#!/usr/bin/env bash # Call the private gateway with normal TLS verification and no public DNS hop. set -euo pipefail if [[ ${1:-} == --help ]]; then cat <<'USAGE' Usage: HERMES_LAN_TOKEN_FILE=/path/to/token hermes_lan_generate.sh < prompt.txt Without a token file, reads kv/atlas/hermes/model-gate-lan-api through Vault CLI. Optional: HERMES_LAN_ADDRESS (192.168.22.50), HERMES_LAN_MAX_TOKENS (256). USAGE exit 0 fi umask 077 scratch=$(mktemp -d) trap 'rm -rf -- "$scratch"' EXIT if [[ -n ${HERMES_LAN_TOKEN_FILE:-} ]]; then token=$(cat -- "$HERMES_LAN_TOKEN_FILE") else token=$(vault kv get -field=token kv/atlas/hermes/model-gate-lan-api) fi if [[ ! $token =~ ^[0-9a-f]{64}$ ]]; then printf 'Invalid LAN gateway token\n' >&2 exit 1 fi # Keep the bearer out of process arguments and shell tracing in the client. printf 'header = "Authorization: Bearer %s"\n' "$token" > "$scratch/curl.conf" unset token python3 -c ' import json, os, sys json.dump({"model": "qwen2.5:14b-instruct-q4_0", "prompt": sys.stdin.read(), "stream": False, "options": {"num_predict": int(os.getenv("HERMES_LAN_MAX_TOKENS", "256"))}}, sys.stdout) ' > "$scratch/request.json" curl --fail-with-body --silent --show-error --connect-timeout 10 --max-time 310 \ --noproxy worker.bstein.dev \ --resolve "worker.bstein.dev:443:${HERMES_LAN_ADDRESS:-192.168.22.50}" \ --config "$scratch/curl.conf" \ --header 'Content-Type: application/json' \ --data-binary "@$scratch/request.json" \ https://worker.bstein.dev/local-model/api/generate