Prepare Cloudflare Production Deployment
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hermes-production-ops .claude/skills/hermes-production-ops && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .claude/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-opsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hermes-production-ops .agents/skills/hermes-production-ops && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .agents/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hermes-production-ops .cursor/skills/hermes-production-ops && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .cursor/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hewi333/Mom-n-Pop-Skills.git --path skills/hermes-production-ops--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hermes-production-ops .gemini/skills/hermes-production-ops && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .gemini/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-opsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hermes-production-ops .github/skills/hermes-production-ops && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .github/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hermes-production-ops .opencode/skills/hermes-production-ops && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hermes-production-ops" agent skill from https://github.com/hewi333/Mom-n-Pop-Skills/tree/main/skills/hermes-production-ops into .opencode/skills/hermes-production-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hermes-production-ops", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hermes-production-opsProcedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.
The gateway is treated as a service that cannot go down, and its users should never see operational noise like restart pings or progress messages. For a global model switch, the skill says to confirm the provider actually lists the new model first, using the Together AI models endpoint as the example, then update both model.default and the matching custom_providers entry in ~/.hermes/config.yaml and restart the gateway, since changes do not apply mid-conversation.
Because the agent normally runs without sudo, it cannot restart hermes-gateway.service itself. After one failed attempt it should hand that step to the operator instead of trying workarounds that each stream a message to end-users. The skill also covers rollback when a new model breaks tool calling, and has two reference notes on restart notifications and on streaming and progress settings.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 70a2273. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.together.xyzFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TOGETHER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hermes Production Gateway Operations loads about 2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 854 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
sudo systemctl restart hermes-gateway.service4. Have the operator restart via SSH: `sudo systemctl restart hermes-gateway.service`~/.hermes/.env API keys and secretsges require a restart to take effect.** Do not tell the user`sudo systemctl stop hermes-gateway.service`.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hewi333/Mom-n-Pop-Skills at commit 70a2273, republished under its MIT licence (© hewi333). 854 words, ~1,993 tokens.
.claude/skills/hermes-production-ops/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Techniques for operating a live production Hermes gateway that serves non-technical end-users via Telegram (or other messaging platforms). The core constraint: the gateway cannot go down and end-users should not see operational noise (restart pings, progress spam, error messages, technical detail).
Verify the new model exists on the provider before changing config. For Together AI, hit the models endpoint with the API key:
curl -s "https://api.together.xyz/v1/models" \
-H "Authorization: Bearer $TOGETHER_API_KEY" -o /tmp/models.json
python3 -c "import json; [print(m['id']) for m in json.load(open('/tmp/models.json')) if 'glm' in m['id'].lower()]"Pitfall: Never blindly change the model string without confirming it's listed. A typo or unlisted model name will break all gateway sessions silently until rollback.
Edit config.yaml (at ~/.hermes/config.yaml):
model.default: change the model string (e.g., zai-org/GLM-5.2 → zai-org/GLM-5.3)custom_providers: update the model: field in the matching provider entrymodel.default is what the agent uses; the
custom_providers entry is the named provider definition.Restart the gateway for changes to take effect:
sudo systemctl restart hermes-gateway.serviceConfig changes do NOT apply mid-conversation. The gateway must restart.
The agent process typically runs without sudo. It cannot stop or restart
hermes-gateway.service itself — the operator must do this via SSH.
hermes gateway restart from inside a tool call also requires elevated
privileges. This is a security feature, not a bug: recognize it after one
failed attempt and hand the action to the operator instead of trying five
workarounds in sequence (each failed attempt is a tool call, and under
tool_progress: all each one streams a message to end-users).
If the new model has issues (tool-calling failures, format incompatibility),
revert model.default and the custom_providers model field to the previous
value and restart again. Always note the previous model string before switching.
Problem: by default, every gateway restart sends two messages to every connected home channel:
For non-technical end-users these are confusing noise that prompts them to text the operator asking what broke.
Solution: set gateway_restart_notification: false per platform in
config.yaml. This suppresses BOTH messages for that platform:
telegram:
gateway_restart_notification: falseOr via CLI: hermes config set telegram.gateway_restart_notification false
(requires a gateway restart — config is read at startup).
| Message | When | Suppressed? |
|---|---|---|
| "⚠️ Gateway restarting/shutting down..." | Before drain (active sessions only) | Yes |
| "♻️ Gateway online — Hermes is back and ready." | On startup (home channels) | Yes |
/restart initiated from within a chat still sends a reply to that
specific chat. The flag only affects the broadcast to home channels and
the shutdown notification to active sessions.The flag lives in gateway/config.py as gateway_restart_notification: bool = True
on the PlatformConfig dataclass, serialized as
<platform>.gateway_restart_notification. It's checked in two places in
gateway/run.py: _notify_active_sessions_of_shutdown() and
_send_home_channel_startup_notifications() — each skips platforms where
the flag is false. For source detail, see
references/gateway-restart-notifications.md.
