Agent skill

Hermes Agent Production Ops

by Hermes-brasil in Hermes-brasil/hermes-brasil

A runbook, written in Portuguese, for keeping Hermes Agent healthy on a VPS: updates, gateway restarts, health checks and hosts without a systemd user bus.

MITAuto-check: notesDevOps & Cloud

SKILL.md written in Portuguese; this summary is our English description.

Install Hermes Agent Production Ops

skills CLI
$ npx skills add Hermes-brasil/hermes-brasil --skill hermes-ops-producao -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hermes-brasil/hermes-brasil hermes-ops-producao --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hermes-brasil/hermes-brasil.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hermes-ops-producao .claude/skills/hermes-ops-producao && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hermes-ops-producao
GitHub stars
154
Token cost
~1.2k tokens
SKILL.md length
460 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

A runbook, written in Portuguese, for keeping Hermes Agent healthy on a VPS: updates, gateway restarts, health checks and hosts without a systemd user bus.

  • Works in 4 steps: Backup em… → git pull no source (ex.:… → Reinstall no venv do projeto → …
  • Updating Hermes Agent on a production VPS and confirming the new version
  • SKILL.md covers Quando carregar, Update, Restart do gateway and Health-check ponta a ponta, plus 6 more sections
  • Calls git and pip

What it does

The skill collects procedures for keeping Hermes Agent running around the clock and is meant for use before and after an update, when the gateway disappears, when Telegram stops answering or when `systemctl --user` fails. An update is `hermes update`, then a mandatory `hermes version` check and `hermes doctor --fix`. The update normally backs up to `~/.hermes/backups/`, pulls the source, reinstalls in the project's virtual environment and builds the web UI. Pitfalls noted: a command timeout does not mean the update failed, the system `pip` must never be used, and the gateway may need a restart if messaging connections go stale.

For restarts it uses `hermes gateway restart` and warns that a graceful shutdown can outlast the CLI timeout while sessions drain, so check the PID and logs. Where the error Failed to connect to bus: No medium found appears, it avoids `systemctl --user`, finds the gateway process, sends it a TERM signal and relaunches through the Hermes supervisor or `hermes gateway run`. For systemd hosts it covers `loginctl enable-linger`, and a SIGKILL on stop is traced to `TimeoutStopSec`, with options such as `KillMode=process`. An end-to-end health check runs `hermes version`, `hermes doctor --fix` and `hermes status --all`.

When your agent uses it

  • Updating Hermes Agent on a production VPS and confirming the new version
  • Restarting a gateway that hangs or does not relaunch its processes
  • Diagnosing messages that never arrive although the status looks fine
  • Operating in an environment where the systemd user bus is unavailable

Example prompts

  • “Update Hermes on the VPS and confirm the new version actually installed.”
  • “The gateway restart hangs, so find the process and relaunch it.”
  • “Hermes status looks fine but Telegram messages are not arriving, run the health check.”
  • “Stopping the gateway fails with Failed to connect to bus: No medium found, what should I do?”

Requirements

  • A VPS running Hermes Agent
  • Shell access to the host

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Backup em ~/.hermes/backups/pre-update-YYYY-MM-DD-HHMMSS...
  2. git pull no source (ex.: /usr/local/lib/hermes-agent em install root FHS)
  3. Reinstall no venv do projeto
  4. Build da web UI se existir

What it can do on your machine

Read from SKILL.md and the folder at commit 8f94818. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • hermes-agent.nousresearch.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hermes Agent Production Ops loads about 1.2k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 460 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:69
    sudo loginctl enable-linger "$USER"
  • NoteMentions a .env fileSKILL.md:134
    - `.env` e tokens fora de git e de skill pública

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hermes-brasil/hermes-brasil at commit 8f94818, republished under its MIT licence (© Hermes-brasil). 460 words, ~1,197 tokens.

Download SKILL.mdSave it as .claude/skills/hermes-ops-producao/SKILL.md (or your agent's skills folder).
name
hermes-ops-producao
description
Operar Hermes Agent em produção no VPS — update, restart de gateway, health-check, profiles múltiplos e ambientes sem systemd user bus.

Hermes Ops — Produção

Procedimentos para manter o Hermes Agent saudável 24/7. Use antes/depois de update, quando o gateway “some”, quando Telegram para de responder, ou quando systemctl --user falha.

Guia longo: guides/instalacao-producao-vps.md neste repositório.

