跳转至

Google Vertex

Required secret Overlay
GCP service-account Secret values-google-vertex.yaml

When to use it

A GCP service-account JSON Secret with Vertex AI User permissions and a project ID are required.

Install

helm upgrade --install hermes-agent ./charts/hermes-agent \
  --namespace hermes-agent --create-namespace \
  -f charts/hermes-agent/values-google-vertex.yaml \
  --set-string env.GCP_service-account_Secret='<real-value>' --wait

When an example requires more than one credential, pass every listed value with --set-string or use extraEnvFrom to reference an existing Secret.

Adapt before deploying

Create the credential Secret before installation because the chart mounts it instead of using a static API key.

Open Raw YAML

Complete overlay

charts/hermes-agent/values-google-vertex.yaml
# values-google-vertex.yaml
#
# Hermes Agent using Google Vertex AI as the model provider (Gemini models via
# Vertex's OpenAI-compatible endpoint). Requires hermes-agent >= v2026.7.1.
#
# Vertex has NO static API key: every request needs a short-lived OAuth2 access
# token, which Hermes mints and auto-refreshes from a service-account JSON (or
# Application Default Credentials). So unlike the other provider examples, the
# credential here is a FILE mounted into the pod, not an env var:
#
# 1. Create a GCP service account with the "Vertex AI User" role and download
#    its JSON key.
# 2. Put the JSON into a Kubernetes Secret:
#      kubectl create secret generic vertex-sa \
#        --namespace hermes-agent \
#        --from-file=sa.json=/path/to/key.json
# 3. Install:
#      helm upgrade --install hermes-agent ./charts/hermes-agent \
#        --namespace hermes-agent --create-namespace \
#        -f charts/hermes-agent/values-google-vertex.yaml \
#        --set-string config.vertex.project_id='<your-gcp-project>' --wait

config:
  model:
    provider: vertex
    default: google/gemini-2.5-flash
  # Non-secret Vertex settings live in config.yaml; only the credential file
  # path goes through the environment (VERTEX_CREDENTIALS_PATH below).
  vertex:
    project_id: "REPLACE_ME_GCP_PROJECT"
    # "global" uses the global endpoint; set a specific region (e.g.
    # us-central1) to pin data residency / regional capacity.
    region: "global"
  terminal:
    backend: local

env:
  # No Vertex API key exists: tokens are minted from the mounted SA JSON.
  # This only overrides the chart's OpenAI placeholder.
  OPENAI_API_KEY: "unused"

extraEnv:
  # Path (inside the container) to the service-account JSON mounted below.
  # Omit it to fall back to ADC (GOOGLE_APPLICATION_CREDENTIALS / metadata
  # server, e.g. GKE Workload Identity).
  - name: VERTEX_CREDENTIALS_PATH
    value: /var/run/secrets/vertex/sa.json
  # The vertex provider needs `google-auth`, which upstream ships as an opt-in
  # extra handled by its lazy-install mechanism: it is NOT baked into the
  # image, and the image disables lazy installs by default. Re-enable them so
  # the first Vertex call can install it into HERMES_LAZY_INSTALL_TARGET on
  # the persistent volume (one-time, needs network egress; survives restarts).
  - name: HERMES_DISABLE_LAZY_INSTALLS
    value: "0"

# Mount the service-account Secret created in step 2.
extraVolumes:
  - name: vertex-sa
    secret:
      secretName: vertex-sa
extraVolumeMounts:
  - name: vertex-sa
    mountPath: /var/run/secrets/vertex
    readOnly: true

# NOTE: as of a recent Hermes security hardening, VERTEX_CREDENTIALS_PATH and
# GOOGLE_APPLICATION_CREDENTIALS are stripped from the environment of
# subprocesses the agent spawns (terminal, execute_code, browser,
# computer_use): they still work for the model's own API calls above. If a
# tool call in your session needs Vertex credentials too (e.g. shelling out to
# `gcloud`), re-allow it explicitly:
#
# config:
#   tools:
#     env_passthrough: ["VERTEX_CREDENTIALS_PATH"]