The default progress settings are tuned for an operator watching a terminal, not for a business owner reading Telegram. The problematic combination:
gateway.tool_progress: all — sends a progress message for EVERY tool callagent.max_turns — allows long multi-tool turnsA 30-tool-call turn (legitimate work — building an integration, debugging) produces 30 streaming progress messages. To end-users this looks like the agent glitching or looping, and it fires the "what's wrong??" texts.
Recommended config for messaging deployments:
# config.yaml
gateway:
tool_progress: final # or 'summary' — NOT 'all' for end-user platforms
long_running_notifications: true # keep — useful for genuinely long tasks
agent:
max_turns: 40-75 # 150 (default) is too generous for messagingFor the full diagnostic — log signatures, config interactions, cascading
delegation re-entry, and what a flood looks like in the logs — see
references/gateway-streaming-config.md.
gateway_restart_notification: false if not already donesudo systemctl restart hermes-gateway.servicehermes gateway statushermes config | grep -A2 Model~/.hermes/config.yaml Main config (model, providers, platform settings)
~/.hermes/.env API keys and secrets
~/.hermes/logs/gateway.log Gateway logs for debugginggateway_restart_notification: false before any planned restart.Restart=always revives the
gateway in seconds. Properly stopping it requires the service unit:
sudo systemctl stop hermes-gateway.service.© hewi333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/hermes-production-ops of hewi333/Mom-n-Pop-Skills.
Open the folder on GitHubat commit 70a2273
Hermes Production Gateway Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hermes Production Gateway Operations this skillhewi333/Mom-n-Pop-Skills | 122 | — | ~2k | Automated safety check: Warn | MIT | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| Protocol Deploymentsablier-labs/evm-monorepo | 353 | — | ~3.8k | Automated safety check: Notes | Custom licence | |
| Activation Governance Chaos RolloutAli-Marandi/DataSense | 107 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Deploy Agent Sessionsjazzyalex/agent-sessions | 895 | — | ~817 | Automated safety check: Pass | MIT | |
| Distill Shieldagenmod/immortal-skill | 1.1k | — | ~408 | Automated safety check: Pass | MIT |
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
sablier-labs/evm-monorepo
Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.
Ali-Marandi/DataSense
Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.
jazzyalex/agent-sessions
Release/deploy workflow for Agent Sessions (Sparkle appcast + GitHub release).
agenmod/immortal-skill
Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。
Hermes-brasil/hermes-brasil
A runbook, written in Portuguese, for keeping Hermes Agent healthy on a VPS: updates, gateway restarts, health checks and hosts without a systemd user bus.
hewi333/Mom-n-Pop-Skills
Runs a construction company's back office by bridging Gmail, Drive and JobTread: routing email attachments to the PM system, checking project status and sending daily Telegram briefings.
hewi333/Mom-n-Pop-Skills
Runs a small service business lead from intake through estimate, owner approval over Telegram, Stripe payment link and customer email draft to payment tracking.
hewi333/Mom-n-Pop-Skills
Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.
hewi333/Mom-n-Pop-Skills
A skill your agent uses when tracking customer interactions, managing leads, or building a lightweight CRM for small businesses without dedicated CRM software.
hewi333/Mom-n-Pop-Skills
A skill your agent uses when calculating service estimates for jobs.
hewi333/Mom-n-Pop-Skills
A skill your agent uses when integrating with Mailchimp for audience management, campaigns, and automation.
Works with
Categories
Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram. The gateway is treated as a service that cannot go down, and its users should never see operational noise like restart pings or progress messages.yaml and restart the gateway, since changes do not apply mid-conversation.
Hermes Production Gateway Operations fits situations like: switching the global model or provider on a running Hermes gateway; planning a gateway restart with the least disruption to users; stopping restart and startup notifications from reaching end-users; tuning streaming and progress settings for a messaging deployment.
Run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a claude-code`. Or copy the skill folder (skills/hermes-production-ops in hewi333/Mom-n-Pop-Skills) into .claude/skills/hermes-production-ops in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a codex`. Or copy the skill folder (skills/hermes-production-ops in hewi333/Mom-n-Pop-Skills) into .agents/skills/hermes-production-ops in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hermes-production-ops, .gemini/skills/hermes-production-ops, .github/skills/hermes-production-ops and .opencode/skills/hermes-production-ops in your project.
Going by SKILL.md and its folder, Hermes Production Gateway Operations needs the command-line tools its instructions call (curl and python3) and credentials named TOGETHER_API_KEY. Our summary lists: A running Hermes gateway with access to ~/.hermes/config.yaml; An operator with SSH and sudo to restart hermes-gateway.service; A provider API key such as TOGETHER_API_KEY.
SKILL.md names 1 domain. In commands or code: api.together.xyz; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.
Hermes Production Gateway Operations is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hermes Production Gateway Operations: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Protocol Deployment (sablier-labs/evm-monorepo, 353 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars) and Deploy Agent Sessions (jazzyalex/agent-sessions, 895 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hewi333 (a GitHub user) maintains it in hewi333/Mom-n-Pop-Skills, which has 122 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 11, 2026.
Source: hewi333/Mom-n-Pop-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.