hermes: fall back to sference when hyper is unavailable #12

Open
hermes wants to merge 4 commits from hermes-fallback into main
Collaborator

Sets fallback_providers to sference's zai-org/GLM-5.3-Flash so sessions keep running when the hyper subscription is out of credits or failing.

How the auto-return works (no cron/checker needed): Hermes fallback is turn-scoped — every new message retries the primary (hyper) first. If hyper is still out of credits, the turn runs on sference; once the subscription renews, the next message naturally succeeds on hyper. Result: 'automatically on hyper again' with zero intervention, and no staleness window from a scheduled checker.

Eval-verified: containers.hermes.config.services.hermes-agent.settings.fallback_providers = [{model: "zai-org/GLM-5.3-Flash", provider: "sference"}].

Sets `fallback_providers` to sference's `zai-org/GLM-5.3-Flash` so sessions keep running when the hyper subscription is out of credits or failing. How the auto-return works (no cron/checker needed): Hermes fallback is **turn-scoped** — every new message retries the primary (hyper) first. If hyper is still out of credits, the turn runs on sference; once the subscription renews, the next message naturally succeeds on hyper. Result: 'automatically on hyper again' with zero intervention, and no staleness window from a scheduled checker. Eval-verified: `containers.hermes.config.services.hermes-agent.settings.fallback_providers` = `[{model: "zai-org/GLM-5.3-Flash", provider: "sference"}]`.
hermes: add rbw + container tools to extraPackages
All checks were successful
Build Images / build (pull_request) Successful in 39s
Check / check (pull_request) Successful in 4m2s
61c1f0ba6a
rbw now works end-to-end against the vault (pinentry stub fixed, account
re-registered with standard key wrapping). Include it with git, forgejo-cli
and jq as the agent's day-to-day toolset.
ci: trigger freun-dev deploy on merge
Some checks failed
Build Images / build (pull_request) Successful in 41s
Check / check (pull_request) Failing after 1m12s
576f9e2f0f
Adds a Forgejo Actions workflow that, on push to main, ssh'es to freun-dev
as the restricted ci-deploy user. The account's authorized_keys entry is
pinned to a single command (systemctl start nixos-upgrade.service) with
port/X11/agent forwarding and PTY allocation disabled — CI can only kick
the existing pull-based upgrade, not run arbitrary commands. The upgrade
then fetches main via the existing read-only deploy key and switches.

Deployment flow on merge:
1. check.yml validates the flake (already in place)
2. deploy.yml triggers nixos-upgrade on freun-dev
3. the upgrade unit fetches the new revision and switches, with the
   existing kuma heartbeats reporting success/failure

Setup remaining (operator):
- sops-encrypt the private key: 'sops secrets/ci-deploy-key' with the
  plaintext from the agent (staged at the agent's secrets dir), then add
  its base64 as the CI_DEPLOY_KEY repository secret
- merge + apply freun-dev once to install the ci-deploy user
hermes: fall back to sference when hyper is unavailable
All checks were successful
Build Images / build (pull_request) Successful in 39s
Check / check (pull_request) Successful in 4m15s
8ad043438a
fallback_providers routes sessions to sference's GLM-5.3-Flash when the
hyper subscription is out of credits or otherwise failing. Fallback is
turn-scoped: every new message retries hyper first, so a renewed
subscription is picked up automatically without manual intervention.
merge main into hermes-fallback
Some checks failed
Check / check (pull_request) Has been cancelled
Build Images / build (pull_request) Has been cancelled
b77afb3483
# Conflicts:
#	.forgejo/workflows/deploy.yml
#	modules/ci-deploy.nix
hermes force-pushed hermes-fallback from b77afb3483
Some checks failed
Check / check (pull_request) Has been cancelled
Build Images / build (pull_request) Has been cancelled
to b3a5efeabc
All checks were successful
Build Images / build (pull_request) Successful in 38s
Check / check (pull_request) Successful in 3m59s
2026-09-27 22:31:19 +03:00
Compare
repomaa force-pushed hermes-fallback from b3a5efeabc
All checks were successful
Build Images / build (pull_request) Successful in 38s
Check / check (pull_request) Successful in 3m59s
to 47a1e79b11
Some checks failed
Build Images / build (pull_request) Has been cancelled
Check / check (pull_request) Has been cancelled
2026-09-27 22:48:54 +03:00
Compare
repomaa force-pushed hermes-fallback from 47a1e79b11
Some checks failed
Build Images / build (pull_request) Has been cancelled
Check / check (pull_request) Has been cancelled
to ab23193bfd
All checks were successful
Build Images / build (pull_request) Successful in 41s
Check / check (pull_request) Successful in 3m50s
2026-09-27 22:56:27 +03:00
Compare
All checks were successful
Build Images / build (pull_request) Successful in 41s
Check / check (pull_request) Successful in 3m50s
Required
Details
This pull request has changes conflicting with the target branch.
  • modules/hermes.nix
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin hermes-fallback:hermes-fallback
git switch hermes-fallback
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
repomaa/nixos!12
No description provided.