Ai Install Hermes In Incus: Difference between revisions

From wiki karavi
Jump to navigation Jump to search
No edit summary
No edit summary
 
(One intermediate revision by the same user not shown)
Line 1: Line 1:
= راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد وب Hermes Agent =
= راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد امن HTTPS وب Hermes Agent =
 
این مستند شامل مراحل کامل نصب Incus، راه‌اندازی کانتینر ایزوله، نصب ابزار Hermes Agent، فعال‌سازی داشبورد تحت وب با گواهی معتبر SSL/HTTPS، ریدایرکت خودکار HTTP به HTTPS و نصب وابستگی‌های اتوماسیون مرورگر (Browser/Playwright) می‌باشد.


== بخش اول: راه‌اندازی Incus و کانتینر روی سرور اصلی (Host) ==
== بخش اول: راه‌اندازی Incus و کانتینر روی سرور اصلی (Host) ==


'''۱. نصب پیش‌نیازها و افزودن مخزن رسمی Zabbly:'''
'''۱. نصب پیش‌نیازها و مخزن رسمی Zabbly روی سرور اصلی:'''
<pre>
<pre>
sudo apt-get update
sudo apt-get update
Line 21: Line 23:
</pre>
</pre>


'''۲. نصب پکیج‌های Incus و مقداردهی اولیه:'''
'''۲. نصب پکیج‌های Incus و راه‌اندازی اولیه استوریج و شبکه:'''
<pre>
<pre>
sudo apt-get update
sudo apt-get update
Line 31: Line 33:
</pre>
</pre>


'''۳. ساخت کانتینر Ubuntu 24.04 و ورود به آن:'''
'''۳. ساخت کانتینر Ubuntu 24.04:'''
<pre>
<pre>
incus launch images:ubuntu/24.04 incus-ubuntu-hermes
incus launch images:ubuntu/24.04 incus-ubuntu-hermes
incus list
incus list
</pre>
'''۴. انتقال سرتیفیکیت‌های SSL فعال هاست به داخل کانتینر:'''
<pre>
incus file push /etc/letsencrypt/live/s5.sovi.ir/fullchain.pem incus-ubuntu-hermes/root/.hermes/cert.pem --create-dirs
incus file push /etc/letsencrypt/live/s5.sovi.ir/privkey.pem incus-ubuntu-hermes/root/.hermes/key.pem --create-dirs
</pre>
'''۵. ورود به محیط کانتینر با دسترسی Root:'''
<pre>
incus exec incus-ubuntu-hermes -- bash
incus exec incus-ubuntu-hermes -- bash
</pre>
</pre>


== بخش دوم: تنظیمات و نصب داشبورد داخل کانتینر ==
== بخش دوم: مراحل داخل کانتینر (incus-ubuntu-hermes) ==
 
'''۱. نصب بسته‌های پایه، ابزارهای شبکه و وب‌سرور داخلی:'''
<pre>
apt update && apt install -y curl git tar xz-utils python3 nano nginx
</pre>


'''۱. به‌روزرسانی و نصب Hermes Agent:'''
'''۲. نصب رسمی ابزار Hermes Agent:'''
<pre>
<pre>
apt update && apt install -y curl git tar xz-utils socat python3 nano
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
source ~/.bashrc
source ~/.bashrc
</pre>
</pre>


'''۲. تولید هش امن رمز عبور (scrypt):'''
'''۳. نصب پکیج‌های اتوماسیون مرورگر و ابزارهای وب (Playwright / Chrome Headless):'''
<pre>
npm install -g --allow-scripts=agent-browser agent-browser @playwright/test playwright
playwright install --with-deps chromium
agent-browser install --with-deps
</pre>
 
'''۴. تولید هش امن رمز عبور با الگوریتم scrypt:'''
<pre>
<pre>
HASH=$(/root/.hermes/bin/uv run python - << 'EOF'
HASH=$(/root/.hermes/bin/uv run python - << 'EOF'
Line 58: Line 81:
</pre>
</pre>


