straylight: declare hermes-gateway user service + linger

This commit is contained in:
2026-09-19 01:56:42 -07:00
parent 3ed97625a1
commit ae9892dce4
+41
View File
@@ -353,6 +353,47 @@ in
# Project tracker (hackerman edition), tailnet-only. # Project tracker (hackerman edition), tailnet-only.
services.tracker.enable = true; services.tracker.enable = true;
# Hermes Agent gateway (messaging platforms, e.g. Mattermost).
# The CLI itself is installed imperatively via `uv tool install hermes-agent`
# (shim at ~/.local/bin/hermes); only the always-on gateway service is
# declared here. Credentials/state live in ~/.hermes (unmanaged; keep the
# bot token out of git). Do NOT also run `hermes gateway install` — it would
# write a mutable unit that shadows this one. Applies to every user manager
# on the host, but kyle is the only linger-enabled user, so effectively his.
users.users.kyle.linger = true;
systemd.user.services.hermes-gateway = {
description = "Hermes Agent Gateway - Messaging Platform Integration";
documentation = [ "https://hermes-agent.nousresearch.com/docs" ];
after = [ "network-online.target" ];
wants = [ "network-online.target" ];
wantedBy = [ "default.target" ];
startLimitIntervalSec = 0;
unitConfig.ConditionPathExists = "%h/.hermes/config.yaml";
serviceConfig = {
Type = "simple";
ExecStart = "%h/.local/bin/hermes gateway run";
WorkingDirectory = "%h/.hermes";
Environment = [
"PATH=%h/.local/bin:/run/current-system/sw/bin"
"HERMES_HOME=%h/.hermes"
# uv's foreign CPython has no CA bundle; point std-lib SSL at the
# NixOS store (needed for OAuth token refresh via urllib).
"SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt"
];
Restart = "always";
RestartSec = 5;
RestartForceExitStatus = 75;
RestartPreventExitStatus = 78;
KillMode = "mixed";
KillSignal = "SIGTERM";
ExecReload = "/run/current-system/sw/bin/kill -USR1 $MAINPID";
TimeoutStopSec = 60;
};
};
# Open ports: DNS (53), mc-proxy (443/8443/9443), agent (9444), master (9555), open-webui (8080). # Open ports: DNS (53), mc-proxy (443/8443/9443), agent (9444), master (9555), open-webui (8080).
networking.firewall.allowedTCPPorts = [ 53 443 8080 8443 9443 9444 9555 ]; networking.firewall.allowedTCPPorts = [ 53 443 8080 8443 9443 9444 9555 ];
networking.firewall.allowedUDPPorts = [ 53 ]; networking.firewall.allowedUDPPorts = [ 53 ];