============================================================
Status: ✅ COMPLETE — all five readiness phases executed (Aug 2026).
Purpose: Prepare the existing SIAAS (Sovereign Infrastructure as a Service) platform
infrastructure so that it can host the planned Hermes agent work — where each client
practice gets their own sovereign environment and clients configure their own AI agents
(model, provider, skills, knowledge) through the application.
client-postgres v1.2.0 (plain) + ssh-v1.2.0 (tunnel)pgvector/pgvector:pg15 base, auto-enabling the vector extension on tenant DBs;git.veripath.co.uk/infra. Central gp_booking_postgres switched to adev-client dev tenant created; pgvector cosineSectorDatabaseRouter. Also fixed a$PGDATA meant client DBs ran0.0.0.0/0 reject).channels/daphne/channels-redis togunicorn → daphne; ASGI routing + Redis channel layer/ws/ upgrade locations added for gp + dental. /ws/echo/ verified (101tenant-gateway@.service systemd units (15432/5435/5436/5437, auto-restart + health).SSH_PRIVATE_KEY env / /run/secrets/tunnel_key) with anousresearch/hermes-agent pinned by digest/root/hermes-sandbox). Reusable per-tenant agent template created at/opt/infra/agent-template (env-driven model keys, per-tenant volume, dashboard port)./root/backup.sh/opt/scripts/volume-backup.sh (minio, media, forgejo, wiki content,Note: a new Forgejo token
docker-push-2026-08(deploy user,write:package, write:repository) was minted to enable image pushes; it is revocable from Forgejo →
Settings → Applications.
The platform runs on a multi-tenant SIAAS model:
client-postgres, the dental app, media storage, and (in future) theirThe plan for Hermes is documented on
development/projects/dental_app/hermes_ai.
That plan requires infrastructure that is not yet in place — this page summarises the
readiness work that must happen first.
SectorDatabaseRouter (per-tenant DB routing), Tenant model with encryptedintegrations.AgentConfig (encrypted API keys) + agent_service.py/integrations/agents/, MinIO DICOM configuration./opt/infra (owns the hub network, digest-pinnedbring-up.sh + systemd infra-bringup.service).10.0.0.1), client cloud-init templates, backup-client.py,collect-capacity.py, restore-client.py, Keycloak partner onboarding.client-postgres image (base pgvector/pgvector:pg15-alpine,ssh-v1.2.0 and push.client-postgres on the tunnel port (127.0.0.1:5436) with the172.18.0.1:5436 so the app reaches it exactly as it would a real client VPS.gp_booking_postgres (in /opt/infra) to a pgvector-enabled image.vector extension on the dev tenant DB and add a minimal vector column as achannels, daphne, channels-redis to the gp + dental apps.gunicorn to daphne; add ASGI routing and a Redis channel layer.Upgrade/Connection headers to the nginx vhosts for gp/dental./ws/ endpoint on the dev tenant to verify end-to-end streaming.client-postgres entrypoint (inject via secrets).latest / v1.0.0 / ssh-v1.1.0 / ssh-latest).Tenant recordAgentConfig seed → register in backup-client.py / collect-capacity.py.nousresearch/hermes-agent image by digest.~/.hermes volume, dashboard port.AgentConfig (encrypted at rest)/root/backup.sh).dental-radiographs, Orthanc, wiki content, tenant media,env.production files, hardcoded keys).Once these phases are complete the platform can:
pgvector inside each client's isolated database.Control Centre UI build-out on /integrations/agents/, the radiograph_ai.py + pgvector
pipeline, the in-surgery streaming UI, per-role agents, and prompt assembly. These depend on
the infrastructure readiness above.
============================================================
Page: https://wiki.veripath.co.uk/infrastructure/siaas/hermes-infrastructure-preparation