Hermes: An Isolated Agent
The hard boundary
An isolated agent architecture places memory, tools, voice, and scheduled work inside explicit trust boundaries. A resource-capped Docker container can run inside a dedicated virtual machine, with no shared host folders and a restricted network. Human access should use an authenticated chat channel or an SSH tunnel.
Inside the VM
A gateway can use a hosted model router and a non-root tool backend. Persistent configuration, memory, skills, and logs should survive container recreation. Mounting the raw Docker socket creates a root-equivalent escalation path; a separate virtual-machine boundary limits what a compromised container can reach.
Access and recovery
Bind administrative dashboards to loopback and reach them through an authenticated tunnel. Keep rollback checkpoints for known-good states, and verify recovery rather than assuming a scheduled backup is working. Nested sandboxing and credential storage need their own threat-model review.
How the pieces connect
Illustrative architecture and workflow.