Agent skill

Hermes Production Gateway Operations

by hewi333 in hewi333/Mom-n-Pop-Skills

Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.

MITAuto-check: warningsDevOps & Cloud

Install Hermes Production Gateway Operations

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hewi333/Mom-n-Pop-Skills hermes-production-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hewi333/Mom-n-Pop-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hermes-production-ops .claude/skills/hermes-production-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hermes-production-ops
GitHub stars
122
Token cost
~2k tokens
SKILL.md length
854 words
Files
3 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.

  • Works in 3 steps: Verify the new model exists on the… → Edit config.yaml (at… → Restart the gateway for changes to take…
  • Switching the global model or provider on a running Hermes gateway
  • SKILL.md covers When to Use, Model/Provider Switching…, Suppressing Gateway Restart… and Streaming & Progress Config…, plus 3 more sections
  • Calls curl and python3; reaches api.together.xyz; needs TOGETHER_API_KEY

What it does

The gateway is treated as a service that cannot go down, and its users should never see operational noise like restart pings or progress messages. For a global model switch, the skill says to confirm the provider actually lists the new model first, using the Together AI models endpoint as the example, then update both model.default and the matching custom_providers entry in ~/.hermes/config.yaml and restart the gateway, since changes do not apply mid-conversation.

Because the agent normally runs without sudo, it cannot restart hermes-gateway.service itself. After one failed attempt it should hand that step to the operator instead of trying workarounds that each stream a message to end-users. The skill also covers rollback when a new model breaks tool calling, and has two reference notes on restart notifications and on streaming and progress settings.

When your agent uses it

  • Switching the global model or provider on a running Hermes gateway
  • Planning a gateway restart with the least disruption to users
  • Stopping restart and startup notifications from reaching end-users
  • Tuning streaming and progress settings for a messaging deployment

Example prompts

  • “Switch our Hermes gateway from GLM-5.2 to GLM-5.3, checking that the provider lists it first.”
  • “Stop the gateway from pinging users every time it restarts.”
  • “Plan a gateway restart that an operator can run over SSH.”
  • “Roll back the model change, because tool calls started failing.”

Requirements

  • A running Hermes gateway with access to ~/.hermes/config.yaml
  • An operator with SSH and sudo to restart hermes-gateway.service
  • A provider API key such as TOGETHER_API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Verify the new model exists on the provider before changing config.
  2. Edit config.yaml (at ~/.hermes/config.yaml)
  3. Restart the gateway for changes to take effect

What it can do on your machine

Read from SKILL.md and the folder at commit 70a2273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.together.xyz

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TOGETHER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hermes Production Gateway Operations loads about 2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 854 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteRuns commands with sudoSKILL.md:51
    sudo systemctl restart hermes-gateway.service
  • NoteRuns commands with sudoSKILL.md:149
    4. Have the operator restart via SSH: `sudo systemctl restart hermes-gateway.service`
  • NoteMentions a .env fileSKILL.md:157
    ~/.hermes/.env              API keys and secrets
  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:165
    ges require a restart to take effect.** Do not tell the user
  • NoteRuns commands with sudoSKILL.md:181
    `sudo systemctl stop hermes-gateway.service`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hewi333/Mom-n-Pop-Skills at commit 70a2273, republished under its MIT licence (© hewi333). 854 words, ~1,993 tokens.

Download SKILL.mdSave it as .claude/skills/hermes-production-ops/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
hermes-production-ops
description
Operate and maintain a live production Hermes gateway deployment: switch models/providers globally, manage gateway restarts, suppress operational notifications to end-users, tune streaming/progress config for messaging platforms, and recover from stuck states without sudo. Use when changing the global model, planning a gateway restart, or configuring platform behavior for end-user-facing deployments.
version
1.0.0
author
Hermes Agent
license
MIT

Hermes Production Gateway Operations

Techniques for operating a live production Hermes gateway that serves non-technical end-users via Telegram (or other messaging platforms). The core constraint: the gateway cannot go down and end-users should not see operational noise (restart pings, progress spam, error messages, technical detail).

When to Use

  • Switching the global model or provider (e.g., GLM-5.2 → GLM-5.3)
  • Suppressing gateway restart/startup notifications to end-users
  • Tuning streaming/progress config for a messaging deployment
  • Planning a gateway restart that minimizes disruption
  • Any config change that requires a gateway restart to take effect

Model/Provider Switching (Global)

Workflow
  1. Verify the new model exists on the provider before changing config. For Together AI, hit the models endpoint with the API key:

    bash
    curl -s "https://api.together.xyz/v1/models" \
         -H "Authorization: Bearer $TOGETHER_API_KEY" -o /tmp/models.json
    python3 -c "import json; [print(m['id']) for m in json.load(open('/tmp/models.json')) if 'glm' in m['id'].lower()]"

    Pitfall: Never blindly change the model string without confirming it's listed. A typo or unlisted model name will break all gateway sessions silently until rollback.

