Files
iris_x_hermes/docs
ARIA c7a16d51e3
CI / Gateway plugin tests (push) Successful in 4m55s
CI / Kotlin tests (android host + desktop) (push) Successful in 6m58s
gateway setup: offer self-signed TLS cert generation (no openssl needed)
hermes gateway setup now asks 'Set up TLS now?' when IRIS_HTTP_CERT is
not in .env (default No, Yes for an all-interfaces bind). Accepting
generates a 10-year RSA-2048 self-signed cert with SANs (advertised LAN
IP, hostname, loopback) under ~/.hermes/iris/ via hermes' existing
cryptography dependency, saves IRIS_HTTP_CERT/IRIS_HTTP_KEY, and prints
the SHA-256 fingerprint in openssl format for the app's confirm-and-pin
dialog. The pairing URL/QR printed afterwards already advertise https.

- key created 0600 from the start (no umask window)
- save_env_value inside the best-effort guard (unwritable .env warns)
- leftover cert without env var -> overwrite confirmation (protects the
  app's pinned fingerprint)
- bind wildcards (0.0.0.0 / ::) never become SANs; :: gets the same
  default-Yes as 0.0.0.0 (pairing._unroutable parity)

Tests: 5 new (cert generation incl. openssl fingerprint cross-check,
accept/decline, no re-prompt, default-follows-bind, overwrite prompt).
Docs: install.md Part 2 table + Part 4 Option B.
2026-08-24 22:46:27 +02:00
..

Iris × Hermes — Implementation Reference Library

A coder-facing reference library for building a native Android + Desktop experience for hermes-agent, connected through a gateway platform plugin.

This folder is the single source of truth for what to build and why. Read it top-to-bottom once, then use the numbered docs as a lookup while implementing.

⚠️ READ FIRST — two hard rules

  1. hermes-agent/ (sibling of this folder) is a read-only research reference. It must NEVER be committed, pushed, or shipped. It is git-ignored at the repo root. We only install our plugin into a live hermes install (~/.hermes/plugins/); we never modify hermes core.
  2. ADB is installed and a device is connected (a5ca2a4b, Xiaomi MIX 2S, Android 10 / API 29). Use it to install/launch/debug the app on-device.

User-facing guides

  • install.md — install the gateway + connect the app (non-technical walkthrough, all options, TLS, push).
  • setup.md — moved; pointer to install.md.

Reading order

# File When to read
0 00-overview.md Always first. Vision, scope, disclaimers, locked decisions.
1 01-architecture.md Before touching code. System shape + rationale.
2 02-monorepo.md When scaffolding the repo.
3 03-gateway-plugin.md When building the Python plugin.
4 04-wire-protocol.md When implementing either side of the WS.
5 05-streaming.md Streaming / reasoning / tools / intermediate.
6 06-channels-cron-search.md Channels, threads, cron delivery, search.
7 07-media.md Media upload/download + playback.
8 08-push.md Push (ntfy default + FCM optional), outbox, sync.
9 09-pairing-security.md Pairing, auth, security model.
10 10-android-app.md When building the Iris app (Android).
11 11-desktop-app.md When building the Desktop app.
12 12-toolchain.md First time on a machine (JDK/SDK/uv/Firebase).
13 13-testing.md Writing tests + on-device ADB workflow.
14 14-milestones.md Planning work / tracking progress.
15 15-hermes-reference.md Cheat-sheet of hermes-agent source to read.
16 16-open-questions.md Decisions made + open items.
17 17-future-control-surface.md Backlog — what the app could control beyond chat (cron, kanban, models, …).
19 19-http-fallback-transport.md Design — HTTP fallback leg (POST + SSE/long-poll) so the app can send/receive when the WS is down.
20 20-qr-pairing.md Terminal QR at gateway setup + in-app QR scanner (Android) + iris://pair deep link.

Machine-readable / diagrams:


The three deliverables (one monorepo)

  1. gateway-plugin/ — a Python hermes platform plugin named iris. Runs inside the hermes gateway process. Opens a WebSocket server the apps connect to. Implements the full BasePlatformAdapter contract. Zero new Python dependencies, zero hermes-core changes.
  2. app/androidApp — native Kotlin + Jetpack Compose client.
  3. app/desktopApp — Kotlin + Compose Multiplatform client that shares the Iris app's code and is "tweaked" for a big screen.

The Iris Android and Desktop clients live in one Compose Multiplatform Gradle project (app/) with a shared KMP module (app/shared).


Status

  • Phase: M0–M6 complete; M7 (polish + E2E + docs) in progress.
  • Owner decisions locked: see 16-open-questions.md.
  • Last updated: 2026-08-19.