- Hardened self-hosted Honcho stack with Postgres, Redis and a deriver worker
- Internal-only database networks and auditable bind mounts
- Heavily commented files that map each choice to a threat
When to use it
- Separating a Hermes gateway from the sandbox where commands run
- Copying hardening settings into your own Compose files
- Self-hosting Honcho for Hermes with tighter container limits
Who it is for: Operators who run Hermes Agent for a company and want concrete container and SSH hardening examples to adapt.
How it fits with Hermes Agent
The patterns are written around Hermes Agent and Honcho deployments, splitting a gateway from a sandbox where agent commands run.
Requirements: Docker Compose, with secrets such as POSTGRES_PASSWORD and LLM API keys supplied through environment variables from a secrets manager
Note: These are reference patterns, not a turnkey install: real secret values, the agent itself and most of the surrounding architecture are intentionally left out.
FAQ
What is Hermes Agent Hardening Patterns?
It is a set of reference files for securing a self-hosted Hermes Agent and Honcho stack. They show a hardened sandbox container, an SSH entry script and a hardened Honcho Compose stack.
Does Hermes Agent Hardening Patterns work with Hermes Agent?
Yes. The files are written for Hermes Agent deployments, but they contain neither the agent itself nor real secrets, so you install Hermes and Honcho from upstream.
Is Hermes Agent Hardening Patterns free and open source?
The repository is public, but it has no license file, so default copyright applies. Check with the author before reusing the files.
Similar security for Hermes Agent
All securityHermes plugin that has a second-lab model review each task before a subagent starts writing code
intentframe IntentFrame for Hermes AgentIntentFrame security plugin that checks Hermes terminal, code, file and cron tool calls against policy
mauricemohr88-debug Hermes Plugin GuardStatic security scanner for Hermes Agent plugins that never imports or runs the plugin code
aibuild-lab Skills GuardThreat scanner and trust matrix for AI skill files, ported from Hermes Agent's skills_guard
0xtbug RecatLocal workspace for reviewing security findings reported by Hermes and other agents
jooray hermes-firewallPrompt-injection gate plugin that scans web, MCP, email and image content before Hermes Agent sees it
Related guides: How to run Hermes Agent securely