3.6 KiB
3.6 KiB
Channel Wiki: #jarvis-jr-v1-hermes-setup
Channel ID: 1526844602303123466 Created: 2026-07-23 18:22 UTC Last sync: 2026-08-02 18:06 UTC
Purpose
Hermes installation, persistent runtime configuration, secret management, and setup troubleshooting.
Key Decisions
- CONFIRMED — Gitea credential (2026-08-02): authenticated operations against
gitea.lego-cloud.eumust use the Bitwarden Secrets Manager key/environment variableHL_V1_GITEA_ACCESS_TOKEN. Do not useGITHUB_TOKENfor this Gitea instance and do not copy the Gitea token into/opt/data/.env. - CONFIRMED — secret naming: Hermes exports Bitwarden secret keys exactly as named; it does not create aliases. The briefly reported
HL_V1_GITEA_TOKENalias was stale cache information and was explicitly corrected. - CONFIRMED — restart semantics:
/resetonly resets a conversation and does not reload process environment. A gateway restart is required after Bitwarden keys change so the gateway imports them.
Active Topics
- Bitwarden setup: enabled and operational. Live verification at sync time showed project access,
bws 2.0.0, and one applied key:HL_V1_GITEA_ACCESS_TOKEN(value never exposed). - PENDING: the gateway process observed during the 2026-08-02 conversation predated the corrected Bitwarden cache and had not imported
HL_V1_GITEA_ACCESS_TOKEN; run/restartonce, then verify the variable is present without printing its value.
Key Context
HERMES_HOME=/opt/data; this is persistent storage, so Bitwarden configuration survives gateway/container restarts and container recreation as long as/opt/dataremains mounted andHERMES_HOMEis unchanged.- Persistent Bitwarden components: token bootstrap in
/opt/data/.env, configuration in/opt/data/config.yaml, managed CLI at/opt/data/bin/bws, and cache at/opt/data/cache/bws_cache.json. - Bitwarden configuration uses
access_token_env: BWS_ACCESS_TOKEN, a 300-second cache TTL, automaticbwsinstallation, and exact-key export. - A permissions incident made
/opt/data/.envunreadable and caused repeated gatewayPermissionErrorresponses. It was fixed; at 2026-08-02 18:06 UTC both/opt/data/.envand/opt/data/config.yamlwere owned byhermes:hermeswith mode0600. gitea-repository-operations,gitea-docusaurus-projects, and the Discord knowledge-wiki Gitea creation workflow were updated to requireHL_V1_GITEA_ACCESS_TOKENand rejectGITHUB_TOKENforgitea.lego-cloud.eu. GitHub-specific workflows may continue usingGITHUB_TOKENforgithub.com.- The blank human message
1533511724370624693includedmessage.txt; its CDN URL returned HTTP 403 when this sync attempted retrieval, so its contents remain UNKNOWN. Subsequent messages and live verification establish the setup outcome above.
People & Roles
- RootAtSkic / Lego: configured Bitwarden and directed the Gitea credential migration.
- Hermes: validates secret integration without revealing values and maintains Gitea-related skills.
Action Items
- Owner: infrastructure operator / Lego — due date UNKNOWN: restart the Hermes gateway once so
HL_V1_GITEA_ACCESS_TOKENis imported into the gateway environment. - Owner: Hermes — due date after restart: verify gateway access to
HL_V1_GITEA_ACCESS_TOKENwithout displaying the value, then use it for future authenticated Gitea API operations.
Source Anchors
- Latest processed human message:
1533516194106048725(2026-08-02 16:45 UTC). - Decision thread: human messages
1533507837391798413through1533516194106048725(2026-08-02 16:12–16:45 UTC), with bot responses used only to establish implementation and verification outcomes.