Hermes Isolated Personal Agent — Trust Boundaries

Hermes Isolated Personal Agent — Trust Boundaries An architecture diagram generated by Archify. User · daily driver PC · Architecture component User daily driver PC Telegram · text + voice · Architecture component Telegram text + voice SSH Tunnel · loopback only + auth · Architecture component SSH Tunnel loopback only + auth Dashboard · loopback bind inside VM · Isolated VM (NAT-only, no LAN visibility) Dashboard loopback bind inside VM Hermes Gateway · container, resource-capped · Isolated VM (NAT-only, no LAN visibility) › Container boundary (resource-capped) Hermes Gateway container, resource-capped Model Router · hosted LLM API · Architecture component Model Router hosted LLM API Tool Execution · local backend, non-root · Isolated VM (NAT-only, no LAN visibility) › Container boundary (resource-capped) Tool Execution local backend, non-root Persistent State · config, memory, skills, logs · Isolated VM (NAT-only, no LAN visibility) › Container boundary (resource-capped) Persistent State config, memory, skills, logs voice + text bot pairing inference ssh forward localhost only full agent control Isolated VM (NAT-only, no LAN visibility) Container boundary (resource-capped) Legend Frontend Backend Database Cloud Security External

Trust boundaries

  • • VM: NAT-only, no shared folders or clipboard — the 'VPS' edge
  • • Container: agent code executes as non-root inside, never on the VM shell
  • • Docker-socket mount rejected: root-equivalent escalation path

Access discipline

  • • Dashboard: loopback bind + basic auth + SSH tunnel
  • • Risky commands surface as chat approval prompts
  • • All persistent state survives container recreation