From 82892042dc9a6c72ede1b091179f5f3e6254fcfa Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Mon, 5 Oct 2026 17:35:34 +0700 Subject: [PATCH] fix(hermes): configure chat platforms in /opt/data/.env, not Coolify The gateway's allow-lists read only the profile .env under the default multiplex mode, so Telegram values passed from the environment left every user blocked. Drop the passthrough and document the dashboard as the one place to set them, plus the dashboard secret's 16-byte minimum. --- hermes/.env.example | 6 ------ hermes/README.md | 34 ++++++++++++++++++++++++++++------ hermes/compose.yml | 3 --- 3 files changed, 28 insertions(+), 15 deletions(-) diff --git a/hermes/.env.example b/hermes/.env.example index a4d62a7..05244da 100644 --- a/hermes/.env.example +++ b/hermes/.env.example @@ -11,12 +11,6 @@ HERMES_DASHBOARD_PASSWORD= # Signs dashboard sessions; keep it stable. Generate with: openssl rand -hex 32 HERMES_DASHBOARD_SECRET= -# Telegram gateway: bot token, then comma-separated user ids and group chat ids -# allowed to talk to it. An empty token leaves Telegram off. -TELEGRAM_BOT_TOKEN= -TELEGRAM_ALLOWED_USERS= -TELEGRAM_GROUP_ALLOWED_CHATS= - # Provider keys normally live in /opt/data/.env, set from the dashboard. # Uncomment here and in compose.yml to pass one from the environment instead. # OPENROUTER_API_KEY= diff --git a/hermes/README.md b/hermes/README.md index a99a636..28a1bf2 100644 --- a/hermes/README.md +++ b/hermes/README.md @@ -25,8 +25,6 @@ on port `9119`. | `HERMES_DASHBOARD_PUBLIC_URL` | — | Full public URL, e.g. `https://hermes.example.com` | | `HERMES_DASHBOARD_USERNAME` / `HERMES_DASHBOARD_PASSWORD` | `hermes` / — | Dashboard login | | `HERMES_DASHBOARD_SECRET` | — | Signs dashboard sessions | -| `TELEGRAM_BOT_TOKEN` | empty | Telegram bot; empty leaves Telegram off | -| `TELEGRAM_ALLOWED_USERS` / `TELEGRAM_GROUP_ALLOWED_CHATS` | empty | Telegram users and group chats allowed to use the bot | | `OPENROUTER_API_KEY`, `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, `GOOGLE_API_KEY` | optional | Provider keys passed from the environment | The dashboard refuses to start on a non-loopback bind without an auth @@ -38,11 +36,35 @@ for a public domain. `HERMES_DASHBOARD_PUBLIC_URL` adds the domain to the dashboard's Host and WebSocket Origin guard, which rejects requests for any other host. `HERMES_DASHBOARD_SECRET` keeps sessions valid across restarts; without it -each restart signs with a new random key. +each restart signs with a new random key. It must decode to at least 16 +bytes (base64, hex, or raw text), or the password provider does not load and +the dashboard refuses to start; `openssl rand -hex 32` is long enough. -Provider keys are commented out because upstream keeps them in -`/opt/data/.env`, written from the dashboard, so they survive without being -repeated in Coolify. An environment variable, when set, wins over that file. +Hermes loads `/opt/data/.env` over the process environment, so a key set in +both takes the file's value. Provider keys are commented out because upstream +keeps them in that file, written from the dashboard. + +## Chat platforms + +Telegram and the other gateway platforms are configured in the dashboard +under Messaging, which writes `TELEGRAM_BOT_TOKEN`, `TELEGRAM_ALLOWED_USERS`, +`TELEGRAM_GROUP_ALLOWED_CHATS` and their equivalents to `/opt/data/.env` and +restarts the gateway. They are not passed from Coolify, so that file is the +one place they are set. + +The Coolify environment cannot be the source for them. The gateway runs with +`multiplex_profiles` on by default, and in that mode its allow-lists read +only the profile's `.env`, never the container environment: with +`TELEGRAM_ALLOWED_USERS` set only in Coolify, the bot connects but blocks +every user. Turning multiplexing off (`GATEWAY_MULTIPLEX_PROFILES=false`) +would make the environment count again, but the file still wins for any key +it holds, and the dashboard's Messaging setup writes those keys there, so a +Coolify value would be silently overridden the first time the dashboard is +used. + +To edit a value by hand, change it in `/opt/data/.env` from a shell in the +container, as the `hermes` user, then run +`/opt/hermes/.venv/bin/hermes gateway restart`. ## Storage diff --git a/hermes/compose.yml b/hermes/compose.yml index 927bc62..9a305e8 100644 --- a/hermes/compose.yml +++ b/hermes/compose.yml @@ -9,9 +9,6 @@ services: - HERMES_DASHBOARD_BASIC_AUTH_USERNAME=${HERMES_DASHBOARD_USERNAME:-hermes} - HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=${HERMES_DASHBOARD_PASSWORD:?required} - HERMES_DASHBOARD_BASIC_AUTH_SECRET=${HERMES_DASHBOARD_SECRET:?required} - - TELEGRAM_BOT_TOKEN=${TELEGRAM_BOT_TOKEN:-} - - TELEGRAM_ALLOWED_USERS=${TELEGRAM_ALLOWED_USERS:-} - - TELEGRAM_GROUP_ALLOWED_CHATS=${TELEGRAM_GROUP_ALLOWED_CHATS:-} # - OPENROUTER_API_KEY=${OPENROUTER_API_KEY:-} # - ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY:-} # - OPENAI_API_KEY=${OPENAI_API_KEY:-}