Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Hermes Agent can run inside a Docker container, or it can run on your host while Docker contains the commands Hermes executes. These are different setups with different data locations and security boundaries. For the full application container, the official guide mounts user data at /opt/data. For Docker-backed terminal execution, Hermes stays on the host and its tools run in a sandbox container.

Which Docker setup do you need?

Choose based on what you want Docker to contain. Putting the whole Hermes application in a container changes how you install and persist Hermes. Using Docker as Hermes’s terminal backend changes where tool commands run, but leaves the application on the host.

Setup Where Hermes runs What Docker contains Where to focus
Full application container Inside Docker The Hermes application Mount and protect the host data directory used at /opt/data.
Docker terminal backend On the host Terminal, code execution, and file-tool execution Review sandbox settings, persistence, network access, and forwarded environment variables.

Neither approach makes an autonomous agent safe by itself. Docker can reduce direct exposure to the host, but it does not prevent an agent from misusing credentials deliberately passed to it, reaching the network when egress is enabled, or changing files and state that its container can access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you run the full Hermes application in Docker?

The official Hermes Agent Docker guide uses the nousresearch/hermes-agent image and a host directory mounted at /opt/data. Follow the guide’s current command block rather than copying a remembered command: image tags and command syntax can change.

  1. Create a host data directory. This directory holds Hermes user data that must survive container recreation.
  2. Run the image’s setup command with that directory mounted at /opt/data. The setup wizard requests API credentials and writes configuration into the mounted data area. Treat that directory as sensitive because it can contain credentials and other user data.
  3. Start the gateway using the same mount. Reusing the mount lets the container find the configuration and state created during setup.
  4. For an upgrade, follow the guide’s pull-and-recreate workflow and retain the data directory. Back it up before upgrading. The Docker guide says an image update can perform non-interactive configuration schema migrations on the mounted configuration and create timestamped backups beside configuration and environment files when a migration is needed.

The installation reference describes application files under /opt/hermes/ and user data under mounted /opt/data/; the image is intended to be stateless apart from that separately stored user data. Removing the mount or replacing it with a different host directory changes where Hermes finds its saved configuration and state. Protect the host directory with access controls appropriate for the credentials and data it holds.

How is Docker terminal execution different?

With this setup, install and run Hermes on the host, then configure its terminal backend to use Docker. The application is not inside the execution container. Hermes’s configuration documentation describes a long-lived shared container as the default, so changes made during tool use can remain available to later calls.

That persistence is convenient for work that needs installed packages or ongoing files and processes. It also means that, unless you configure isolation, separate conversations or Hermes processes may share the same execution environment. Files in /workspace, working-directory changes, installed packages, and background processes may carry over.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Shared container or per-session container?

The configuration documentation describes container_persistent: false as per-session mode: a fresh sandbox is created when needed for a chat or session and removed when that session closes or expires. The documented trade-offs are:

Consideration Long-lived shared container container_persistent: false
Files and installed packages Can carry over between tool calls and processes. Do not carry over between sessions.
Isolation between conversations Conversations can share the same container unless you choose another isolation approach. Each session gets a fresh sandbox.
Background processes Can persist in the shared container. Do not carry over between sessions; the sandbox is removed when the session closes or expires.
Convenience Retains setup and state for continuing work. Trades that carryover for session separation.

Use the shared mode only when the value of persistent state outweighs the risk of cross-conversation carryover. Per-session mode is a better fit when conversations should not inherit one another’s execution files or processes.

What security controls should you review?

Hermes Agent security documentation lists hardening controls for the Docker terminal backend, including dropping Linux capabilities, adding back DAC_OVERRIDE, CHOWN, and FOWNER, enabling no-new-privileges, setting a PID limit, and using size-limited temporary filesystems. It also documents configurable CPU, memory, disk, and persistence settings. These are controls for that backend; they do not establish that every Docker installation—or the full application container—has identical protections.

Review custom Docker arguments carefully. The configuration documentation says docker_extra_args are appended to the Docker invocation and can override defaults. An extra flag that conflicts with sandbox hardening may silently weaken isolation. Treat changes to this setting as changes to the security boundary, not merely as convenience tweaks.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limit credentials passed into the sandbox

Hermes Agent security documentation states: “If you add names to terminal.docker_forward_env, those variables are intentionally injected into the container for terminal commands.” The documentation warns that code running there can read and exfiltrate forwarded values. Forward only the credentials a task requires, keep their scope and lifetime as limited as possible, and avoid putting broadly useful secrets into a shared or persistent execution context.

Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Decide whether the terminal sandbox needs network access

The terminal configuration option terminal.docker_network: false disables network egress for the execution container by using --network=none. The setting applies to the container used by terminal, code execution, and file tools. It can block tasks that need to download dependencies or contact services, so use it when those network capabilities are unnecessary and account for the workflow impact when they are required.

If a persistent container already exists, changing network configuration can cause Hermes to replace it. That replacement can end background processes running in the old container. Plan the change around any work that depends on those processes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What risks remain after containerizing Hermes?

A container narrows what execution tools can directly reach on the host; it does not resolve risks involving agent instructions, credentials, network-accessible services, or persistent data. The practical exposure depends on what the agent can read, which tools and skills it can use, what network access is available, and whether its execution state is shared.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Cloud Security Alliance research note dated May 2026 discussed risks involving credentials, persistent memory, community skills, prompt injection, and network-accessible endpoints. It recommended measures including a non-local sandbox backend, a restricted write-safe root, memory protections and audits, review of community skills, and controls on network-accessible endpoints. The note labels its work AI-assisted; treat it as a dated research note and a set of operational recommendations, not as a vendor guarantee or proof of the present status of any particular issue. Docker alone does not establish that these risks have been addressed.

  • Give the agent access only to files and credentials needed for its task.
  • Review skills before enabling them, especially when they can execute code or access external services.
  • Choose persistent or per-session execution deliberately, based on whether state should cross conversation boundaries.
  • Review network access and exposed endpoints alongside container settings.
  • Back up full-application data before upgrades that may migrate persisted configuration.

Which setup is the safer fit?

If you want Hermes itself packaged in a container, use the official application image and preserve its host-mounted /opt/data directory. If your goal is to keep tool execution away from the host, run Hermes on the host and configure Docker as its terminal backend, then review persistence, forwarded credentials, network egress, and extra arguments. In either case, make the container’s actual access—not the word “Docker”—the basis for your security decision.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.