Ai Install Hermes In Incus: Difference between revisions
No edit summary |
No edit summary |
||
| (One intermediate revision by the same user not shown) | |||
| Line 1: | Line 1: | ||
= راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد وب Hermes Agent = | = راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد امن HTTPS وب Hermes Agent = | ||
این مستند شامل مراحل کامل نصب Incus، راهاندازی کانتینر ایزوله، نصب ابزار Hermes Agent، فعالسازی داشبورد تحت وب با گواهی معتبر SSL/HTTPS، ریدایرکت خودکار HTTP به HTTPS و نصب وابستگیهای اتوماسیون مرورگر (Browser/Playwright) میباشد. | |||
== بخش اول: راهاندازی Incus و کانتینر روی سرور اصلی (Host) == | == بخش اول: راهاندازی Incus و کانتینر روی سرور اصلی (Host) == | ||
'''۱. نصب پیشنیازها و | '''۱. نصب پیشنیازها و مخزن رسمی Zabbly روی سرور اصلی:''' | ||
<pre> | <pre> | ||
sudo apt-get update | sudo apt-get update | ||
| Line 21: | Line 23: | ||
</pre> | </pre> | ||
'''۲. نصب پکیجهای Incus و | '''۲. نصب پکیجهای Incus و راهاندازی اولیه استوریج و شبکه:''' | ||
<pre> | <pre> | ||
sudo apt-get update | sudo apt-get update | ||
| Line 31: | Line 33: | ||
</pre> | </pre> | ||
'''۳. ساخت کانتینر Ubuntu 24.04 | '''۳. ساخت کانتینر Ubuntu 24.04:''' | ||
<pre> | <pre> | ||
incus launch images:ubuntu/24.04 incus-ubuntu-hermes | incus launch images:ubuntu/24.04 incus-ubuntu-hermes | ||
incus list | incus list | ||
</pre> | |||
'''۴. انتقال سرتیفیکیتهای SSL فعال هاست به داخل کانتینر:''' | |||
<pre> | |||
incus file push /etc/letsencrypt/live/s5.sovi.ir/fullchain.pem incus-ubuntu-hermes/root/.hermes/cert.pem --create-dirs | |||
incus file push /etc/letsencrypt/live/s5.sovi.ir/privkey.pem incus-ubuntu-hermes/root/.hermes/key.pem --create-dirs | |||
</pre> | |||
'''۵. ورود به محیط کانتینر با دسترسی Root:''' | |||
<pre> | |||
incus exec incus-ubuntu-hermes -- bash | incus exec incus-ubuntu-hermes -- bash | ||
</pre> | </pre> | ||
== بخش دوم: | == بخش دوم: مراحل داخل کانتینر (incus-ubuntu-hermes) == | ||
'''۱. نصب بستههای پایه، ابزارهای شبکه و وبسرور داخلی:''' | |||
<pre> | |||
apt update && apt install -y curl git tar xz-utils python3 nano nginx | |||
</pre> | |||
''' | '''۲. نصب رسمی ابزار Hermes Agent:''' | ||
<pre> | <pre> | ||
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash | curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash | ||
source ~/.bashrc | source ~/.bashrc | ||
</pre> | </pre> | ||
''' | '''۳. نصب پکیجهای اتوماسیون مرورگر و ابزارهای وب (Playwright / Chrome Headless):''' | ||
<pre> | |||
npm install -g --allow-scripts=agent-browser agent-browser @playwright/test playwright | |||
playwright install --with-deps chromium | |||
agent-browser install --with-deps | |||
</pre> | |||
'''۴. تولید هش امن رمز عبور با الگوریتم scrypt:''' | |||
<pre> | <pre> | ||
HASH=$(/root/.hermes/bin/uv run python - << 'EOF' | HASH=$(/root/.hermes/bin/uv run python - << 'EOF' | ||
| Line 58: | Line 81: | ||
</pre> | </pre> | ||
''' | '''۵. تنظیم دامنه HTTPS و احراز هویت در فایل config.yaml:''' | ||
<pre> | <pre> | ||
mkdir -p /root/.hermes | mkdir -p /root/.hermes | ||
| Line 66: | Line 89: | ||
