Skip to main content

Overview

Hermes is Ankra’s autonomous infrastructure agent. It runs on the open-source OpenClaw runtime and connects to Ankra through the CLI, so it can manage clusters, build stacks, query Ankra AI, and provision the backing services your application needs — all from chat platforms like Slack, Discord, and Telegram. Hermes is built to be given real responsibility. You can hand it full control to design and configure the infrastructure your app depends on — a Postgres database, a Redis cache, an ingress, observability — and it will draft the architecture, produce a detailed bill of materials, and ask for your confirmation before it builds anything. This guide covers:
  1. What Hermes can do — skills, the CLI, Ankra AI, stacks, profiles, and full architecture design
  2. Deploying Hermes on any Kubernetes cluster as an Ankra stack
  3. Connecting Hermes to Ankra by adding the Ankra CLI as a skill
  4. The safeguards that keep autonomy safe — confirmations, drafted architecture, and a detailed bill of materials
Hermes runs on the OpenClaw runtime. If you are looking for the OpenClaw integration, this is now Hermes — the deployment mechanics are unchanged.

What Hermes can do

Skills

Extend Hermes with skills. The Ankra CLI skill turns natural language into cluster, stack, and credential operations.

Ankra CLI

Hermes drives the full ankra CLI — clusters, stacks, charts, credentials, and tokens — on your behalf.

Ankra AI

Hermes asks Ankra AI about live cluster state for health checks, root-cause analysis, and troubleshooting.

Build stacks

Hermes composes Helm addons and manifests into stacks and deploys them through Ankra’s GitOps flow.

Profiles

Reusable agent profiles bundle a model, skills, guardrails, and an autonomy level so Hermes behaves consistently per environment.

Design your app's tools

Hand Hermes a goal (“my app needs a database and a cache”) and it designs the architecture, lists the components, and builds them after you confirm.

Part 1: Deploy Hermes as an Ankra Stack

Deploy Hermes to any Kubernetes cluster managed by Ankra using the Stack Builder. This gives you a self-hosted, containerized agent running inside your own infrastructure.

Prerequisites

  • A cluster imported into Ankra with the agent connected
  • An API key from Anthropic or OpenAI
You do not need to add a Helm registry. OpenClaw ships as a global registry in every Ankra organisation, pointing at oci://registry.gitlab.com/xrow-public/helm-openclaw/charts/openclaw. Search for openclaw in the chart picker and it is there.

Step 1: Create the Stack

1

Open Stack Builder

Navigate to your cluster → StacksCreate Stack.
2

Name Your Stack

Name it hermes or ai-agent.

Step 2: Add the Hermes Chart

1

Add the Chart

Click + Add → search for openclaw from the OpenClaw registry (this is the runtime Hermes is built on).
2

Configure Core Settings

Click the component and set these values. Every value the chart reads lives under the top-level openclaw key:
Hermes runs as a single instance — it does not support horizontal scaling, and the chart does not expose a replica count.
3

Configure API Key

The chart renders openclaw.secrets into a Kubernetes Secret and injects each entry as an environment variable:
Encrypt the value with SOPS before it reaches Git, or point the entry at an existing Secret (see Production Setup below).
4

Configure Resources

5

Enable Persistent Storage

Hermes stores workspace data and conversation memory. Persistence is on by default at 20Gi; shrink it if your cluster is small:
Encrypt sensitive values with SOPS: In the manifest edit view, click the SOPS button to encrypt your API key. This ensures the key is stored encrypted in your GitOps repository. See SOPS Encryption for setup instructions.

Step 3: Expose the Gateway (Optional)

The gateway ingress publishes the webhook endpoints Hermes listens on, /api/hooks and /api/messages, so a chat platform can reach it. The chart renders those paths for you; you only supply the host, class and TLS.
On an Ankra-provisioned cluster the networking stack installs Traefik as the default ingress class, the letsencrypt-prod ClusterIssuer, and external-dns bound to the cluster’s delegated ankra.cc subdomain. Use a host under that subdomain and the DNS record and certificate are created for you. See UpCloud Clusters for where the subdomain comes from.
Alternatively, use port-forwarding for local access:

Step 4: Deploy

1

Review

Your stack should contain the chart with your configured values.
2

Save and Deploy

Click Save, then Deploy. Watch progress in Operations.
3

Verify

After 1-2 minutes, the Hermes pod should be running:

Production API Key Management

For production deployments, store your API key in a Kubernetes Secret rather than in plain-text values:
1

Create the Secret

2

Keep the value out of Git

The chart takes the key as a literal in openclaw.secrets, so encrypt that value with SOPS and let Ankra decrypt it at deploy time:
Add the path to the stack’s encrypted_paths so the plaintext never reaches the repository.