'''۳. تنظیم دامنه و احراز هویت در config.yaml:'''
'''۵. تنظیم دامنه HTTPS و احراز هویت در فایل config.yaml:'''
<pre>
<pre>
mkdir -p /root/.hermes
mkdir -p /root/.hermes
Line 66: Line 89:


dashboard:
dashboard:
   public_url: "http://s5.sovi.ir:9119"
   public_url: "https://s5.sovi.ir:9119"
   basic_auth:
   basic_auth:
     username: "admin"
     username: "admin"
Line 73: Line 96:
</pre>
</pre>


'''۴. ساخت سرویس systemd داشبورد Hermes:'''
'''۶. ساخت سرویس پایدار systemd برای داشبورد Hermes (روی پورت داخلی 9118):'''
<pre>
<pre>
cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service
cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service
Line 85: Line 108:
WorkingDirectory=/root
WorkingDirectory=/root
Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin"
Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin"
ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port 9119 --no-open --skip-build
ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port 9118 --no-open --skip-build
Restart=always
Restart=always
RestartSec=5
RestartSec=3
StandardOutput=journal
StandardOutput=journal
StandardError=journal
StandardError=journal
Line 94: Line 117:
WantedBy=multi-user.target
WantedBy=multi-user.target
EOF
EOF
systemctl daemon-reload
systemctl enable --now hermes-dashboard
</pre>
</pre>


'''۵. ساخت سرویس فورواردر پورت socat:'''
'''۷. تنظیم Nginx داخلی کانتینر با گواهی SSL و ریدایرکت خودکار HTTP به HTTPS (روی پورت 9119):'''
<pre>
<pre>
cat << 'EOF' > /etc/systemd/system/hermes-proxy.service
cat << 'EOF' > /etc/nginx/sites-available/hermes-ssl.conf
[Unit]
server {
Description=Expose Hermes Dashboard to Network
    listen 9119 ssl;
After=hermes-dashboard.service
    server_name s5.sovi.ir;
 
    ssl_certificate /root/.hermes/cert.pem;
    ssl_certificate_key /root/.hermes/key.pem;
    ssl_protocols TLSv1.2 TLSv1.3;


[Service]
    # ریدایرکت خودکار ترافیک HTTP به HTTPS روی همین پورت
Type=simple
    error_page 497 301 =307 https://$host:9119$request_uri;
ExecStart=/usr/bin/socat TCP4-LISTEN:9120,fork,reuseaddr TCP4:127.0.0.1:9119
Restart=always
RestartSec=3


[Install]
    location / {
WantedBy=multi-user.target
        proxy_pass http://127.0.0.1:9118;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto https;
        proxy_buffering off;
        proxy_read_timeout 86400s;
        proxy_send_timeout 86400s;
    }
}
EOF
EOF
</pre>


'''۶. فعال‌سازی و راه‌اندازی سرویس‌ها:'''
ln -sf /etc/nginx/sites-available/hermes-ssl.conf /etc/nginx/sites-enabled/
<pre>
rm -f /etc/nginx/sites-enabled/default 2>/dev/null || true
systemctl daemon-reload
nginx -t && systemctl restart nginx
systemctl enable --now hermes-dashboard hermes-proxy
exit
exit
</pre>
</pre>


== بخش سوم: فوروارد پورت روی سرور اصلی (Host) ==
== بخش سوم: پورت فورواردینگ روی سرور اصلی (Host) ==


'''اتصال پورت به اینترنت از طریق Incus Proxy:'''
'''اتصال پورت 9119 هاست به پورت 9119 کانتینر از طریق پروکسی Incus:'''
<pre>
<pre>
incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1:9120
incus config device remove incus-ubuntu-hermes hermes-web-port 2>/dev/null || true
incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1:9119
ss -tulpn | grep 9119
ss -tulpn | grep 9119
</pre>
</pre>


== بخش چهارم: مشخصات ورود و دستورات مدیریتی ==
== بخش چهارم: مشخصات ورود و دستورات پرکاربرد ==


{| class="wikitable"
{| class="wikitable"
! پارامتر !! مقدار
! پارامتر !! مقدار
|-
|-
| آدرس در مرورگر || <code>http://s5.sovi.ir:9119</code>
| آدرس داشبورد امن || <code>https://s5.sovi.ir:9119</code> (پشتیبانی از ریدایرکت خودکار HTTP)
|-
|-
| نام کاربری (Username) || <code>admin</code>
| نام کاربری (Username) || <code>admin</code>
Line 141: Line 179:
|}
|}


