80 Commits

Author SHA1 Message Date
jenkins
3229e5a67e fix(hermes): expose router to agent workspaces 2026-08-09 14:45:26 -03:00
jenkins
d71624410a fix(hermes): provision Cassandra diagnostics 2026-08-09 14:38:51 -03:00
jenkins
fc99d114a3 fix(hermes): route new agent tabs 2026-08-09 14:08:45 -03:00
jenkins
51fbddc051 security(hermes): update oauth boundaries 2026-08-09 13:49:40 -03:00
jenkins
772f05ac2e security(hermes): canary current oauth proxy 2026-08-09 13:40:58 -03:00
jenkins
0815021756 fix(hermes): recover expired chat callbacks 2026-08-09 13:33:36 -03:00
jenkins
1521fae348 fix(hermes): preserve reconnect history and browser access 2026-08-09 13:19:12 -03:00
jenkins
dad7d39c05 fix(hermes): enable browser tools and private files 2026-08-09 12:55:36 -03:00
jenkins
9bedec9cad fix(hermes): expose private files and reconnect Herdr 2026-08-09 09:33:30 -03:00
jenkins
ed7abc8ced feat(hermes): extend agent tool budget 2026-08-09 03:59:08 -03:00
jenkins
54fe5aaf15 fix(hermes): expose actual routed provider 2026-08-09 03:51:03 -03:00
jenkins
f2c9c003a5 fix(hermes): roll out chat iteration budgets 2026-08-09 03:30:22 -03:00
jenkins
9e9d2748c3 fix(hermes): prune duplicate coordinator workspaces 2026-08-09 03:21:00 -03:00
jenkins
04fca285d2 fix(hermes): keep Jetson route classifier warm 2026-08-09 03:13:21 -03:00
jenkins
169468ee58 fix(hermes): recover stale coordinator panes 2026-08-09 02:50:38 -03:00
jenkins
9bdcddad7c feat(hermes): add Jetson-assisted auto routing 2026-08-09 02:42:30 -03:00
jenkins
d14c23df59 fix(hermes): install native herdr integration 2026-08-09 01:35:38 -03:00
jenkins
8afe98606f fix(hermes): match versioned worker cleanup 2026-08-09 01:08:31 -03:00
jenkins
e182d19950 fix(hermes): recover agent and chat sessions 2026-08-09 01:04:27 -03:00
jenkins
ce89153497 fix(hermes): deploy isolated chat personalization 2026-08-09 00:22:11 -03:00
jenkins
432466156b fix(hermes): discover chat extraction backend 2026-08-08 23:59:05 -03:00
jenkins
90607e073b perf(hermes): avoid recursive chat volume chown 2026-08-08 23:47:50 -03:00
jenkins
e0e38a7f14 fix(hermes): avoid stalled chat image node 2026-08-08 23:44:49 -03:00
jenkins
7f8916c501 fix(hermes): reuse chat runtime for auth init 2026-08-08 23:40:17 -03:00
jenkins
3b3529691e fix(hermes): avoid broken chat storage node 2026-08-08 23:33:21 -03:00
jenkins
639ac031a8 feat(hermes): strengthen isolated chat reasoning 2026-08-08 23:25:16 -03:00
jenkins
a35e2ce337 fix(hermes): allow slow worker prompt startup 2026-08-08 22:44:11 -03:00
jenkins
1a05d4a1e3 fix(hermes): detect worker prompt readiness 2026-08-08 22:38:14 -03:00
jenkins
9fab37b387 fix(hermes): settle Claude prompts in HERDR 2026-08-08 22:31:34 -03:00
jenkins
a9f687f6e7 fix(hermes): allow agent TUI proxy egress 2026-08-08 22:11:35 -03:00
jenkins
17baaa8a24 feat(hermes): expose persistent agent TUI 2026-08-08 22:05:39 -03:00
jenkins
5bb04b37c7 fix(hermes): restore isolated user features 2026-08-08 21:28:33 -03:00
jenkins
66eb0717ef fix(hermes): request supported OIDC scopes 2026-08-08 20:08:44 -03:00
jenkins
97e0113aa8 fix(hermes): exclude runtime-stalled worker 2026-08-08 19:23:58 -03:00
jenkins
d0e2668409 fix(hermes): use WebUI for control surfaces 2026-08-08 19:18:33 -03:00
jenkins
3250f6d9d4 fix(hermes): allow coordinator startup to finish 2026-08-08 19:05:17 -03:00
jenkins
62312cc4ce fix(hermes): run triage gateway as nonroot 2026-08-08 19:01:14 -03:00
jenkins
29d2d74079 fix(hermes): avoid unhealthy session nodes 2026-08-08 18:42:13 -03:00
jenkins
7ebc44596b fix(hermes): right-size coordinator requests 2026-08-08 18:34:52 -03:00
jenkins
249628a4fa fix(hermes): avoid storage-unready accelerators 2026-08-08 18:27:22 -03:00
jenkins
04b42b1208 fix(hermes): harden non-root startup 2026-08-08 18:17:30 -03:00
jenkins
c03bdb248f fix(hermes): retain oauth tokens for cookie refresh 2026-08-08 18:08:03 -03:00
jenkins
af84a11bb7 fix(hermes): use supported oauth proxy flags 2026-08-08 18:05:19 -03:00
jenkins
bb73efb285 feat(hermes): split chat agent and triage surfaces 2026-08-08 17:59:57 -03:00
jenkins
10a629d5a7 feat(ariadne): sweep seven projects, and stop advertising the wrong model
The sweep covered four projects because only four had a write allowlist.
ananke (Go, cmd/ and internal/), pegasus (Go backend, TS frontend) and
atlasbot (Python) all have SonarQube projects and mapped repositories; they
were excluded only for want of prefixes and suffixes, which are now set from
each repository's actual layout.

