Hermes
hermes-agent 0.19.0InstalledInstalled 11 Sep 2026 in an isolated Python virtual environment.
~/workspace/venvs/hermes~/workspace/venvs/hermes/bin/hermes~/workspace/agents/hermes/ops-notebook.mdThe Google document version of this artifact is here.
A current-state map of agent frameworks, runtimes, utilities, backups, automation, and unfinished setup — with the paths and limits needed to rebuild the machine without relying on memory.
Tool versions and the reported operational states were refreshed on 27 Sep. No tool-version drift, new tools, or removed tools were found since 26 Sep. The 1Password session supervisor and Tailscale are healthy; Syncthing is not running and remote-device pairing remains pending. The enabled machine-inventory-refresh job maintains this record daily. Significant installs, upgrades, failures, and architecture decisions remain in the separate Machine Changelog.
Installed 11 Sep 2026 in an isolated Python virtual environment.
~/workspace/venvs/hermes~/workspace/venvs/hermes/bin/hermes~/workspace/agents/hermes/ops-notebook.mdInstalled 11 Sep 2026 globally with bun.
bun add -g~/.bun/bin/openclawInstalled 13 Sep 2026 globally with bun.
bun add -g @openai/codex~/.bun/bin/codexcodex exec runs non-interactively without a TUI; codex exec resume --last continues the latest session.codex login --device-auth. Current status: Not logged in.Global npm installs fail as root because npm attempts a chown operation that the /home/hatch mount rejects with EPERM. pnpm also fails because the mount rejects its hardlinks. bun works reliably, so global JavaScript tools should use bun. The bun.sh installer is URL-blocked from the shell; fetch bun from GitHub releases instead.
/tmp is a 512 MB noexec filesystem. Keep downloads small, use ~/workspace for working files, and never run binaries from /tmp.
Credential operations, session continuity, and nightly vault hygiene.
CLI installed under the workspace tool directory.
~/workspace/bin/opAuto-tidy and auto-merge automation, with dated run reports and non-secret state.
~/workspace/1password-tidy/tidy.py — nightly tidy and mergesession_supervisor.py — keeps the user-mode session in process memorykeepalive.sh — pings the session and records checksstate.json, README.md, and tidy-reports/The ssoLogin / UNKNOWN-field validation bug remains present in op 2.39.0. The CLI can neither edit nor delete SSO-affected items; the my.1password.com web app is the only confirmed write path for them.
Joined 9 Sep 2026.
Durable SSH configuration and wrapper path for ten enrolled fleet hosts, routed through the required tunnel proxy.
~/workspace/fleet/ssh_confighp-z-book + WSL, dell-latitude + WSL, dell-xps + WSL, lg-gram + WSL, hp-elitebook, and pixel-8-rooted./home/hatch/.ssh/id_ed25519/home/hatch/.ssh/known_hosts_fleetProxyCommand ~/workspace/bin/tailscale-ssh-proxy.py through the HTTP CONNECT tunnel proxy on port 3130.~/workspace/bin/fleet-ssh, fleet-scp, and fleet-ssh-ensure.fleet-ssh-ensure restores /root/.ssh/config from the canonical copy; the wrappers then connect with ssh -F or scp -F. Always use the wrappers for fleet hosts, never bare ssh or scp.After a VM restart, the shell runs as root and OpenSSH reads configuration from the passwd home at /root/.ssh/config, ignoring $HOME. Because /root is ephemeral and wiped on restart while /home/hatch persists, the ensure step rebuilds root’s active config from the durable canonical copy.
Most tools were installed 11 Sep 2026 under ~/workspace/bin through the reproducible installer at ~/workspace/bootstrap-tools.sh. The inotify utilities were added separately on 18 Sep and are now active in the transcript-watching stack.
Persistent event-driven file-watching utilities, installed 18 Sep 2026 and now used by the transcript-watching stack.
~/workspace/bin/inotifywait and ~/workspace/bin/inotifywatch~/workspace/lib/libinotifytools.so.0 → libinotifytools.so.0.4.1LD_LIBRARY_PATH=~/workspace/lib.dpkg-deb -x from inotify-tools_4.23.9.0-2_amd64.deb and libinotifytools0_4.23.9.0-2_amd64.deb in Ubuntu 24.04 noble’s universe pool after apt fetching stalled. Nothing was installed under ephemeral /usr.Platform-agnostic continuity backup. Rebuilds every Wednesday and Sunday at 09:20 ET and keeps the four newest kits.
~/workspace/backup/build-revival-kit.sh~/workspace/your_files/moose-revival-kit-2026-09-16.tar.gz — produced by the Wed 16 Sep rebuildThe collector and renderer behind the Muse Machine VM health cockpit.
Installed and verified 15 Sep 2026. Uses only the Python standard library; no new packages were installed.