=== دستورات کاربردی مدیریت: ===
=== دستورات مفید مدیریتی: ===
{| class="wikitable"
{| class="wikitable"
! عملیات !! دستور
! عملیات !! دستور
|-
|-
| ورود به ترمینال کانتینر || <code>incus exec incus-ubuntu-hermes -- bash</code>
| ورود به شل کانتینر || <code>incus exec incus-ubuntu-hermes -- bash</code>
|-
| عیب‌یابی و وضعیت سلامت ابزارها || <code>hermes doctor</code>
|-
|-
| مشاهده لاگ زنده || <code>journalctl -u hermes-dashboard -f</code>
| مشاهده لاگ زنده وب‌داشبورد || <code>journalctl -u hermes-dashboard -f</code>
|-
|-
| ریستارت داشبورد || <code>systemctl restart hermes-dashboard</code>
| تست وب‌گردی و استخراج مرورگر || <code>hermes chat -q "Open https://github.com and tell me the title"</code>
|-
|-
| خاموش / روشن کردن || <code>incus stop incus-ubuntu-hermes</code> / <code>incus start incus-ubuntu-hermes</code>
| خاموش / روشن کردن کانتینر || <code>incus stop incus-ubuntu-hermes</code> / <code>incus start incus-ubuntu-hermes</code>
|}
|}

Latest revision as of 22:34, 27 August 2026

راهنمای جامع صفر تا صد: نصب Incus، کانتینر Ubuntu و داشبورد امن HTTPS وب Hermes Agent

این مستند شامل مراحل کامل نصب Incus، راه‌اندازی کانتینر ایزوله، نصب ابزار Hermes Agent، فعال‌سازی داشبورد تحت وب با گواهی معتبر SSL/HTTPS، ریدایرکت خودکار HTTP به HTTPS و نصب وابستگی‌های اتوماسیون مرورگر (Browser/Playwright) می‌باشد.

بخش اول: راه‌اندازی Incus و کانتینر روی سرور اصلی (Host)

۱. نصب پیش‌نیازها و مخزن رسمی Zabbly روی سرور اصلی:

sudo apt-get update
sudo apt-get install -y curl gpg
sudo mkdir -p /etc/apt/keyrings/
curl -fsSL https://pkgs.zabbly.com/key.asc -o /etc/apt/keyrings/zabbly.asc

sudo sh -c 'cat <<EOF > /etc/apt/sources.list.d/zabbly-incus-stable.sources
Enabled: yes
Types: deb
URIs: https://pkgs.zabbly.com/incus/stable
Suites: $(. /etc/os-release && echo ${VERSION_CODENAME})
Components: main
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/zabbly.asc
EOF'

۲. نصب پکیج‌های Incus و راه‌اندازی اولیه استوریج و شبکه:

sudo apt-get update
sudo apt-get install -y incus incus-ui-canonical
sudo usermod -aG incus-admin $USER
newgrp incus-admin

incus admin init --auto

۳. ساخت کانتینر Ubuntu 24.04:

incus launch images:ubuntu/24.04 incus-ubuntu-hermes
incus list

۴. انتقال سرتیفیکیت‌های SSL فعال هاست به داخل کانتینر:

incus file push /etc/letsencrypt/live/s5.sovi.ir/fullchain.pem incus-ubuntu-hermes/root/.hermes/cert.pem --create-dirs
incus file push /etc/letsencrypt/live/s5.sovi.ir/privkey.pem incus-ubuntu-hermes/root/.hermes/key.pem --create-dirs

۵. ورود به محیط کانتینر با دسترسی Root:

incus exec incus-ubuntu-hermes -- bash

بخش دوم: مراحل داخل کانتینر (incus-ubuntu-hermes)

۱. نصب بسته‌های پایه، ابزارهای شبکه و وب‌سرور داخلی:

apt update && apt install -y curl git tar xz-utils python3 nano nginx

۲. نصب رسمی ابزار Hermes Agent:

curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
source ~/.bashrc

۳. نصب پکیج‌های اتوماسیون مرورگر و ابزارهای وب (Playwright / Chrome Headless):

npm install -g --allow-scripts=agent-browser agent-browser @playwright/test playwright
playwright install --with-deps chromium
agent-browser install --with-deps

