Academy → Using HermesOfficial documentation · clear explanation

Egress credential-injection proxy (iron-proxy)

Egress credential-injection proxy (iron-proxy)

Essential31 minutes3 questions2026-08-09
The idea in one minute

Start with meaning, then move to detail.

This lesson explains Egress credential-injection proxy (iron-proxy) as part of operating Hermes with explicit security boundaries. You will learn what it does, when it matters, and the smallest safe test that proves it works.

If you are new

If you are new, do not memorize names. Focus on three questions: what problem does this solve, what access does it need, and how can you verify the result?

For hands-on use

For practice, inspect the first example, identify its effects, run it on test data, and compare the result with the source claim.

For specialists

For advanced readers, inspect What it is, What it is not, Quick start, then verify failure modes and version compatibility.

What do you need first?

You only need to know which files and accounts the agent may access.

What will you know?

A clear outcome before you read.

  • Understand Egress credential-injection proxy (iron-proxy) without assumed prior knowledge.
  • Separate the source description from what still needs testing in your environment.
  • Read the first command and identify its inputs and outputs before copying it.
Lesson terms

Short definitions before the details.

Provider
The service that runs or provides access and authentication to a model.
Topic map

What does the source say, and in what order?

  1. 01
    What it is

    Start here to understand the core idea or structure.

  2. 02
    What it is not

    Read this after the foundation, then connect it to the previous step.

  3. 03
    Quick start

    Read this after the foundation, then connect it to the previous step.

  4. 04
    Configuration

    Read this after the foundation, then connect it to the previous step.

  5. 05
    Default allowed upstream hosts

    Read this after the foundation, then connect it to the previous step.

  6. 06
    Default SSRF deny CIDRs

    Read this after the foundation, then connect it to the previous step.

  7. 07
    Bind policy

    Read this after the foundation, then connect it to the previous step.

  8. 08
    Covered auth schemes

    Read this after the foundation, then connect it to the previous step.

  9. 09
    Uncovered providers

    Read this after the foundation, then connect it to the previous step.

  10. 10
    Bitwarden integration

    Finish here to verify the result and special cases.

Examples from the official page

Copy only after you understand the effect.

# 1. Install the iron-proxy binary (pinned version, SHA-256 verified) hermes egress install # 2. Run the wizard: generates CA, mints proxy tokens for every provider key # in your env, writes proxy.yaml. hermes egress setup # 3. Start the proxy daemon hermes egress start # 4. Check status hermes egress status
proxy: # Master switch. When false the feature is a complete no-op — no # binaries downloaded, no docker mounts added, no subprocess started. enabled: false # Tunnel listener port. Sandboxes hit http://host.docker.internal:<port>. tunnel_port: 9090 # Auto-download the pinned iron-proxy binary on first use. auto_install: true # Where iron-proxy looks up the real upstream secrets at egress time. # env — process env (default). Whatever is in your ~/.hermes/.env # at proxy-start time is the source of truth. # bitwarden — refetch from Bitwarden Secre
openrouter.ai *.openrouter.ai api.openai.com api.anthropic.com generativelanguage.googleapis.com api.x.ai api.mistral.ai api.groq.com api.together.xyz api.deepseek.com inference.nousresearch.com
Try it now

Read the first command and identify its inputs and outputs before copying it.

Match every command to your installed Hermes version, review the files and accounts it can reach, and use non-sensitive data for the first test. If this explanation differs from the source, the official source wins.

Knowledge check

Three decisions before completion.

1. What is the source of truth when “Egress credential-injection proxy (iron-proxy)” changes?
2. What is the best way to apply this lesson?
3. What should happen before a step can modify files or an external account?