  2. Edit config.yaml (at ~/.hermes/config.yaml):

    • model.default: change the model string (e.g., zai-org/GLM-5.2 → zai-org/GLM-5.3)
    • custom_providers: update the model: field in the matching provider entry
    • Both must match — model.default is what the agent uses; the custom_providers entry is the named provider definition.
  3. Restart the gateway for changes to take effect:

    bash
    sudo systemctl restart hermes-gateway.service

    Config changes do NOT apply mid-conversation. The gateway must restart.

No-Sudo Constraint

The agent process typically runs without sudo. It cannot stop or restart hermes-gateway.service itself — the operator must do this via SSH. hermes gateway restart from inside a tool call also requires elevated privileges. This is a security feature, not a bug: recognize it after one failed attempt and hand the action to the operator instead of trying five workarounds in sequence (each failed attempt is a tool call, and under tool_progress: all each one streams a message to end-users).

Rollback

If the new model has issues (tool-calling failures, format incompatibility), revert model.default and the custom_providers model field to the previous value and restart again. Always note the previous model string before switching.

Suppressing Gateway Restart Notifications

Problem: by default, every gateway restart sends two messages to every connected home channel:

  • Shutdown: "⚠️ Gateway restarting — Your current task will be interrupted..."
  • Startup: "♻️ Gateway online — Hermes is back and ready."

For non-technical end-users these are confusing noise that prompts them to text the operator asking what broke.

Solution: set gateway_restart_notification: false per platform in config.yaml. This suppresses BOTH messages for that platform:

yaml
telegram:
  gateway_restart_notification: false

Or via CLI: hermes config set telegram.gateway_restart_notification false (requires a gateway restart — config is read at startup).

What It Suppresses
MessageWhenSuppressed?
"⚠️ Gateway restarting/shutting down..."Before drain (active sessions only)Yes
"♻️ Gateway online — Hermes is back and ready."On startup (home channels)Yes
What It Does NOT Suppress
  • /restart initiated from within a chat still sends a reply to that specific chat. The flag only affects the broadcast to home channels and the shutdown notification to active sessions.
  • Messages from the agent during normal operation are unaffected.
Implementation Detail

The flag lives in gateway/config.py as gateway_restart_notification: bool = True on the PlatformConfig dataclass, serialized as <platform>.gateway_restart_notification. It's checked in two places in gateway/run.py: _notify_active_sessions_of_shutdown() and _send_home_channel_startup_notifications() — each skips platforms where the flag is false. For source detail, see references/gateway-restart-notifications.md.

Show full SKILL.md (345 more words)Show less

Streaming & Progress Config for End-User Deployments

The default progress settings are tuned for an operator watching a terminal, not for a business owner reading Telegram. The problematic combination:

  • gateway.tool_progress: all — sends a progress message for EVERY tool call
  • generous agent.max_turns — allows long multi-tool turns
  • streaming enabled on the platform

A 30-tool-call turn (legitimate work — building an integration, debugging) produces 30 streaming progress messages. To end-users this looks like the agent glitching or looping, and it fires the "what's wrong??" texts.

Recommended config for messaging deployments:

yaml
# config.yaml
gateway:
  tool_progress: final           # or 'summary' — NOT 'all' for end-user platforms
  long_running_notifications: true   # keep — useful for genuinely long tasks
agent:
  max_turns: 40-75               # 150 (default) is too generous for messaging

For the full diagnostic — log signatures, config interactions, cascading delegation re-entry, and what a flood looks like in the logs — see references/gateway-streaming-config.md.

Planning a Safe Restart

  1. Check if any sessions are actively running (ask the operator or check logs)
  2. Set gateway_restart_notification: false if not already done
  3. Make config changes
  4. Have the operator restart via SSH: sudo systemctl restart hermes-gateway.service
  5. Verify the gateway came back: hermes gateway status
  6. Verify the new model is active: hermes config | grep -A2 Model

Key Config Locations

~/.hermes/config.yaml       Main config (model, providers, platform settings)
~/.hermes/.env              API keys and secrets
~/.hermes/logs/gateway.log  Gateway logs for debugging

Pitfalls

  • Never change a model string without verifying it exists on the provider. A bad model name breaks ALL sessions until rollback.
  • Config changes require a restart to take effect. Do not tell the user the change is "done" until the gateway has been restarted.
  • The agent has no sudo. It cannot restart the gateway. Plan for the operator to do this via SSH — and don't burn five tool calls rediscovering that fact.
  • Restart notifications confuse end-users. Set gateway_restart_notification: false before any planned restart.
  • Cron jobs inherit the global model. Switching the default model affects all cron jobs that don't have a per-job model override.
  • Background threads compound outages. Auto skill-review threads and background delegations make their own API calls. During a provider outage or credit exhaustion, each thread retries independently — the session looks stuck while multiple retry loops burn wall-clock time. Know what runs concurrently on your deployment.
  • Killing the PID under systemd is futile. Restart=always revives the gateway in seconds. Properly stopping it requires the service unit: sudo systemctl stop hermes-gateway.service.

© hewi333, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/hermes-production-ops of hewi333/Mom-n-Pop-Skills.

