Hermes gateway
01- ▸Routes Slack, webhooks, and channels to the right worker
- ▸Channel auth stays out of the execution pod
- ▸One gateway can front many workers
// agents
A reproducible template we run in production—spin up new agents for your org without long-lived secrets in the execution environment.
// architecture
// how it runs
Channels hit the gateway. The worker runs your config and tools. For GitHub or cloud APIs it calls in-cluster Go services that mint short-lived credentials—nothing long-lived in the pod.
// trust boundary
// pillars
What you provide
Identity, rules, scope
Static reference docs
Callable procedures
Repos, files, volume
How it runs
MCP, external APIs
Preferences, entities, corrections
Provider, routing
Platform
Kubernetes pod, gateway
Broker, identity, policy
Slack, webhooks, gateway
Logs, metrics, traces
You configure context, knowledge, skills, and workspace. The agent opens branches, commits, and PRs in repositories you own—state lives in your GitHub account, not in a disposable chat session.