github Neoplanetz/hermes-agent-desktop-docker v1.1.0
v1.1.0 — Secure CDP browser automation

latest releases: v1.1.1, v1.1.1-rc1
3 months ago

Secure, zero-privilege CDP browser automation. A turnkey Ubuntu 24.04 + XFCE4 desktop with the Hermes Agent (Nous Research) pre-installed. A CDP-enabled Chrome runs on the :1 display and Hermes' /browser drives it over loopback while you watch and steer via NoVNC, VNC, or RDP — all with no extra privilege (docker compose up).

docker pull neoplanetz/hermes-desktop-docker:1.1.0

Highlights

  • Browser automation over CDP — Chrome (amd64) / Chromium (arm64) autostarts on :1; Hermes /browser attaches over CDP 127.0.0.1:9222 (in-container only, never published to the host).
  • Multi-arch — a single manifest serves linux/amd64 (Google Chrome) and linux/arm64 (Chromium via ppa:xtradeb/apps); docker pull auto-selects your CPU's variant.
  • One observable desktop — NoVNC (6080), raw VNC (5901), and xRDP (3390→3389) all converge on the same :1 session, so the agent's actions are visible no matter how you connect.
  • Web dashboard on :9119 — Status, Chat (TUI), Config, API Keys, Sessions, Skills, MCP, Logs, Cron, Channels; scrypt-hashed login, no plaintext at rest.

Security

  • Runs with no extra privilege; seccomp=unconfined dropped (verified unnecessary).
  • CDP port 9222 is bound to loopback inside the container and is not host-published — the automation surface is never reachable externally.
  • VNC + dashboard secrets are generated at container start (mode 600), never baked into the image or committed.

Platforms (verified in CI)

  • linux/amd64 — Google Chrome stable, CDP ✅
  • linux/arm64 — Chromium (xtradeb), native-arm64 CDP ✅

CI

  • amd64 verify-gate workflow (PR / push / dispatch).
  • Native-arm64 published-image verification (weekly + dispatch).
  • Docker Hub description auto-sync.

Docs

  • Multilingual READMEs — English / 한국어 / 中文 / 日本語.
  • Four-language beginner's guide (docs/GUIDE_FOR_BEGINNERS.*).

Known limitations

Native computer_use keyboard/mouse input into GTK apps is out of scope: TigerVNC's Xvnc exposes only XTEST input and rejects uinput/libinput virtual devices, so the native real-input path can't attach (it falls back to XSendEvent, which GTK ignores). The supported, secure automation path is browser automation over CDP. Full analysis in docs/E2E-ACCEPTANCE.md.

Bundled versions

Hermes v0.17.0 (pinned dd0e4ab) · Ubuntu 24.04.4 LTS · XFCE4 4.18.3 · Chrome 149.0.7827.200 (amd64) · Node v22.23.1 · Python 3.12.3 · TigerVNC 1.13.1 · noVNC 1.3.0.


Note: 1.0.0 was an early preview and has been superseded — 1.1.0 is the recommended tag.

Don't miss a new hermes-agent-desktop-docker release

NewReleases is sending notifications on new releases.