Files
iris_x_hermes/docs
ARIA 6f339330c5
CI / Gateway plugin tests (push) Successful in 5m13s
CI / Kotlin tests (android host + desktop) (push) Successful in 6m43s
Move gateway-plugin tests out of the installable tree; clean plugin scan
The install-time security scanner scans the whole plugin directory and
flagged the test/dev fixtures (hardcoded tokens, /tmp paths, and the
~/.hermes/.env literal in setup.py) as DANGEROUS, blocking installs with
"19 findings".

- Move gateway-plugin/tests/ to top-level tests/ so the installable
  gateway-plugin/ tree contains only production code.
- Update _plugin_dir() in the tests and REPO in e2e.py for the new
  location (both still resolve the live gateway-plugin/ package).
- Update all references: docs, CI-SETUP.md, Gitea workflows, .pi-lens.json.
- Build the hermes .env path at runtime in setup.py via get_hermes_home()
  so the scanner no longer matches the literal ~/.hermes/.env.

Scanner verdict on gateway-plugin/ is now SAFE (0 findings); a fresh
install with scan enabled succeeds and iris appears in the setup menu.
2026-08-25 13:26:12 +02:00
..

Iris × Hermes — Implementation Reference Library

A coder-facing reference library for building a native Android + Desktop experience for hermes-agent, connected through a gateway platform plugin.

This folder is the single source of truth for what to build and why. Read it top-to-bottom once, then use the numbered docs as a lookup while implementing.

⚠️ READ FIRST — two hard rules

  1. hermes-agent/ (sibling of this folder) is a read-only research reference. It must NEVER be committed, pushed, or shipped. It is git-ignored at the repo root. We only install our plugin into a live hermes install (~/.hermes/plugins/); we never modify hermes core.
  2. ADB is installed and a device is connected (a5ca2a4b, Xiaomi MIX 2S, Android 10 / API 29). Use it to install/launch/debug the app on-device.

User-facing guides

  • install.md — install the gateway + connect the app (non-technical walkthrough, all options, TLS, push).
  • setup.md — moved; pointer to install.md.

Reading order

# File When to read
0 00-overview.md Always first. Vision, scope, disclaimers, locked decisions.
1 01-architecture.md Before touching code. System shape + rationale.
2 02-monorepo.md When scaffolding the repo.
3 03-gateway-plugin.md When building the Python plugin.
4 04-wire-protocol.md When implementing either side of the WS.
5 05-streaming.md Streaming / reasoning / tools / intermediate.
6 06-channels-cron-search.md Channels, threads, cron delivery, search.
7 07-media.md Media upload/download + playback.
8 08-push.md Push (ntfy default + FCM optional), outbox, sync.
9 09-pairing-security.md Pairing, auth, security model.
10 10-android-app.md When building the Iris app (Android).
11 11-desktop-app.md When building the Desktop app.
12 12-toolchain.md First time on a machine (JDK/SDK/uv/Firebase).
13 13-testing.md Writing tests + on-device ADB workflow.
14 14-milestones.md Planning work / tracking progress.
15 15-hermes-reference.md Cheat-sheet of hermes-agent source to read.
16 16-open-questions.md Decisions made + open items.
17 17-future-control-surface.md Backlog — what the app could control beyond chat (cron, kanban, models, …).
19 19-http-fallback-transport.md Design — HTTP fallback leg (POST + SSE/long-poll) so the app can send/receive when the WS is down.
20 20-qr-pairing.md Terminal QR at gateway setup + in-app QR scanner (Android) + iris://pair deep link.

Machine-readable / diagrams:


The three deliverables (one monorepo)

  1. gateway-plugin/ — a Python hermes platform plugin named iris. Runs inside the hermes gateway process. Opens a WebSocket server the apps connect to. Implements the full BasePlatformAdapter contract. Zero new Python dependencies, zero hermes-core changes.
  2. app/androidApp — native Kotlin + Jetpack Compose client.
  3. app/desktopApp — Kotlin + Compose Multiplatform client that shares the Iris app's code and is "tweaked" for a big screen.

The Iris Android and Desktop clients live in one Compose Multiplatform Gradle project (app/) with a shared KMP module (app/shared).


Status

  • Phase: M0–M6 complete; M7 (polish + E2E + docs) in progress.
  • Owner decisions locked: see 16-open-questions.md.
  • Last updated: 2026-08-19.