dashboard: | dashboard: | ||
public_url: " | public_url: "https://s5.sovi.ir:9119" | ||
basic_auth: | basic_auth: | ||
username: "admin" | username: "admin" | ||
| Line 73: | Line 96: | ||
</pre> | </pre> | ||
''' | '''۶. ساخت سرویس پایدار systemd برای داشبورد Hermes (روی پورت داخلی 9118):''' | ||
<pre> | <pre> | ||
cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service | cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service | ||
| Line 85: | Line 108: | ||
WorkingDirectory=/root | WorkingDirectory=/root | ||
Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin" | Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin" | ||
ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port | ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port 9118 --no-open --skip-build | ||
Restart=always | Restart=always | ||
RestartSec= | RestartSec=3 | ||
StandardOutput=journal | StandardOutput=journal | ||
StandardError=journal | StandardError=journal | ||
| Line 94: | Line 117: | ||
WantedBy=multi-user.target | WantedBy=multi-user.target | ||
EOF | EOF | ||
systemctl daemon-reload | |||
systemctl enable --now hermes-dashboard | |||
</pre> | </pre> | ||
''' | '''۷. تنظیم Nginx داخلی کانتینر با گواهی SSL و ریدایرکت خودکار HTTP به HTTPS (روی پورت 9119):''' | ||
<pre> | <pre> | ||
cat << 'EOF' > /etc/ | cat << 'EOF' > /etc/nginx/sites-available/hermes-ssl.conf | ||
server { | |||
listen 9119 ssl; | |||
server_name s5.sovi.ir; | |||
ssl_certificate /root/.hermes/cert.pem; | |||
ssl_certificate_key /root/.hermes/key.pem; | |||
ssl_protocols TLSv1.2 TLSv1.3; | |||
# ریدایرکت خودکار ترافیک HTTP به HTTPS روی همین پورت | |||
error_page 497 301 =307 https://$host:9119$request_uri; | |||
location / { | |||
proxy_pass http://127.0.0.1:9118; | |||
proxy_http_version 1.1; | |||
proxy_set_header Upgrade $http_upgrade; | |||
proxy_set_header Connection "upgrade"; | |||
proxy_set_header Host $host; | |||
proxy_set_header X-Real-IP $remote_addr; | |||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |||
proxy_set_header X-Forwarded-Proto https; | |||
proxy_buffering off; | |||
proxy_read_timeout 86400s; | |||
proxy_send_timeout 86400s; | |||
} | |||
} | |||
EOF | EOF | ||
ln -sf /etc/nginx/sites-available/hermes-ssl.conf /etc/nginx/sites-enabled/ | |||
rm -f /etc/nginx/sites-enabled/default 2>/dev/null || true | |||
nginx -t && systemctl restart nginx | |||
systemctl | |||
exit | exit | ||
</pre> | </pre> | ||
== بخش سوم: | == بخش سوم: پورت فورواردینگ روی سرور اصلی (Host) == | ||
'''اتصال پورت به | '''اتصال پورت 9119 هاست به پورت 9119 کانتینر از طریق پروکسی Incus:''' | ||
<pre> | <pre> | ||
incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1: | incus config device remove incus-ubuntu-hermes hermes-web-port 2>/dev/null || true | ||
incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1:9119 | |||
ss -tulpn | grep 9119 | ss -tulpn | grep 9119 | ||
</pre> | </pre> | ||
== بخش چهارم: مشخصات ورود و دستورات | == بخش چهارم: مشخصات ورود و دستورات پرکاربرد == | ||
{| class="wikitable" | {| class="wikitable" | ||
