HTTPRoute
| Required secret | Overlay |
|---|---|
OPENAI_API_KEY, API_SERVER_KEY, WEBHOOK_SECRET |
values-httproute.yaml |
When to use it¶
Use this when the cluster already provides the Gateway API CRD and a Gateway.
Set httpRoute.parentRefs to that Gateway. The chart does not install Gateway
API CRDs or create the Gateway.
Install¶
helm upgrade --install hermes-agent ./charts/hermes-agent \
--namespace hermes-agent --create-namespace \
-f charts/hermes-agent/values-httproute.yaml --wait
Adapt before deploying¶
An empty backendRefs[].name targets this release's Service, so it requires
service.enabled: true. Name an external Service explicitly to route to it
without the chart Service. The chart fails early if an implicit backend would
target no Service.
hostnames apply to every rule in one HTTPRoute. Create separate HTTPRoutes
when API and webhook rules must be isolated by hostname.
For clusters operated through an Ingress controller, use Ingress instead. Both routing resources are off by default; choose one per host and path.
Complete overlay¶
charts/hermes-agent/values-httproute.yaml
# values-httproute.yaml
#
# Routes Hermes' API server and generic webhook receiver through a Gateway API
# HTTPRoute. The cluster must already have the Gateway API CRD and a Gateway
# named hermes-gateway. Create hermes-agent-listener-secrets with
# OPENAI_API_KEY, API_SERVER_KEY, and WEBHOOK_SECRET before installing. Do not
# commit real credentials.
#
# helm upgrade --install hermes-agent ./charts/hermes-agent \
# --namespace hermes-agent --create-namespace \
# -f charts/hermes-agent/values-httproute.yaml --wait
config:
model:
provider: openai-api
default: gpt-4o-mini
terminal:
backend: local
extraEnvFrom:
- secretRef:
name: hermes-agent-listener-secrets
apiServer:
enabled: true
host: 0.0.0.0
port: 8642
corsOrigins: "https://chat.example.com"
webhook:
enabled: true
port: 8644
service:
enabled: true
ports:
- name: api-server
port: 8642
- name: webhook
port: 8644
httpRoute:
enabled: true
parentRefs:
- name: hermes-gateway
sectionName: https
hostnames:
- api.example.com
- webhooks.example.com
rules:
- matches:
- path:
type: PathPrefix
value: /v1
backendRefs:
- port: 8642
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- port: 8644