← Back to all fieldnotes
Hermes · High confidence

Hermes: An Isolated Personal Agent

The hard boundary

Hermes is an always-on personal agent with memory, tools, voice, and scheduled work. It runs in a resource-capped Docker container inside a hardened Ubuntu Server VM on a NAT-only switch. The VM has no LAN exposure or shared host folders. The daily-driver PC reaches chat through Telegram or the dashboard through an authenticated SSH tunnel.

Inside the VM

The gateway uses a hosted model router and a non-root tool backend. Persistent configuration, memory, skills, and logs survive container recreation. I rejected mounting the raw Docker socket for nested sandboxing: that would give the container a root-equivalent path into the VM. The VM remains the hard isolation boundary while nested sandboxing is deferred.

Access and recovery

The dashboard binds to loopback inside the VM and is reached through the tunnel, not directly over the network. Checkpoints cover clean OS, configured, and voice-working states. Voice and core automation are working; the weekly auto-checkpoint is not confirmed enabled.

How the pieces connect

Explore the original interactive diagram. Its controls include guided views, search, trace, and theme switching. On a narrow screen, use the diagram controls or open it full size.

Open diagram full size ↗

More notes will be added as this work develops.