~/workspace/machine-monitor/monitor.py1.1.1.1:443, DNS lookup latency, boot and uptime, top processes, and service health.cockpit.html.~/workspace/machine-monitor/, pushed to the private GitHub repository muse-000-meta-hatch/muse-machine.ICMP ping is blocked on this VM, so the monitor measures TCP connection latency to 1.1.1.1:443 and DNS lookup latency instead. No temperature sensor or thermal zone is exposed; the cockpit reports that absence rather than fabricating a value.
Two-tier scheduling architecture established 18 Sep 2026. The full SOP is the source of truth; Meta retains supervision and rollback while supercronic runs the high-frequency programmatic jobs.
Runs the workspace crontab with -inotify, so schedule changes reload live without restarting the process.
~/workspace/bin/supercronic~/workspace/scheduler/crontab~/workspace/bin/scheduler-run.sh~/workspace/scheduler/logs/; failures append to ~/workspace/scheduler/alerts.log.programmatic-supervisor runs every 15 minutes through ~/workspace/bin/supervise-programmatic.sh to keep supercronic and the inotify watchers alive.~/workspace/scheduler/SOP.md — authoritative workflow, process, specification, and operating procedure.~/workspace/scheduler/MIGRATION.md — migration record and rollback context.Runs the existing muse-machine-collect job through the programmatic runner.
muse-machine-collectRuns the existing completion-enforcement job through the programmatic runner.
completion-enforcer-15mRuns the OpenClaw keepalive watchdog through the programmatic runner.
openclaw-keepalive-watchdogPersistent file watchers supervised alongside supercronic.
~/workspace/bin/inotifywait and ~/workspace/bin/inotifywatch~/workspace/lib; requires LD_LIBRARY_PATH=~/workspace/lib.~/workspace/bin/inotify-watchdog.sh~/hooks/state/inotify-watches.json8845 and 8857 were running on 22 Sep, watching MUSE-DECISIONS.md and TEAM-DECISIONS.md.Rebuilt as an echo-only file-watcher relay; Variant #01 remains the judge.
/home/hatch/agents/*/sessions/*.jsonl, covering every session thread.Core process and schedule states were refreshed 27 Sep 2026. No scheduler changes were found since 26 Sep: 1Password keepalive, session revive, nightly tidy, daily disk watch, both Revival Kit rebuilds, the programmatic supervisor, the OpenClaw gateway keepalive, and the daily inventory refresh remain enabled. The inotify watchdog remains disabled and dormant by design in ~/workspace/cron.d/_archive; when no watch manifest exists, it verifies the inotifywait binary only. Other unchanged scheduler entries retain their last recorded states below; programmatic schedules are listed above.
The standalone session_supervisor.py process was running as PID 6672 on 27 Sep after routine churn since 26 Sep. At 06:40:50 ET, the latest keepalive.log check reported OK user session alive and supervisor alive, pid 30928.
OP_SESSION_my in process memory only; the value is never written to disk.1password-session-keepalive schedule providing regular health checks and the new 1password-session-revive schedule providing recovery.tidy-reports/YYYY-MM-DD.md.The latest check at 06:40:50 ET recorded OK user session alive and supervisor alive, pid 30928.
1password-session-keepaliveCompanion recovery job for the user-mode 1Password session.
1password-session-reviveDelivers the morning report to the “1Password vault cleanup” side chat.
1password-nightly-tidyStays silent unless disk usage reaches 80%.
daily-disk-watchRebuilds the continuity archive and keeps the newest four kits.
revival-kit-rebuild-wedRebuilds the continuity archive and keeps the newest four kits.
revival-kit-rebuild-sunReports supercronic and the manifest-driven inotify watchers healthy through ~/workspace/bin/supervise-programmatic.sh.
programmatic-supervisorMaintains gateway availability through the Meta scheduler.
openclaw-gateway-keepaliveMaintains this inventory every day without changing the separate manual Machine Changelog.
machine-inventory-refreshNo watchdog is restarting Syncthing. The daemon had no running PIDs on 27 Sep, and remote-device pairing remains pending.
syncthing-vm-watchdogArchived in ~/workspace/cron.d/_archive and disabled by design; when no watch manifest exists, it verifies the inotifywait binary only.
inotify-watchdog · owner goal:machine-health-monitoringThe Meta schedule is retained but disabled. The active job now runs every 10 minutes through supercronic.
muse-machine-collectThe Meta schedule is retained but disabled. The active job now runs every 15 minutes through supercronic.
completion-enforcer-15mThe Meta schedule is retained but disabled. The active watchdog now runs every 15 minutes through supercronic.
openclaw-keepalive-watchdogConfigure model-provider credentials.
Sign in through the headless device-code flow.
Pair with the user’s devices.
Choose and configure Cloudflare R2, Backblaze B2, or NAS.