Quando carregar

  • hermes update / dúvida se a versão subiu
  • hermes gateway restart trava ou não relança processos
  • hermes status ok mas mensagem não chega
  • Erro Failed to connect to bus: No medium found
  • Pós-reboot do VPS

Update

bash
hermes update
hermes version          # obrigatório validar
hermes doctor --fix

O update tipicamente:

  1. Backup em ~/.hermes/backups/pre-update-YYYY-MM-DD-HHMMSS...
  2. git pull no source (ex.: /usr/local/lib/hermes-agent em install root FHS)
  3. Reinstall no venv do projeto
  4. Build da web UI se existir

Pitfalls

  • Timeout do comando ≠ update falhou. Backup grande demora; confira hermes version.
  • Nunca use pip do sistema. Fallback manual: cd no source e ./venv/bin/pip install -e .
  • Depois do update, reinicie gateway se as conexões de messaging ficarem stale

Restart do gateway

bash
hermes gateway restart
# se a CLI aceitar na sua versão:
hermes gateway status
ps aux | grep 'gateway run' | grep -v grep

Graceful shutdown pode estourar timeout da CLI enquanto o processo ainda está drenando sessões. Olhe o PID e os logs.

Sem systemd user bus
bash
systemctl --user stop hermes-gateway
# → Failed to connect to bus: No medium found

Nesse ambiente:

  1. Não dependa de systemctl --user
  2. ps aux | grep 'gateway run'
  3. kill -TERM <pid> no gateway principal
  4. Relançar via supervisor do Hermes, hermes gateway run, ou o unit/supervisor que você configurou no host

Se a imagem permitir systemd de verdade:

bash
sudo loginctl enable-linger "$USER"
# units em ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user restart hermes-gateway
SIGKILL no stop (systemd)

Se o journal mostra status=9/KILL no restart, o gateway passou de TimeoutStopSec drenando agentes. Mitigações comuns:

  • Aumentar TimeoutStopSec no unit
  • KillMode=process (não mata cgroup inteiro de uma vez)
  • Ajustar timeouts de drain/inactivity na config.yaml do Hermes

Health-check ponta a ponta

Ordem curta:

bash
hermes version
hermes doctor --fix
hermes status --all
tail -40 ~/.hermes/logs/gateway.log
tail -20 ~/.hermes/logs/errors.log
hermes send --to telegram:CHAT_ID "ping pós-ops"
# fórum/tópico:
hermes send --to telegram:CHAT_ID:THREAD_ID "ping thread"

Checklist mental:

CheckOK se
Versãostring de versão + commit recente
Doctorsem erro bloqueante
Processogateway run presente
Sendmensagem chega no app
Cronhermes cron list sem rain de last_status ruim
Show full SKILL.md (169 more words)Show less

Avisos comuns (muitas vezes não-críticos)

  • Home-channel startup notification failed: send_path_degraded — confirme com hermes send
  • API server network-accessible AND terminal backend local — risco de desenho; não “ignore para sempre” se a API está pública
  • Secret redaction: DISABLED — ligue se quiser: hermes config set security.redact_secrets true
  • Running as ROOT — comum em VPS single-tenant; ciente do blast radius

Profiles múltiplos

bash
hermes profile list
ps aux | grep 'hermes.*-p \|gateway run' | grep -v grep

Após update/restart, confira se o default voltou. Workers Kanban usam -p <profile> no spawn — profile inexistente = task pronta que nunca anda (assignee fantasma).

Ver: guides/profiles-e-kanban.md

Cron (ponte)

Jobs de produção: prompt autocontido, delivery explícito, ledger se muta o mundo, script = filename em ~/.hermes/scripts/.

Ver: guides/cron-em-producao.md

Segurança operacional rápida

  • .env e tokens fora de git e de skill pública
  • Preferir approve mode consciente em gateway (approvals.mode)
  • Não expor API server + shell local na internet sem auth e rede restrita
  • Backup de ~/.hermes antes de migração grande (hermes backup se disponível na versão)

Comandos de bolso

bash
hermes version
hermes doctor --fix
hermes status --all
hermes update
hermes gateway status
hermes gateway restart
hermes cron list
hermes profile list
hermes logs                 # se disponível
tail -f ~/.hermes/logs/gateway.log

Referências

© Hermes-brasil, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hermes-ops-producao of Hermes-brasil/hermes-brasil.

Open the folder on GitHubat commit 8f94818

Compare with similar skills

Hermes Agent Production Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hermes Agent Production Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hermes Agent Production Ops this skillHermes-brasil/hermes-brasil154—~1.2kAutomated safety check: NotesMIT
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Openbkn Deployopenbkn-ai/bkn-foundry661—~1.9kAutomated safety check: NotesCustom licence
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Setup Cpu Proxy Serverdrawthingsai/draw-things-community584—~3.8kAutomated safety check: PassGPL-3.0
Linux Troubleshooting with Inspektor Gadgetinspektor-gadget/inspektor-gadget2.9k—~2.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Openbkn Deploy

    openbkn-ai/bkn-foundry

    Deploy or upgrade OpenBKN on a customer-authorized Linux server through the repository's deploy scripts, with preflight checks, explicit confirmation, secret handling, and post-deployment…

    661 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    584 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Linux Troubleshooting with Inspektor Gadget

    inspektor-gadget/inspektor-gadget

    Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes.

