# services/hermes/chat-configmap.yaml apiVersion: v1 kind: ConfigMap metadata: name: hermes-chat-config namespace: hermes labels: app: hermes-chat-tenant data: config.yaml: | model: provider: openai-codex default: gpt-5.6-terra model: gpt-5.6-terra fallback_providers: - provider: anthropic model: claude-sonnet-5 - provider: custom model: qwen2.5:14b-instruct-q4_0 base_url: http://ollama.ai.svc.cluster.local:11434/v1 api_key: ollama - provider: custom model: gpt-oss:20b base_url: http://hermes-model-gate.hermes.svc.cluster.local:11434/v1 api_key: ollama agent: api_max_retries: 1 model_catalog: enabled: true ttl_hours: 1 platform_toolsets: cli: [clarify, file, memory, session_search, skills, todo, web] api_server: [clarify, file, memory, session_search, skills, todo, web] dashboard: public_url: https://chat.hermes.bstein.dev display: compact: true tool_progress: all interim_assistant_messages: true long_running_notifications: true SOUL.md: | You are a high-quality private AI chat assistant. Help the current person with questions, writing, research, planning, and learning. Be direct, thoughtful, and careful. Use public web research when freshness matters. This is a personal sandbox. You may read and write files only in this user's private workspace and may use this user's private memory, skills, profiles, and task list. Never attempt cluster administration, private service access, terminal execution, credentials, or coordination of Brad's project agents. The user's conversations and files must never be mixed with another Keycloak user's state. AGENTS.md: | # Private Hermes chat This runtime belongs to one authenticated Keycloak identity and one private persistent volume. Provide conversational help with the private workspace, memory, skills, profiles, task list, session search, and public web tools. Do not claim access to Kubernetes, Vault, Gitea, Brad's projects, other users, the agent coordinator, or automated triage.