エージェント

Hermes: An Always-On Agent for the Home Lab

It runs my automations. Every change still needs my yes.

← back to all projects
home lab·in progress·started 2026-06-11·updated 2026-10-08
agentsself-hostedguardrailsmcp

Overview

Hermes is Nous Research's open-source agent. Mine lives in a Docker container on my NAS and stays awake when my PC sleeps. I talk to it through a Telegram bot that only answers my account.

Its main job is the n8n workflows behind my Instagram pipeline. When a schedule needs moving or a run fails, I message Hermes instead of opening a laptop.

How it's wired

how it's wired
me, on telegram, wherever
        │
        ▼
telegram bot ──► Hermes (docker, on the NAS)
                    │                    │
                    ▼                    ▼
               OpenRouter           n8n MCP server
         Claude Sonnet: thinking     read workflows and runs
         small models: side jobs     edit drafts, publish

It started out on a small model running on my desktop GPU. An always-on agent whose brain switches off with my PC is not always on. The small model also struggled with its own tools, and most of the time it simply went quiet.

Now the thinking happens in Claude Sonnet through OpenRouter, on a key with its own monthly cap. Cheaper models take the side jobs like summarising. The bridge to my workflows is the MCP server built into n8n.

Guardrails

Being able to change a workflow and being allowed to change it are two different things. I wrote a whole post about that gap. Hermes gets a fixed routine for every change:

every change, every time
request on telegram
        │
        ▼
read the live workflow .......... never from memory
        │
        ▼
explain the plan
        │
        ▼
ask me ──── no ───► stop
        │ yes
        ▼
edit a draft .................... the live version keeps running
        │
        ▼
show me the diff
        │
        ▼
ask again ── no ───► the draft stays a draft
        │ yes
        ▼
publish

Two things it never does on its own: post to Instagram, or delete anything I didn't name. Scraped text inside a workflow run counts as data, never as instructions.

What went wrong

It described workflow nodes it had never opened. Confidently, with values. Then it apologised and admitted it hadn't read them. That earned a rule I didn't expect to write for software:

its rules file (excerpt)
## Hard rules (never drop these when editing this skill)
- Never claim you read something you didn't. If you describe a node,
  a value or a setting, you must have fetched it in this conversation.

It also has a self-improvement feature that rewrites its own instruction files. One pass tidied my rules file from about a hundred lines down to thirty-four. The thirty-four it kept were the polite ones. The ones it dropped were the safety rules. I put them back and switched the feature off.

Then it ran out of money mid-build. A big rebuild meant reading a lot of workflow code, and it burned through about ten euros in half an hour before hitting its cap. To its credit, it wrote a handoff note on the way down. Big builds now go to Claude Code on my desktop. Hermes keeps the small, frequent jobs.

What's next

Health checks for disks and backups that only wake me up when something breaks. After that, the same draft-first routine for every automation I add.