The per-sweep ceiling rises to seven, one per project. With rule-level dedupe
a project stops producing proposals once every rule it has is already under
review, so this is a ceiling rather than a rate - the backlog cannot become a
queue nobody drains.

The Hermes deployment annotation still advertised gpt-5.6-terra as primary.
The config has had claude-opus-5 as default and primary for some time, so the
annotation was telling operators the wrong thing about which model made a
decision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 04:45:15 -03:00
jenkins
65ecbd9199 docs(hermes): drop demonstration framing from the agent workspace
START-HERE.md is visible in the Hermes dashboard, so its wording is part of
what an operator sees. Describing the runbook as a five-minute demonstration
frames the automation as a set piece rather than as something that runs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 14:26:13 -03:00
jenkins
18886c5177 fix(hermes): run the Vault agent before the pod's own init containers
The agent init container is appended by default, so init-config ran before
/vault/secrets existed and fell back to the Secret every time. The values were
identical, so the migration appeared to work while Vault was never actually
read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 12:20:53 -03:00
jenkins
9965b34534 feat(hermes): take the Anthropic credential from Vault
The Claude subscription OAuth token was created as a manual kubectl Secret in
the interest of demo time, with migration to Vault agreed as follow-up. The
value now lives at kv/atlas/hermes/agent-tokens and is injected as a file.

The hermes role gains that path and binds the hermes-triage service account
the deployment actually runs as; it previously bound only hermes-vault. The
init container prefers the Vault file and falls back to the Secret, so this
can be rolled back by removing the annotations alone, and the Secret should be
deleted once Vault has been serving it for a while.

Vault was reachable all along without the operator credential: Ariadne already
holds a vault-admin Kubernetes auth role, which is how the value was written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 12:14:52 -03:00
jenkins
c2c8a81c7f feat(hermes): switch the primary model to Claude Opus 5
The Codex weekly limit is close, so make anthropic/claude-opus-5 primary and
demote openai-codex to first fallback with the local gpt-oss:20b behind it.

The credential is a Claude subscription OAuth token, not an API key. The
anthropic provider resolves ANTHROPIC_API_KEY, then ANTHROPIC_TOKEN, then
CLAUDE_CODE_OAUTH_TOKEN, so the OAuth token must arrive under the last name
to be treated correctly. Marked optional so Hermes still starts and falls
back if the Secret is absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-06 05:00:09 -03:00
jenkins
11063daaaa feat(hermes-triage-demo): isolated demo surface + Jenkins job + Hermes key seeding
- New hermes-triage-demo namespace with fixture PVC and RBAC scoped to
  Jenkins agent Job creation only
- JCasC pipelineJob hermes-triage-demo: SEED_FAILURE-parameterized fixture
  check running as a Kubernetes Job in the demo namespace, emitting the
  incident ID to pod stdout (Fluent Bit -> OpenSearch kube-*) and JUnit to
  Jenkins
- Hermes init container can seed API_SERVER_KEY in the persistent .env
  from an optional hermes-api-server-key Secret (no-op until it exists)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-05 16:42:37 -03:00