콘텐츠로 이동

OpenAI Codex

필요한 secret Overlay
DISCORD_BOT_TOKEN values-openai-codex.yaml

사용 시점

계정 기반 Codex access에는 이 provider를 사용하세요. OPENAI_API_KEY가 필요한 openai-api와는 별개입니다. 사용할 수 있는 모델은 인증한 계정의 ChatGPT plan과 live Codex catalog에 따라 달라집니다.

Hermes가 refresh 가능한 자격증명을 HERMES_HOME/auth.json에 저장하므로 영속 스토리지가 필요합니다.

설치

helm upgrade --install hermes-codex ./charts/hermes-agent \
  --namespace hermes-codex --create-namespace \
  -f charts/hermes-agent/values-openai-codex.yaml \
  --set-string env.DISCORD_BOT_TOKEN='<real-value>' --wait

Discord에 게시된 링크를 열고 일회용 코드를 입력해 OpenAI 로그인을 완료하세요. 이후 Pod 시작 시 init container가 Hermes에게 저장된 자격증명을 검증하거나 갱신하도록 요청하며, 계속 사용할 수 있으면 새 로그인을 건너뜁니다.

kubectl logs deploy/hermes-codex-hermes-agent -n hermes-codex \
  -c auth-device-login -f

로그인 코드 만료

코드는 약 15분 동안 유효합니다. 승인하기 전에 만료되면 init container가 타임아웃을 알리고 새 코드를 스스로 요청하므로, 가장 최근 코드를 입력하세요. 실제 실행에서도 첫 코드가 만료된 뒤 두 번째 코드가 오고, 그 코드를 승인해 로그인이 끝났습니다.

더 큰 컨텍스트 창

Codex 경로는 대부분의 모델에 272K를 광고합니다. Hermes는 gpt-6-luna-900k처럼 -900k 접미사로 옵트인하면 약 900K까지 쓸 수 있고, 이때 compression.threshold_tokens도 함께 올려야 합니다. 이 접미사는 Hermes의 별칭이지 OpenAI 모델명이 아니며, 창이 크면 구독 사용량을 더 빨리 씁니다. 자세한 내용은 아래 overlay의 주석을 참고하세요.

하나의 ChatGPT 계정에 릴리스 여러 개

각 릴리스는 독립적으로 로그인하고 자기 auth.json에 자격증명을 보관합니다. 업스트림 문서는 같은 OpenAI 계정으로 두 번 로그인하면 하나의 토큰 계열을 공유하고 OpenAI가 이전 로그인을 폐기한다고 설명합니다. 실제 확인에서는 릴리스 3개가 1분 안에 같은 Plus 계정으로 로그인했고, 각 릴리스에서 hermes auth refresh openai-codex를 실행해도 모두 성공해서 즉시 폐기되는 현상은 나타나지 않았습니다. 시간이 지난 뒤의 갱신은 확인하지 못했습니다.

  • 팀에서는 릴리스마다 계정을 따로 쓰는 것을 권합니다.
  • 어떤 릴리스가 갱신에 실패하기 시작하면, 각 릴리스에서 hermes auth refresh openai-codex를 실행해 어느 로그인이 죽었는지 확인하고 그 릴리스에서 다시 로그인하세요.
  • 하나의 auth.json을 여러 릴리스에 복사하지 마세요. 리프레시 토큰은 일회용이라 복사본이 모두 유효할 수 없습니다.

원본 YAML 열기

전체 overlay

charts/hermes-agent/values-openai-codex.yaml
# values-openai-codex.yaml
#
# Hermes Agent backed by the account-authenticated OpenAI Codex provider. The
# auth init container sends a verification URL + one-time code to Discord,
# waits for approval, and stores the refreshable credential in
# HERMES_HOME/auth.json through Hermes' native auth-store helper.
#
# This is distinct from the `openai-api` provider and does not use an OpenAI API
# key. Your ChatGPT plan and the live Codex catalog determine model access.
#
# All secrets below are DUMMY placeholders. Do not commit real tokens.
#
#   helm upgrade --install hermes-codex ./charts/hermes-agent \
#     --namespace hermes-codex --create-namespace \
#     -f charts/hermes-agent/values-openai-codex.yaml \
#     --set-string env.DISCORD_BOT_TOKEN='<real-bot-token>' --wait
#
#   kubectl logs deploy/hermes-codex-hermes-agent -n hermes-codex \
#     -c auth-device-login -f

config:
  model:
    provider: openai-codex
    # Listed in the pinned Hermes Codex catalog. Your plan decides whether the
    # account can use it.
    # Use /model in Discord to select another model available to your account.
    default: gpt-5.6-terra
    # Optional larger context window. The Codex route advertises 272K for these
    # models. Hermes can use about 900K when you opt in with a `-900k` suffix,
    # for example:
    #   default: gpt-6-luna-900k
    # Notes (checked against Hermes v2026.9.24, the chart's pinned image):
    #   - `-900k` is a Hermes alias, not an OpenAI model name. It is removed
    #     from the model id sent to OpenAI, and Hermes caps the window at the
    #     account catalog's maximum. Hermes verified the larger window live; it
    #     is not an OpenAI-published guarantee, so drop the suffix if a request
    #     is rejected.
    #   - Only some models qualify (the gpt-5.6 and gpt-6 families, among
    #     others). The suffix on any other model is not a valid alias. This
    #     chart's live check used gpt-6-luna-900k; other models are untested.
    #   - It is opt-in because a large context uses your subscription quota
    #     faster.
    #   - The behavior is still evolving upstream (several fixes landed between
    #     2026-09-19 and 2026-10-01), so re-check it after an image bump.
  terminal:
    backend: local
  # Compaction fires at the lower of the ratio trigger and this absolute cap.
  # The default cap is 256000, so a 900K window would still compact at 256K.
  # Raise it (or set it to null for the ratio only) when you use `-900k`.
  # compression:
  #   threshold_tokens: 700000

auth:
  deviceFlow:
    enabled: true
    provider: openai-codex
    notify: discord

env:
  # Unused by openai-codex; overrides the chart's OpenAI placeholder.
  OPENAI_API_KEY: "unused"
  DISCORD_BOT_TOKEN: "MTA0DUMMYtoken000000000000.DUMMY.replace_me_with_a_real_token"

extraEnv:
  - name: DISCORD_HOME_CHANNEL
    value: "000000000000000000" # DUMMY - channel id for login delivery
  - name: DISCORD_ALLOWED_USERS
    value: "111111111111111111" # DUMMY - allowed Discord user id
  - name: DISCORD_ALLOW_ALL_USERS
    value: "false"

# Required so auth.json and its refresh token survive Pod replacement.
persistence:
  enabled: true
  storageClass: ""
  accessModes:
    - ReadWriteOnce
  size: 5Gi

resources:
  requests:
    cpu: 100m
    memory: 256Mi
  limits:
    cpu: "1"
    memory: 1Gi