Security Hardening

Lock down the Hermes pod with security contexts:
Hermes has shell access and can read files inside its container. Kubernetes provides meaningful isolation through container boundaries and network policies. For sensitive environments, apply a NetworkPolicy to restrict egress to only the AI provider API endpoints your model requires.

Network Policy Example

Restrict Hermes’ network access to only the AI provider API:
You can add this as a manifest in your stack alongside the chart.

Connect a Chat Platform

Once Hermes is running in your cluster, connect it to your team’s chat:
Store all chat platform tokens in a Kubernetes Secret and reference them via existingSecret for production use.

Part 2: Add Ankra CLI as a Hermes Skill

Once Hermes is running (either via the stack above or any other installation), you give it the ability to manage your Ankra infrastructure by adding the CLI as a skill.

Prerequisites

  • Hermes installed and running (or deployed as a stack above)
  • Ankra CLI installed and authenticated
  • An Ankra API token (for non-interactive auth)

Step 1: Install and Authenticate the Ankra CLI

If you haven’t already, install the Ankra CLI:
Create an API token for Hermes to use (this avoids browser-based SSO, which doesn’t work in headless environments):
Save the returned token — you’ll need it in the next step.

Step 2: Create the Ankra Skill

Create the skill directory and manifest:
Create ~/.openclaw/skills/ankra/SKILL.md with the following content:

Step 3: Configure the Skill

Add the Ankra skill to your Hermes configuration at ~/.openclaw/openclaw.json:
Replace your-ankra-api-token with the token you created in Step 1.
If you already have other skills configured, just add the ankra entry to your existing entries object.

Step 4: Verify the Integration

Restart Hermes or wait for the skill watcher to pick up the changes, then test:

Use cases

Use the Ankra CLI

With the Ankra CLI skill installed, Hermes turns plain language into CLI operations. You never have to remember command syntax — describe the outcome and Hermes runs the right commands.

Use Ankra AI

Hermes uses ankra chat to consult Ankra AI, which has live access to your cluster state. Use it for health checks, root-cause analysis, and “why is this broken” questions.

Build stacks

Hermes composes Helm addons and manifests into stacks and deploys them through Ankra’s GitOps flow.

Profiles

A profile is a reusable agent configuration that bundles a model, a set of skills, guardrails, and an autonomy level. Profiles let Hermes behave consistently and appropriately per environment — a cautious, read-mostly profile for production and a freer profile for a sandbox. Define profiles in your Hermes configuration:

Give Hermes full control to design your app’s tools

This is what Hermes is built for. Hand it a goal and let it design and configure the infrastructure your application needs — a database, a cache, ingress, secrets, and observability — end to end. Hermes works in three phases: design, confirm, build. It never provisions anything before you approve the drafted architecture and its bill of materials.
Hermes can iterate on the design before building — ask it to add a read replica, change storage sizes, swap a chart, or pin versions, and it will re-draft the architecture and bill of materials before asking again.

Safeguards

Autonomy is only safe with rails. Hermes enforces these by default, and you can tighten them per profile.

Confirmations

Destructive and provisioning actions (delete, deprovision, scale-down, building infrastructure) require explicit approval before they run.

Drafted architecture

Before building anything, Hermes presents the architecture it intends to create so you can review and adjust it.

Detailed bill of materials

Every build is accompanied by a bill of materials — charts, versions, replicas, storage, and estimated resources — so there are no surprises.

Secrets stay secret

Credentials are written to Kubernetes Secrets and encrypted with SOPS in GitOps. Hermes never echoes tokens or credentials back in chat.
Match the autonomy level to the environment. Use a confirm-all profile with architecture drafts and a bill of materials required for production, and reserve freer profiles for sandbox clusters.

Sandboxed Environments

If you run Hermes in sandboxed mode (Docker), the ANKRA_API_TOKEN environment variable won’t be inherited automatically. Add it to your sandbox config:
You’ll also need to ensure the ankra binary is available inside the container. Either mount it or install it in a custom image:

Troubleshooting

Stack Deployment Issues

Skill Integration Issues

The Ankra CLI stores its config at ~/.ankra.yaml. When using API token auth via ANKRA_API_TOKEN, no config file is needed.

Next Steps

Stacks

Learn more about building and managing stacks in Ankra.

SOPS Encryption

Encrypt sensitive values in your stack configuration.

Ankra CLI

Full CLI reference for all Ankra commands.

Monitoring Stack

Add observability alongside your Hermes deployment.