The trusted provider-worker image for Hermes Control Plane. It executes only exact-ticket-bound, allowlisted provider and infrastructure operations after the Control Plane has completed planning, preview, policy, approval, and drift checks.
docker pull afsharidevops/hermes-control-plane-node-agent:0.5.11
0.5.11 is the stable release tag.latest is published from stable, non-prerelease version tags.edge follows the main branch; use it only for evaluation.sha-… tags identify individual source commits.linux/amd64 and linux/arm64, with OCI provenance and an SBOM.vm.create, vm.clone, vm.update, vm.delete, vm.power, network.attach, snapshot.create, and snapshot.restore.Run this image only through the complete Hermes Control Plane Compose or Helm deployment:
git clone https://github.com/Afsharidevops/hermes-control-plane.git
cd hermes-control-plane
cp .env.example .env
./hermesctl init
VERSION=0.5.11 ./hermesctl up
8810GET /health/credentials/ssh and /credentials/infrastructure/var/lib/hermes-provider/tmp tmpfs in the reference deployment.false.Keep this service on the internal Hermes network and bind it to loopback only if a host mapping is required. Provision credentials as read-only worker mounts; never send them through the Control Plane, UI, audit evidence, or model path. The Proxmox runtime remains disabled until both infrastructure execution and its dedicated Proxmox flag are explicitly enabled with narrow capability allowlists.
See SECURITY.md and docs/PROXMOX-VM-RUNTIME-VALIDATION.md in the source repository.
Content type
Image
Digest
sha256:cf305d1bc…
Size
135.4 MB
Last updated
21 days ago
docker pull afsharidevops/hermes-control-plane-node-agent