الأكاديمية ← تشغيل Hermes يوميًاتوثيق رسمي · إرشاد عربي

تحديد نطاق عمل الوكيل

Managed Scope

متوسط5 دقائق قراءةالدرس 115 أسئلة✓ 2026-08-18
قبل أن تقرأ

ما هذه الصفحة، وماذا تحتوي.

الأمان والموافقات: القواعد التي تحدّد ما يفعله Hermes وحده، وما يجب أن يستأذنك فيه أولًا. الوكيل ينفّذ ما فهمه لا ما قصدته. الموافقة هي فرصتك لتصحيح الفهم قبل أن يقع الفعل. الصفحة فيها تحذير من المصدر، و5 دقائق قراءة. انتبه: لا تلغِ الموافقات لتوفير الوقت. ابدأ بصلاحية القراءة فقط، ووسّع خطوة خطوة بعد أن تثق بالنتائج.

5أقسام
6أمثلة برمجية
1جداول
5أوامر
817كلمة من المصدر
الوصف الرسمي في سطر

Administrator-pinned, user-immutable config and secrets via a system-level managed directory

ماذا ستستطيع بعدها

نتائج مأخوذة من هذه الصفحة، لا من قالب.

  • تعرف ما الأمان والموافقات ولماذا قد تحتاجه.
  • تنفّذ hermes doctor وhermes config وتفهم ما يحدث بعدها.
  • تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
  • تضبط HERMES_MANAGED_DIR في المكان الصحيح.
ما ستقابله من أسماء

كما تظهر تمامًا داخل Hermes.

الأوامر
  • hermes doctor
  • hermes config
  • hermes config set
  • hermes sudo chmod
  • hermes config set model
متغيرات البيئة
  • HERMES_MANAGED_DIR
  • HERMES_HOME
  • OPENAI_API_BASE
خريطة الصفحة

انتقل مباشرة إلى ما تحتاجه.

  1. 01Where it lives
  2. 02Precedence
  3. 03Seeing what's managed
  4. 04Setting up a managed scope (administrators)
  5. 05Security model and limitations (v1)
الصفحة الرسمية كاملة

بلا اختصار أو حذف.

النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.

Managed scope lets an administrator push a baseline of configuration and secrets that a standard (non-root) user cannot override. It is intended for fleet/org deployments where IT needs to pin, for example, the model provider, a shared API base URL, or security.redact_secrets: true across every user on a machine.

When a managed scope is present, the values it specifies win over the user's ~/.hermes/config.yaml, ~/.hermes/.env, and even the shell environment — for exactly the keys it pins. Everything else stays fully user-controlled.

Where it lives

فيه تحذير مهم. اقرأه قبل أن تنفّذ أي شيء من هذا القسم. الأوامر هنا: hermes doctor. نصّ التحذير من المصدر مذكور أسفل هذا الشرح.

Managed scope is read from a system-level directory, default /etc/hermes:

Text3 أسطر
/etc/hermes/
├── config.yaml     # managed config layer (wins over ~/.hermes/config.yaml)
└── .env            # managed env layer (wins over ~/.hermes/.env + shell)

The directory and files are owned by root (directory mode 0755, files 0644): readable by everyone, writable only by an administrator. **That filesystem permission is the enforcement mechanism** — a standard user can read the managed files but cannot edit them.

Either file is optional. A missing managed directory or missing file simply means "no managed scope," and configuration resolves exactly as it does without the feature.

Relocating the directory

The location can be relocated with the HERMES_MANAGED_DIR environment variable (for containers or non-/etc deployments). This is a deployment/bootstrap path knob — like HERMES_HOME — set by the same administrator who owns the managed files. It is never persisted to any .env by Hermes.

Shellسطران
# Point managed scope at a custom directory (set by IT / the deployment, not the user)
export HERMES_MANAGED_DIR=/opt/org/hermes-policy

Precedence

إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير.

