# ~/.hermes/config.yaml (mounted as /opt/data/config.yaml) for the
# "Proxmox Sentinel" pilot. Secrets live in .env next to it
# (TELEGRAM_BOT_TOKEN, OPENAI_API_KEY, PVE_*). Key reference:
# https://hermes-agent.nousresearch.com/docs/user-guide/configuration

model:
  provider: custom                    # any OpenAI-compatible endpoint = our LiteLLM
  model: hermes                       # LiteLLM alias: gemini-3.5-flash, no Groq fallback
  base_url: http://litellm:4000/v1
  api_key: ${OPENAI_API_KEY}          # LiteLLM virtual key `hermes` (from .env)
  max_tokens: 16000                   # thinking model: the budget includes reasoning
  reasoning_effort: low               # otherwise ~4k tokens go to thinking
  temperature: 0.3

agent:
  max_turns: 40                       # fuse against endless loops
  reasoning_effort: low
  # Global toolset ban; wins over anything a platform enables.
  # What stays: terminal (our scripts), skills, memory, todo, clarify, session_search.
  disabled_toolsets:
    - web
    - search
    - browser
    - vision
    - video
    - image_gen
    - video_gen
    - x_search
    - tts
    - file              # write_file/patch/read_file: not needed, reading goes through terminal
    - cronjob           # schedules stay in our hands (hermes cron from the CLI)
    - code_execution    # one execution path is enough: terminal + scripts
    - delegation
    - spotify
    - discord
    - discord_admin
    - homeassistant
    - bfl
    - computer_use
    - yuanbao
    - kanban
  # Do NOT add `debugging`/`coding`/`safe` here: those are composite toolsets
  # and disabled_toolsets subtracts their TOOLS. `debugging` contains
  # terminal/process and would switch the terminal off entirely (learned on
  # the first start).

# What is available from Telegram (an allow list on top of disabled_toolsets)
platform_toolsets:
  telegram:
    - terminal
    - skills
    - memory
    - todo
    - clarify
    - session_search

display:
  persona: "Proxmox Sentinel"
  show_thinking: false

terminal:
  backend: local                      # the sandbox is the container itself (no docker.sock)
  cwd: /opt/data/work
  timeout: 300
  # variables the model's commands see (from /opt/data/.env)
  env_passthrough:
    - PVE_URL
    - PVE_TOKEN_ID
    - PVE_TOKEN_SECRET
    - PVE_VERIFY_TLS
    - PVE_CA_CERT
    - LITELLM_URL
    - LITELLM_KEY
    - LLM_MODEL
    - LLM_MAX_TOKENS
    - LLM_REASONING_EFFORT
    - TG_BOT_TOKEN
    - ALLOWED_USER_IDS
    - TG_CHAT_ID

approvals:
  mode: manual                        # anything "dangerous" only with confirmation in the chat
  timeout: 300
  cron_mode: deny
  destructive_slash_confirm: true
  # unconditional denies (even with /yolo); belt to the braces of a read-only PVE token
  deny:
    - "*pvesh set*"
    - "*pvesh create*"
    - "*pvesh delete*"
    - "*qm set*"
    - "*qm start*"
    - "*qm stop*"
    - "*qm shutdown*"
    - "*qm destroy*"
    - "*pct set*"
    - "*pct start*"
    - "*pct stop*"
    - "*pct destroy*"
    - "*ssh *"
    - "*scp *"
    - "*docker *"
    - "*curl*-X POST*"
    - "*curl*-X PUT*"
    - "*curl*-X DELETE*"
    - "*curl*--data*"
    - "*curl*-d *"
    - "*curl*-F *"
    - "*wget*--post*"

skills:
  write_approval: true                # new/changed skills only after review
  guard_agent_created: true
  # Hermes syncs its bundled skills into ~/.hermes/skills at start; all of
  # them are switched off by name so the agent only sees our proxmox-* skills
  # (the list = `ls /opt/hermes/skills/*/`).
  disabled:
    - apple-notes
    - apple-reminders
    - findmy
    - imessage
    - claude-code
    - codex
    - computer-use
    - hermes-agent
    - merge-reconciler
    - opencode
    - architecture-diagram
    - ascii-art
    - ascii-video
    - baoyu-infographic
    - claude-design
    - comfyui
    - design-md
    - excalidraw
    - humanizer
    - manim-video
    - p5js
    - popular-web-designs
    - pretext
    - sketch
    - songwriting-and-ai-music
    - touchdesigner-mcp
    - sdlc-review
    - email-inbox-triage
    - himalaya
    - codebase-inspection
    - github-auth
    - github-code-review
    - github-issue-to-pr
    - github-issues
    - github-pr-workflow
    - github-repo-management
    - gif-search
    - songsee
    - youtube-content
    - huggingface-hub
    - obsidian
    - airtable
    - box
    - document-to-action-items
    - docx
    - google-workspace
    - maps
    - meeting-action-items
    - nano-pdf
    - notion
    - ocr-and-documents
    - pdf
    - powerpoint
    - product-price-monitor
    - session-librarian
    - teams-meeting-pipeline
    - weekly-review-planning
    - xlsx
    - arxiv
    - blocked-page-recovery
    - blogwatcher
    - competitor-news-monitor
    - grounded-citations
    - llm-wiki
    - research-paper-writing
    - openhue
    - xurl
    - dogfood
    - hermes-agent-skill-authoring
    - inspecting-hermes-desktop-dom
    - node-inspect-debugger
    - plan
    - python-debugpy
    - requesting-code-review
    - simplify-code
    - spike
    - systematic-debugging
    - test-driven-development
    - evaluating-llms-harness
    - weights-and-biases
    - llama-cpp
    - serving-llms-vllm

memory:
  memory_enabled: true
  write_approval: false

compression:
  enabled: true
  threshold: 0.50
  target_ratio: 0.20

security:
  allow_private_urls: false           # web tools are off anyway; belt and braces