  • SKILL.md
  • references/gateway-restart-notifications.md
  • references/gateway-streaming-config.md

Open the folder on GitHubat commit 70a2273

Compare with similar skills

Hermes Production Gateway Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hermes Production Gateway Operations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hermes Production Gateway Operations this skillhewi333/Mom-n-Pop-Skills122—~2kAutomated safety check: WarnMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Protocol Deploymentsablier-labs/evm-monorepo353—~3.8kAutomated safety check: NotesCustom licence
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Deploy Agent Sessionsjazzyalex/agent-sessions895—~817Automated safety check: PassMIT
Distill Shieldagenmod/immortal-skill1.1k—~408Automated safety check: PassMIT

Similar skills

  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Protocol Deployment

    sablier-labs/evm-monorepo

    Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~3.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Deploy Agent Sessions

    jazzyalex/agent-sessions

    Release/deploy workflow for Agent Sessions (Sparkle appcast + GitHub release).

    895 GitHub stars~817 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Distill Shield

    agenmod/immortal-skill

    Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。

    1.1k GitHub stars~408 tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Hermes Agent Production Ops

    Hermes-brasil/hermes-brasil

    A runbook, written in Portuguese, for keeping Hermes Agent healthy on a VPS: updates, gateway restarts, health checks and hosts without a systemd user bus.

    154 GitHub stars~1.2k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes

More from hewi333/Mom-n-Pop-Skills

All 13 skills in this repo
  • Construction Business Agent

    hewi333/Mom-n-Pop-Skills

    Runs a construction company's back office by bridging Gmail, Drive and JobTread: routing email attachments to the PM system, checking project status and sending daily Telegram briefings.

    122 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Lead-to-Payment Sales Flow

    hewi333/Mom-n-Pop-Skills

    Runs a small service business lead from intake through estimate, owner approval over Telegram, Stripe payment link and customer email draft to payment tracking.

    122 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • QuickBooks Online Integration

    hewi333/Mom-n-Pop-Skills

    Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.

    122 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • CRM Lite

    hewi333/Mom-n-Pop-Skills

    A skill your agent uses when tracking customer interactions, managing leads, or building a lightweight CRM for small businesses without dedicated CRM software.

    122 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Estimator Engine

    hewi333/Mom-n-Pop-Skills

    A skill your agent uses when calculating service estimates for jobs.

    122 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Mailchimp Integration

    hewi333/Mom-n-Pop-Skills

    A skill your agent uses when integrating with Mailchimp for audience management, campaigns, and automation.

    122 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hermes Production Gateway Operations

What does Hermes Production Gateway Operations do?

Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram. The gateway is treated as a service that cannot go down, and its users should never see operational noise like restart pings or progress messages.yaml and restart the gateway, since changes do not apply mid-conversation.

When should I use Hermes Production Gateway Operations?

Hermes Production Gateway Operations fits situations like: switching the global model or provider on a running Hermes gateway; planning a gateway restart with the least disruption to users; stopping restart and startup notifications from reaching end-users; tuning streaming and progress settings for a messaging deployment.

How do I install Hermes Production Gateway Operations in Claude Code?

Run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a claude-code`. Or copy the skill folder (skills/hermes-production-ops in hewi333/Mom-n-Pop-Skills) into .claude/skills/hermes-production-ops in your project. Claude Code loads it when a task matches its description.

How do I install Hermes Production Gateway Operations in Codex?

Run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a codex`. Or copy the skill folder (skills/hermes-production-ops in hewi333/Mom-n-Pop-Skills) into .agents/skills/hermes-production-ops in your project. Codex loads it when a task matches its description.

Can I use Hermes Production Gateway Operations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hewi333/Mom-n-Pop-Skills --skill hermes-production-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hermes-production-ops, .gemini/skills/hermes-production-ops, .github/skills/hermes-production-ops and .opencode/skills/hermes-production-ops in your project.

What does Hermes Production Gateway Operations need to run?

Going by SKILL.md and its folder, Hermes Production Gateway Operations needs the command-line tools its instructions call (curl and python3) and credentials named TOGETHER_API_KEY. Our summary lists: A running Hermes gateway with access to ~/.hermes/config.yaml; An operator with SSH and sudo to restart hermes-gateway.service; A provider API key such as TOGETHER_API_KEY.

Does Hermes Production Gateway Operations access the network?

SKILL.md names 1 domain. In commands or code: api.together.xyz; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Hermes Production Gateway Operations safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hermes Production Gateway Operations use?

Hermes Production Gateway Operations is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hermes Production Gateway Operations use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Hermes Production Gateway Operations?

Skills that share tags, products or a category with Hermes Production Gateway Operations: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Protocol Deployment (sablier-labs/evm-monorepo, 353 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars) and Deploy Agent Sessions (jazzyalex/agent-sessions, 895 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hermes Production Gateway Operations?

hewi333 (a GitHub user) maintains it in hewi333/Mom-n-Pop-Skills, which has 122 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 11, 2026.

Source: hewi333/Mom-n-Pop-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.