إدارة الأسرار والمفاتيح
Secrets
ما هذه الصفحة، وماذا تحتوي.
الأسرار والمفاتيح: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك. تُحفظ في مكان واحد محمي، فلا تظهر في المحادثات ولا في الملفات التي تشاركها. ستستعمل هنا hermes model، والقراءة نحو 3 دقائق. انتبه: لا تكتب مفتاحًا داخل محادثة ولا داخل ملف إعداد تشاركه. استعمل متغيرات البيئة أو مدير أسرار.
نتائج مأخوذة من هذه الصفحة، لا من قالب.
- تعرف ما الأسرار والمفاتيح ولماذا قد تحتاجه.
- تنفّذ
hermes modelوتفهم ما يحدث بعدها. - تضبط
BWS_ACCESS_TOKENفي المكان الصحيح.
كما تظهر تمامًا داخل Hermes.
hermes model
BWS_ACCESS_TOKENFEISHU_APP_SECRETTELEGRAM_BOT_TOKENTELEGRAM_BOT_TOKEN_MILLA
انتقل مباشرة إلى ما تحتاجه.
بلا اختصار أو حذف.
النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.
Hermes can pull API keys from external secret managers at process startup instead of storing them in ~/.hermes/.env. The bootstrap token for the secret manager lives in .env; every other provider key (OpenAI, Anthropic, OpenRouter, etc.) can stay in the manager and rotate centrally.
Supported:
- Bitwarden Secrets Manager —
bwsCLI, lazy-installed, free tier works. - 1Password —
op://references via the officialopCLI; service-account or desktop session auth. - Command helper — any CLI vault (
keepassxc-cli,secret-tool,pass, custom scripts) via a user-configured helper that printsKEY=VALUElines.
Multiple sources at once
إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير. الأوامر هنا: hermes model. تضبط BWS_ACCESS_TOKEN خارج المحادثة، في بيئة التشغيل.
You can enable more than one secret source at the same time — for example a team Bitwarden project alongside a personal vault plugin. Sources compose per env var with a deterministic precedence ladder:
- Your
.env/ shell wins by default. A source only replaces a pre-existing value when its ownoverride_existing: trueis set (Bitwarden defaults to true so central rotation works). - Mapped sources beat bulk sources. A source where you explicitly bind env vars to references (an
env:map) outranks a source that injects a whole project of secrets implicitly, regardless of ordering. - First source wins. Within the same shape, the order of the optional
secrets.sourceslist (or registration order) decides. Later claims on an already-claimed var are skipped — with a startup warning, never silently.
override_existing never lets one source overwrite a var another source already claimed, and no source can ever overwrite another source's bootstrap token (e.g. BWS_ACCESS_TOKEN).
secrets:
sources: [bitwarden] # optional explicit ordering
bitwarden:
enabled: true
project_id: "..."Every credential injected by a source is labelled with its origin — setup flows and hermes model show (from Bitwarden) next to detected keys so you always know where a value came from.
Adding your own backend
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك.
Third-party secret managers ship as standalone plugins, not core PRs. A backend subclasses agent.secret_sources.base.SecretSource (one required method: fetch(cfg, home_path) -> FetchResult) and registers via ctx.register_secret_source(MySource()) in the plugin's register(ctx). The orchestrator owns precedence, conflict handling, timeouts, and provenance — your source only fetches. Full guide with the contract rules, subprocess-safety helper, and conformance kit: Building a Secret Source Plugin.
The bundled set is deliberately closed (same policy as memory providers): Bitwarden and 1Password ship in-tree. Everything else — Infisical, Proton Pass, HashiCorp Vault, AWS Secrets Manager, OS keystores — belongs in plugin repos; share them in the Nous Research Discord (#plugins-skills-and-skins).
3 أسئلة إجاباتها كلها في هذه الصفحة.
كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.