콘텐츠로 이동

Google Vertex

필수 Secret 오버레이
GCP service-account Secret values-google-vertex.yaml

언제 사용하나요?

Vertex AI User 권한의 GCP 서비스 계정 JSON Secret과 project ID가 필요합니다.

설치

helm upgrade --install hermes-agent ./charts/hermes-agent \
  --namespace hermes-agent --create-namespace \
  -f charts/hermes-agent/values-google-vertex.yaml \
  --set-string env.GCP_service-account_Secret='<real-value>' --wait

둘 이상의 자격 증명이 필요한 예제에서는 모든 값을 --set-string으로 전달하거나 extraEnvFrom으로 기존 Secret을 참조하세요.

배포 전 조정

정적 API key 대신 credential 파일을 mount하므로 Secret 생성 단계를 먼저 수행합니다.

원본 YAML 열기

전체 오버레이

charts/hermes-agent/values-google-vertex.yaml
# values-google-vertex.yaml
#
# Hermes Agent using Google Vertex AI as the model provider (Gemini models via
# Vertex's OpenAI-compatible endpoint). Requires hermes-agent >= v2026.7.1.
#
# Vertex has NO static API key: every request needs a short-lived OAuth2 access
# token, which Hermes mints and auto-refreshes from a service-account JSON (or
# Application Default Credentials). So unlike the other provider examples, the
# credential here is a FILE mounted into the pod, not an env var:
#
# 1. Create a GCP service account with the "Vertex AI User" role and download
#    its JSON key.
# 2. Put the JSON into a Kubernetes Secret:
#      kubectl create secret generic vertex-sa \
#        --namespace hermes-agent \
#        --from-file=sa.json=/path/to/key.json
# 3. Install:
#      helm upgrade --install hermes-agent ./charts/hermes-agent \
#        --namespace hermes-agent --create-namespace \
#        -f charts/hermes-agent/values-google-vertex.yaml \
#        --set-string config.vertex.project_id='<your-gcp-project>' --wait

config:
  model:
    provider: vertex
    default: google/gemini-2.5-flash
  # Non-secret Vertex settings live in config.yaml; only the credential file
  # path goes through the environment (VERTEX_CREDENTIALS_PATH below).
  vertex:
    project_id: "REPLACE_ME_GCP_PROJECT"
    # "global" uses the global endpoint; set a specific region (e.g.
    # us-central1) to pin data residency / regional capacity.
    region: "global"
  terminal:
    backend: local

env:
  # No Vertex API key exists: tokens are minted from the mounted SA JSON.
  # This only overrides the chart's OpenAI placeholder.
  OPENAI_API_KEY: "unused"

extraEnv:
  # Path (inside the container) to the service-account JSON mounted below.
  # Omit it to fall back to ADC (GOOGLE_APPLICATION_CREDENTIALS / metadata
  # server, e.g. GKE Workload Identity).
  - name: VERTEX_CREDENTIALS_PATH
    value: /var/run/secrets/vertex/sa.json
  # The vertex provider needs `google-auth`, which upstream ships as an opt-in
  # extra handled by its lazy-install mechanism: it is NOT baked into the
  # image, and the image disables lazy installs by default. Re-enable them so
  # the first Vertex call can install it into HERMES_LAZY_INSTALL_TARGET on
  # the persistent volume (one-time, needs network egress; survives restarts).
  - name: HERMES_DISABLE_LAZY_INSTALLS
    value: "0"

# Mount the service-account Secret created in step 2.
extraVolumes:
  - name: vertex-sa
    secret:
      secretName: vertex-sa
extraVolumeMounts:
  - name: vertex-sa
    mountPath: /var/run/secrets/vertex
    readOnly: true

# NOTE: as of a recent Hermes security hardening, VERTEX_CREDENTIALS_PATH and
# GOOGLE_APPLICATION_CREDENTIALS are stripped from the environment of
# subprocesses the agent spawns (terminal, execute_code, browser,
# computer_use): they still work for the model's own API calls above. If a
# tool call in your session needs Vertex credentials too (e.g. shelling out to
# `gcloud`), re-allow it explicitly:
#
# config:
#   tools:
#     env_passthrough: ["VERTEX_CREDENTIALS_PATH"]