    2.9k GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Termux Safe

    ferrumclaudepilgrim/claude-code-android

    Android/Termux constraints reference. An agent skill from ferrumclaudepilgrim/claude-code-android.

    268 GitHub stars~935 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from Hermes-brasil/hermes-brasil

All 8 skills in this repo
  • Hermes Podcast Insights

    Hermes-brasil/hermes-brasil

    Portuguese notes on a podcast interview with a Nous Research co-founder about Hermes Agent: memory over models, self-improvement, anti-sycophancy and open source.

    154 GitHub stars~802 tokensUpdated 6 days ago
    Auto-check passed
  • Human and Agent Kanban Orchestration

    Hermes-brasil/hermes-brasil

    Runs a project on one Kanban board shared by people and AI agents, where a dispatcher splits goals into tasks and any task can go to either a human or an agent.

    154 GitHub stars~738 tokensUpdated 6 days ago
    Auto-check passed
  • Local Business B2B Prospecting

    Hermes-brasil/hermes-brasil

    Runs a B2B prospecting pipeline for local shops in Brazil: Google Places lead collection, WhatsApp or Instagram filtering, messaging and SQLite logging.

    154 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • RAG Company Knowledge Assistant

    Hermes-brasil/hermes-brasil

    Portuguese guide to building a retrieval-augmented generation assistant over a company's documents, with embeddings, section-based chunking, retrieval and a client workflow.

    154 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Think Tank Research

    Hermes-brasil/hermes-brasil

    Use quando precisar de pesquisa multi-persona com síntese protegida por evidências.

    154 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check passed
  • Triagem Conteudo Externo

    Hermes-brasil/hermes-brasil

    Tratar conteúdo externo não confiável antes de agir. An agent skill from Hermes-brasil/hermes-brasil.

    154 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Hermes Agent Production Ops

What does Hermes Agent Production Ops do?

A runbook, written in Portuguese, for keeping Hermes Agent healthy on a VPS: updates, gateway restarts, health checks and hosts without a systemd user bus. The skill collects procedures for keeping Hermes Agent running around the clock and is meant for use before and after an update, when the gateway disappears, when Telegram stops answering or when `systemctl --user` fails. An update is `hermes update`, then a mandatory `hermes version` check and `hermes doctor --fix`.

When should I use Hermes Agent Production Ops?

Hermes Agent Production Ops fits situations like: updating Hermes Agent on a production VPS and confirming the new version; restarting a gateway that hangs or does not relaunch its processes; diagnosing messages that never arrive although the status looks fine; operating in an environment where the systemd user bus is unavailable.

How do I install Hermes Agent Production Ops in Claude Code?

Run `npx skills add Hermes-brasil/hermes-brasil --skill hermes-ops-producao -a claude-code`. Or copy the skill folder (skills/hermes-ops-producao in Hermes-brasil/hermes-brasil) into .claude/skills/hermes-ops-producao in your project. Claude Code loads it when a task matches its description.

How do I install Hermes Agent Production Ops in Codex?

Run `npx skills add Hermes-brasil/hermes-brasil --skill hermes-ops-producao -a codex`. Or copy the skill folder (skills/hermes-ops-producao in Hermes-brasil/hermes-brasil) into .agents/skills/hermes-ops-producao in your project. Codex loads it when a task matches its description.

Can I use Hermes Agent Production Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hermes-brasil/hermes-brasil --skill hermes-ops-producao -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hermes-ops-producao, .gemini/skills/hermes-ops-producao, .github/skills/hermes-ops-producao and .opencode/skills/hermes-ops-producao in your project.

What does Hermes Agent Production Ops need to run?

Going by SKILL.md and its folder, Hermes Agent Production Ops needs the command-line tools its instructions call (git and pip). Our summary lists: A VPS running Hermes Agent; Shell access to the host.

Does Hermes Agent Production Ops access the network?

SKILL.md names 1 domain. As links in the text: hermes-agent.nousresearch.com. This is read from the text; nothing was executed.

Is Hermes Agent Production Ops safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo; mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Hermes Agent Production Ops use?

Hermes Agent Production Ops is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hermes Agent Production Ops use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hermes Agent Production Ops?

Skills that share tags, products or a category with Hermes Agent Production Ops: Openclaw Live Updater (openclaw/openclaw, 392k stars), Openbkn Deploy (openbkn-ai/bkn-foundry, 661 stars), Minimega (sandia-minimega/minimega, 160 stars) and Setup Cpu Proxy Server (drawthingsai/draw-things-community, 584 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hermes Agent Production Ops?

Hermes-brasil (a GitHub organization) maintains it in Hermes-brasil/hermes-brasil, which has 154 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 5, 2026.

Source: Hermes-brasil/hermes-brasil on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.