diff --git a/hermes/.env.example b/hermes/.env.example index a4d62a7..05244da 100644 --- a/hermes/.env.example +++ b/hermes/.env.example @@ -11,12 +11,6 @@ HERMES_DASHBOARD_PASSWORD= # Signs dashboard sessions; keep it stable. Generate with: openssl rand -hex 32 HERMES_DASHBOARD_SECRET= -# Telegram gateway: bot token, then comma-separated user ids and group chat ids -# allowed to talk to it. An empty token leaves Telegram off. -TELEGRAM_BOT_TOKEN= -TELEGRAM_ALLOWED_USERS= -TELEGRAM_GROUP_ALLOWED_CHATS= - # Provider keys normally live in /opt/data/.env, set from the dashboard. # Uncomment here and in compose.yml to pass one from the environment instead. # OPENROUTER_API_KEY= diff --git a/hermes/README.md b/hermes/README.md index a99a636..28a1bf2 100644 --- a/hermes/README.md +++ b/hermes/README.md @@ -25,8 +25,6 @@ on port `9119`. | `HERMES_DASHBOARD_PUBLIC_URL` | — | Full public URL, e.g. `https://hermes.example.com` | | `HERMES_DASHBOARD_USERNAME` / `HERMES_DASHBOARD_PASSWORD` | `hermes` / — | Dashboard login | | `HERMES_DASHBOARD_SECRET` | — | Signs dashboard sessions | -| `TELEGRAM_BOT_TOKEN` | empty | Telegram bot; empty leaves Telegram off | -| `TELEGRAM_ALLOWED_USERS` / `TELEGRAM_GROUP_ALLOWED_CHATS` | empty | Telegram users and group chats allowed to use the bot | | `OPENROUTER_API_KEY`, `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GOOGLE_API_KEY` | optional | Provider keys passed from the environment | The dashboard refuses to start on a non-loopback bind without an auth @@ -38,11 +36,35 @@ for a public domain. `HERMES_DASHBOARD_PUBLIC_URL` adds the domain to the dashboard's Host and WebSocket Origin guard, which rejects requests for any other host. `HERMES_DASHBOARD_SECRET` keeps sessions valid across restarts; without it -each restart signs with a new random key. +each restart signs with a new random key. It must decode to at least 16 +bytes (base64, hex, or raw text), or the password provider does not load and +the dashboard refuses to start; `openssl rand -hex 32` is long enough. -Provider keys are commented out because upstream keeps them in -`/opt/data/.env`, written from the dashboard, so they survive without being -repeated in Coolify. An environment variable, when set, wins over that file. +Hermes loads `/opt/data/.env` over the process environment, so a key set in +both takes the file's value. Provider keys are commented out because upstream +keeps them in that file, written from the dashboard. + +## Chat platforms + +Telegram and the other gateway platforms are configured in the dashboard +under Messaging, which writes `TELEGRAM_BOT_TOKEN`, `TELEGRAM_ALLOWED_USERS`, +`TELEGRAM_GROUP_ALLOWED_CHATS` and their equivalents to `/opt/data/.env` and +restarts the gateway. They are not passed from Coolify, so that file is the +one place they are set. + +The Coolify environment cannot be the source for them. The gateway runs with +`multiplex_profiles` on by default, and in that mode its allow-lists read +only the profile's `.env`, never the container environment: with +`TELEGRAM_ALLOWED_USERS` set only in Coolify, the bot connects but blocks +every user. Turning multiplexing off (`GATEWAY_MULTIPLEX_PROFILES=false`) +would make the environment count again, but the file still wins for any key +it holds, and the dashboard's Messaging setup writes those keys there, so a +Coolify value would be silently overridden the first time the dashboard is +used. + +To edit a value by hand, change it in `/opt/data/.env` from a shell in the +container, as the `hermes` user, then run +`/opt/hermes/.venv/bin/hermes gateway restart`. ## Storage diff --git a/hermes/compose.yml b/hermes/compose.yml index 927bc62..9a305e8 100644 --- a/hermes/compose.yml +++ b/hermes/compose.yml @@ -9,9 +9,6 @@ services: - HERMES_DASHBOARD_BASIC_AUTH_USERNAME=${HERMES_DASHBOARD_USERNAME:-hermes} - HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=${HERMES_DASHBOARD_PASSWORD:?required} - HERMES_DASHBOARD_BASIC_AUTH_SECRET=${HERMES_DASHBOARD_SECRET:?required} - - TELEGRAM_BOT_TOKEN=${TELEGRAM_BOT_TOKEN:-} - - TELEGRAM_ALLOWED_USERS=${TELEGRAM_ALLOWED_USERS:-} - - TELEGRAM_GROUP_ALLOWED_CHATS=${TELEGRAM_GROUP_ALLOWED_CHATS:-} # - OPENROUTER_API_KEY=${OPENROUTER_API_KEY:-} # - ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY:-} # - OPENAI_API_KEY=${OPENAI_API_KEY:-}