For the keys a managed layer specifies, the order is (highest wins):

Tierconfig.yaml.env
1/etc/hermes/config.yaml (managed)/etc/hermes/.env (managed)
2~/.hermes/config.yaml (user)~/.hermes/.env (user)
3built-in defaultspre-existing shell environment

Merging is leaf-level: pinning model.default does not freeze the rest of model.*. A managed config.yaml of:

YAMLسطران
model:
  default: org/standard-model

forces model.default for every user while leaving model.fallback (and every other key) under user control.

Seeing what's managed

خطوات عملية بالترتيب. نفّذ خطوة وتأكد أنها نجحت قبل الانتقال للتالية. الأوامر هنا: hermes config، hermes doctor.

Shellسطران
hermes config        # shows a header naming the managed source + the pinned keys
hermes doctor        # reports the resolved managed dir + pinned key counts

If you try to change a managed value, Hermes refuses and names the source:

Shell3 أسطر
$ hermes config set model.default my/model
Cannot set 'model.default': it is managed by your administrator
(/etc/hermes/config.yaml) and cannot be changed.

The same applies to managed secrets — hermes config set / setup will not write a user value for an env key pinned by the managed .env.

Setting up a managed scope (administrators)

إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير. الأوامر هنا: hermes doctor، hermes sudo chmod. تضبط OPENAI_API_BASE خارج المحادثة، في بيئة التشغيل.

Shell17 سطرًا
sudo mkdir -p /etc/hermes

# Pin some config values for every user on this machine
sudo tee /etc/hermes/config.yaml >/dev/null <<'YAML'
model:
  provider: nous
security:
  redact_secrets: true
YAML

# Optionally pin a shared, non-sensitive env value
sudo tee /etc/hermes/.env >/dev/null <<'ENV'
OPENAI_API_BASE=https://inference.example.com/v1
ENV

sudo chmod 0755 /etc/hermes
sudo chmod 0644 /etc/hermes/config.yaml /etc/hermes/.env

Changes take effect on the next Hermes start (a malformed managed file is logged loudly and ignored — it never blocks startup, but the admin should check hermes doctor to confirm the policy is being applied).

Security model and limitations (v1)

شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: القواعد التي تحدّد ما يفعله Hermes وحده، وما يجب أن يستأذنك فيه أولًا.

  • Enforcement is filesystem permissions only. If a user has write access to the managed directory (or runs Hermes as root), managed scope is advisory.
  • The managed .env is world-readable (0644), so any local user can read secrets pushed through it. Use it for shared, non-sensitive values (an org API base URL, feature defaults) rather than high-sensitivity secrets.
  • *The agent's own tools are not hard-blocked from a managed env value.* A managed environment variable is applied at startup, but nothing stops the agent from setting a different value inside its own subprocess shell. v1 is a management-convenience boundary against a normal user, not an un-escapable sandbox.

The following are intentionally out of scope for v1 and may come later:

  • A hard boundary that the agent itself cannot escape.
  • Native managed locations on macOS and Windows (v1 is Linux/POSIX-first).
  • Drop-in fragment directories (managed.d/) for layered policy.
  • Signed / integrity-checked managed files.
  • Remote / device-management (MDM) delivery.
  • Tighter (group-scoped) permissions for managed secrets.
اختبار الفهم

5 أسئلة إجاباتها كلها في هذه الصفحة.

كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.

1. بحسب هذا الدرس، أي أمر يقوم بـ«shows a header naming the managed source + the pinned keys»؟
2. بحسب هذا الدرس، أي أمر يقوم بـ«reports the resolved managed dir + pinned key counts»؟
3. في جدول هذا الدرس، ما «config.yaml» المقابل لـ«1»؟
4. أي متغير بيئة من التالي يظهر فعليًا في هذا الدرس؟
5. ما التحذير الذي يذكره المصدر في هذا الدرس؟