! پارامتر !! مقدار | ! پارامتر !! مقدار | ||
|- | |- | ||
| آدرس | | آدرس داشبورد امن || <code>https://s5.sovi.ir:9119</code> (پشتیبانی از ریدایرکت خودکار HTTP) | ||
|- | |- | ||
| نام کاربری (Username) || <code>admin</code> | | نام کاربری (Username) || <code>admin</code> | ||
| Line 141: | Line 179: | ||
|} | |} | ||
=== دستورات | === دستورات مفید مدیریتی: === | ||
{| class="wikitable" | {| class="wikitable" | ||
! عملیات !! دستور | ! عملیات !! دستور | ||
|- | |- | ||
| ورود به | | ورود به شل کانتینر || <code>incus exec incus-ubuntu-hermes -- bash</code> | ||
|- | |||
| عیبیابی و وضعیت سلامت ابزارها || <code>hermes doctor</code> | |||
|- | |- | ||
| مشاهده لاگ زنده || <code>journalctl -u hermes-dashboard -f</code> | | مشاهده لاگ زنده وبداشبورد || <code>journalctl -u hermes-dashboard -f</code> | ||
|- | |- | ||
| | | تست وبگردی و استخراج مرورگر || <code>hermes chat -q "Open https://github.com and tell me the title"</code> | ||
|- | |- | ||
| خاموش / روشن کردن || <code>incus stop incus-ubuntu-hermes</code> / <code>incus start incus-ubuntu-hermes</code> | | خاموش / روشن کردن کانتینر || <code>incus stop incus-ubuntu-hermes</code> / <code>incus start incus-ubuntu-hermes</code> | ||
|} | |} | ||
Latest revision as of 22:34, 27 August 2026
راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد امن HTTPS وب Hermes Agent
این مستند شامل مراحل کامل نصب Incus، راهاندازی کانتینر ایزوله، نصب ابزار Hermes Agent، فعالسازی داشبورد تحت وب با گواهی معتبر SSL/HTTPS، ریدایرکت خودکار HTTP به HTTPS و نصب وابستگیهای اتوماسیون مرورگر (Browser/Playwright) میباشد.
بخش اول: راهاندازی Incus و کانتینر روی سرور اصلی (Host)
۱. نصب پیشنیازها و مخزن رسمی Zabbly روی سرور اصلی:
sudo apt-get update
sudo apt-get install -y curl gpg
sudo mkdir -p /etc/apt/keyrings/
curl -fsSL https://pkgs.zabbly.com/key.asc -o /etc/apt/keyrings/zabbly.asc
sudo sh -c 'cat <<EOF > /etc/apt/sources.list.d/zabbly-incus-stable.sources
Enabled: yes
Types: deb
URIs: https://pkgs.zabbly.com/incus/stable
Suites: $(. /etc/os-release && echo ${VERSION_CODENAME})
Components: main
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/zabbly.asc
EOF'
۲. نصب پکیجهای Incus و راهاندازی اولیه استوریج و شبکه:
sudo apt-get update sudo apt-get install -y incus incus-ui-canonical sudo usermod -aG incus-admin $USER newgrp incus-admin incus admin init --auto
۳. ساخت کانتینر Ubuntu 24.04:
incus launch images:ubuntu/24.04 incus-ubuntu-hermes incus list
۴. انتقال سرتیفیکیتهای SSL فعال هاست به داخل کانتینر:
incus file push /etc/letsencrypt/live/s5.sovi.ir/fullchain.pem incus-ubuntu-hermes/root/.hermes/cert.pem --create-dirs incus file push /etc/letsencrypt/live/s5.sovi.ir/privkey.pem incus-ubuntu-hermes/root/.hermes/key.pem --create-dirs
۵. ورود به محیط کانتینر با دسترسی Root:
incus exec incus-ubuntu-hermes -- bash
بخش دوم: مراحل داخل کانتینر (incus-ubuntu-hermes)
۱. نصب بستههای پایه، ابزارهای شبکه و وبسرور داخلی:
apt update && apt install -y curl git tar xz-utils python3 nano nginx
۲. نصب رسمی ابزار Hermes Agent:
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash source ~/.bashrc