۴. تولید هش امن رمز عبور با الگوریتم scrypt:

HASH=$(/root/.hermes/bin/uv run python - << 'EOF'
import sys
sys.path.insert(0, '/usr/local/lib/hermes-agent')
from plugins.dashboard_auth.basic import hash_password
print(hash_password("TestPass@2026"))
EOF
)

۵. تنظیم دامنه HTTPS و احراز هویت در فایل config.yaml:

mkdir -p /root/.hermes
sed -i '/^dashboard:/,$d' /root/.hermes/config.yaml

cat << EOF >> /root/.hermes/config.yaml

dashboard:
  public_url: "https://s5.sovi.ir:9119"
  basic_auth:
    username: "admin"
    password_hash: "$HASH"
EOF

۶. ساخت سرویس پایدار systemd برای داشبورد Hermes (روی پورت داخلی 9118):

cat << 'EOF' > /etc/systemd/system/hermes-dashboard.service
[Unit]
Description=Hermes Agent Web Dashboard
After=network.target

[Service]
Type=simple
User=root
WorkingDirectory=/root
Environment="PATH=/usr/local/bin:/root/.hermes/bin:/usr/local/share/uv/bin:/usr/bin:/bin"
ExecStart=/usr/local/bin/hermes dashboard --host 127.0.0.1 --port 9118 --no-open --skip-build
Restart=always
RestartSec=3
StandardOutput=journal
StandardError=journal

[Install]
WantedBy=multi-user.target
EOF

systemctl daemon-reload
systemctl enable --now hermes-dashboard

۷. تنظیم Nginx داخلی کانتینر با گواهی SSL و ریدایرکت خودکار HTTP به HTTPS (روی پورت 9119):

cat << 'EOF' > /etc/nginx/sites-available/hermes-ssl.conf
server {
    listen 9119 ssl;
    server_name s5.sovi.ir;

    ssl_certificate /root/.hermes/cert.pem;
    ssl_certificate_key /root/.hermes/key.pem;
    ssl_protocols TLSv1.2 TLSv1.3;

    # ریدایرکت خودکار ترافیک HTTP به HTTPS روی همین پورت
    error_page 497 301 =307 https://$host:9119$request_uri;

    location / {
        proxy_pass http://127.0.0.1:9118;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto https;
        proxy_buffering off;
        proxy_read_timeout 86400s;
        proxy_send_timeout 86400s;
    }
}
EOF

ln -sf /etc/nginx/sites-available/hermes-ssl.conf /etc/nginx/sites-enabled/
rm -f /etc/nginx/sites-enabled/default 2>/dev/null || true
nginx -t && systemctl restart nginx
exit

بخش سوم: پورت فورواردینگ روی سرور اصلی (Host)

اتصال پورت 9119 هاست به پورت 9119 کانتینر از طریق پروکسی Incus:

incus config device remove incus-ubuntu-hermes hermes-web-port 2>/dev/null || true
incus config device add incus-ubuntu-hermes hermes-web-port proxy listen=tcp:0.0.0.0:9119 connect=tcp:127.0.0.1:9119
ss -tulpn | grep 9119

بخش چهارم: مشخصات ورود و دستورات پرکاربرد

پارامتر مقدار
آدرس داشبورد امن https://s5.sovi.ir:9119 (پشتیبانی از ریدایرکت خودکار HTTP)
نام کاربری (Username) admin
رمز عبور تستی (Password) TestPass@2026

دستورات مفید مدیریتی:

عملیات دستور
ورود به شل کانتینر incus exec incus-ubuntu-hermes -- bash
عیب‌یابی و وضعیت سلامت ابزارها hermes doctor
مشاهده لاگ زنده وب‌داشبورد journalctl -u hermes-dashboard -f
تست وب‌گردی و استخراج مرورگر hermes chat -q "Open https://github.com and tell me the title"
خاموش / روشن کردن کانتینر incus stop incus-ubuntu-hermes / incus start incus-ubuntu-hermes