Security Policy¶
This document covers security for the Helm chart in this repository
(charts/hermes-agent) - its templates, default values, examples, and CI.
It is a community-maintained chart, not an official Nous Research release.
Reporting a vulnerability¶
Report privately via GitHub Security Advisories. Do not open public issues for security vulnerabilities.
A useful report includes:
- A concise description and severity assessment.
- The affected template, value, or example (file path and line range).
- Chart version (
Chart.yamlversion) and, if relevant, the image tag (appVersionor your override). - Rendered output (
helm template) or reproduction steps demonstrating the issue.
You can expect an initial response within a reasonable time frame; this is a volunteer-maintained project without an SLA or bug bounty program.
Scope¶
In scope - report here:
- Chart templates rendering insecure resources (e.g. secrets leaked into ConfigMaps, logs, or annotations; unintended privilege escalation).
- Insecure defaults in
values.yaml(e.g. anything that would expose the management dashboard or credentials by default). - Vulnerabilities in the example manifests (
values-*.yaml,examples/argocd/) that would mislead users into an insecure deployment. - Supply-chain issues in this repository's release pipeline (GitHub Actions workflows, published OCI artifacts).
Out of scope - report upstream:
- Vulnerabilities in Hermes Agent itself (the application inside the image). Follow the upstream policy: NousResearch/hermes-agent SECURITY.md.
- Vulnerabilities in Kubernetes, Helm, or third-party charts/controllers (ingress controllers, sealed-secrets, etc.).
- Issues that require the operator to have already overridden the chart's
secure defaults (e.g. exposing the dashboard with
--insecureand no authentication is a documented, deliberate choice).
Supported versions¶
Only the latest released chart version (latest vX.Y.Z tag) receives
security fixes. Older versions are not patched; upgrade to the latest release.
Security model of the chart¶
Facts worth knowing before deploying:
- The pod is the sandbox. The agent runs commands inside its own pod
(
config.terminal.backend: local). Kubernetes-level isolation - namespace,securityContext, resource limits, NetworkPolicy - is the security boundary. Thedockerterminal backend is unsupported in-cluster because it would require a Docker daemon/socket. - No inbound API by default. The agent makes outbound connections only.
The single HTTP surface is the optional management dashboard (port 9119),
which exposes API keys to whoever is signed in. A signed-in user can also
edit the configuration, create shell hooks and use the Chat tab, so treat
sign-in as shell access to the pod. The chart ships with
dashboard.enabled: false,service.enabled: falseandingress.enabled: false. Once enabled, the dashboard binds0.0.0.0inside the container and upstream's auth gate is mandatory: without an auth provider it fails closed and never listens (--insecureis a deprecated no-op). Choose the sign-in method withdashboard.auth.provider. Upstream recommends the password provider only for a trusted network or a VPN; use Nous Portal OAuth or your own OIDC provider for a public host, and note that with OIDC access must be restricted at the identity provider (seevalues-ingress.yaml,values-ingress-oauth.yaml,values-ingress-oidc.yamland the README section "Expose the dashboard"). - Secrets are injected via
envFrom, rendered into a KubernetesSecret - never into the ConfigMap. For GitOps, don't commit real secrets; use the
SealedSecret pattern in
examples/argocd/. podSecurityContext/securityContextare empty by default for image compatibility. Hardening them (non-root, read-only root filesystem, dropped capabilities) is recommended where the image permits - validate in your environment.
Repository protections¶
This repository has GitHub secret scanning with push protection, Dependabot security updates, and private vulnerability reporting enabled.