Something went wrong. Try again.
Nix configuration
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445# Hermes Agent — secrets, firewall, linger.## Imported only from hosts/s.nix so hermes runs on host s (AMD/NVIDIA desktop)# and not host x (Intel XPS 13). All hermes-related agenix declarations live# here so they have a single owner — nothing leaks into controld.nix or gpg.nix.
{ config, ... }:
{ # API keys for Aperture / OpenRouter / messaging bots. Read at runtime by # the hermes-agent systemd user service from $HERMES_HOME/.env. # # owner = "jgarr" because the service runs as jgarr (Home Manager user # service), not root. The file ends up world-unreadable (0600) with the # right user; agenix sets mode automatically. age.secrets."hermes-env" = { file = ./secrets/hermes-env.age; owner = "jgarr"; group = "users"; };
# Session token for the hermes dashboard (backend.mode = "dashboard"). # Generate with: openssl rand -hex 32 # Client presents it as Authorization: Bearer <token>. # owner = "jgarr" so the hermes gateway (running as a systemd user # service under jgarr) can read the token. Mode 0640 by default, # owner-overridable to make it group-readable; here we set user-only. age.secrets."hermes-dashboard-token" = { file = ./secrets/hermes-dashboard-token.age; owner = "jgarr"; group = "users"; };
# Open :9119 so the hermes dashboard can be reached from the LAN / Tailscale. # Auth is gated by backend.sessionTokenFile; tailscale provides additional # protection on the public side. Tighten to a specific interface later if # you want to restrict to the tailnet only. networking.firewall.allowedTCPPorts = [ 9119 ];
# Without linger, systemd stops the user manager (and the hermes-agent # gateway) the moment jgarr's last session ends. Required for any HM-managed # systemd user service. users.users.jgarr.linger = true;}