Egress credential-injection proxy (iron-proxy)
Egress credential-injection proxy (iron-proxy)
Start with meaning, then move to detail.
This lesson explains Egress credential-injection proxy (iron-proxy) as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.
If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?
For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.
For advanced readers, inspect What it is, What it is not, Quick start, then verify failure modes and version compatibility.
You only need to know which files and accounts the agent may access.
A clear outcome before you read.
- Understand Egress credential-injection proxy (iron-proxy) without assumed prior knowledge.
- Separate the source description from what still needs testing in your environment.
- Read the first command and identify its inputs and outputs before copying it.
Short definitions before the details.
- Provider
- The service that runs or provides access and authentication to a model.
What does the source say, and in what order?
- 01What it is
Start here to understand the core idea or structure.
- 02What it is not
Read this after the foundation, then connect it to the previous step.
- 03Quick start
Read this after the foundation, then connect it to the previous step.
- 04Configuration
Read this after the foundation, then connect it to the previous step.
- 05Default allowed upstream hosts
Read this after the foundation, then connect it to the previous step.
- 06Default SSRF deny CIDRs
Read this after the foundation, then connect it to the previous step.
- 07Bind policy
Read this after the foundation, then connect it to the previous step.
- 08Covered auth schemes
Read this after the foundation, then connect it to the previous step.
- 09Uncovered providers
Read this after the foundation, then connect it to the previous step.
- 10Bitwarden integration
Finish here to verify the result and special cases.
Copy only after you understand the effect.
# 1. Install the iron-proxy binary (pinned version, SHA-256 verified)
hermes egress install
# 2. Run the wizard: generates CA, mints proxy tokens for every provider key
# in your env, writes proxy.yaml.
hermes egress setup
# 3. Start the proxy daemon
hermes egress start
# 4. Check status
hermes egress statusproxy:
# Master switch. When false the feature is a complete no-op — no
# binaries downloaded, no docker mounts added, no subprocess started.
enabled: false
# Tunnel listener port. Sandboxes hit http://host.docker.internal:<port>.
tunnel_port: 9090
# Auto-download the pinned iron-proxy binary on first use.
auto_install: true
# Where iron-proxy looks up the real upstream secrets at egress time.
# env — process env (default). Whatever is in your ~/.hermes/.env
# at proxy-start time is the source of truth.
# bitwarden — refetch from Bitwarden Secreopenrouter.ai *.openrouter.ai
api.openai.com api.anthropic.com
generativelanguage.googleapis.com
api.x.ai api.mistral.ai
api.groq.com api.together.xyz
api.deepseek.com inference.nousresearch.comRead the first command and identify its inputs and outputs before copying it.
Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.