۳. نصب پکیجهای اتوماسیون مرورگر و ابزارهای وب (Playwright / Chrome Headless):
npm install -g --allow-scripts=agent-browser agent-browser @playwright/test playwright playwright install --with-deps chromium agent-browser install --with-deps
۴. تولید هش امن رمز عبور با الگوریتم scrypt:
HASH=$(/root/.hermes/bin/uv run python - << 'EOF'
import sys
sys.path.insert(0, '/usr/local/lib/hermes-agent')
from plugins.dashboard_auth.basic import hash_password
print(hash_password("TestPass@2026"))
EOF
)
۵. تنظیم دامنه HTTPS و احراز هویت در فایل config.yaml:
mkdir -p /root/.hermes
sed -i '/^dashboard:/,$d' /root/.hermes/config.yaml
cat << EOF >> /root/.hermes/config.yaml
dashboard:
public_url: "https://s5.sovi.ir:9119"
basic_auth:
username: "admin"
password_hash: "$HASH"
EOF
۶. ساخت سرویس پایدار systemd برای داشبورد Hermes (روی پورت داخلی 9118):
cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service [Unit] Description=Hermes Agent Web Dashboard After=network.target [Service] Type=simple User=root WorkingDirectory=/root Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin" ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port 9118 --no-open --skip-build Restart=always RestartSec=3 StandardOutput=journal StandardError=journal [Install] WantedBy=multi-user.target EOF systemctl daemon-reload systemctl enable --now hermes-dashboard
۷. تنظیم Nginx داخلی کانتینر با گواهی SSL و ریدایرکت خودکار HTTP به HTTPS (روی پورت 9119):
cat << 'EOF' > /etc/nginx/sites-available/hermes-ssl.conf
server {
listen 9119 ssl;
server_name s5.sovi.ir;
ssl_certificate /root/.hermes/cert.pem;
ssl_certificate_key /root/.hermes/key.pem;
ssl_protocols TLSv1.2 TLSv1.3;
# ریدایرکت خودکار ترافیک HTTP به HTTPS روی همین پورت
error_page 497 301 =307 https://$host:9119$request_uri;
location / {
proxy_pass http://127.0.0.1:9118;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto https;
proxy_buffering off;
proxy_read_timeout 86400s;
proxy_send_timeout 86400s;
}
}
EOF
ln -sf /etc/nginx/sites-available/hermes-ssl.conf /etc/nginx/sites-enabled/
rm -f /etc/nginx/sites-enabled/default 2>/dev/null || true
nginx -t && systemctl restart nginx
exit
بخش سوم: پورت فورواردینگ روی سرور اصلی (Host)
اتصال پورت 9119 هاست به پورت 9119 کانتینر از طریق پروکسی Incus:
incus config device remove incus-ubuntu-hermes hermes-web-port 2>/dev/null || true incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1:9119 ss -tulpn | grep 9119
بخش چهارم: مشخصات ورود و دستورات پرکاربرد
| پارامتر | مقدار |
|---|---|
| آدرس داشبورد امن | https://s5.sovi.ir:9119 (پشتیبانی از ریدایرکت خودکار HTTP)
|
| نام کاربری (Username) | admin
|
| رمز عبور تستی (Password) | TestPass@2026
|
دستورات مفید مدیریتی:
| عملیات | دستور |
|---|---|
| ورود به شل کانتینر | incus exec incus-ubuntu-hermes -- bash
|
| عیبیابی و وضعیت سلامت ابزارها | hermes doctor
|
| مشاهده لاگ زنده وبداشبورد | journalctl -u hermes-dashboard -f
|
| تست وبگردی و استخراج مرورگر | hermes chat -q "Open https://github.com and tell me the title"
|
| خاموش / روشن کردن کانتینر | incus stop incus-ubuntu-hermes / incus start incus-ubuntu-hermes
|