Show HN: Hermzner – Provisioning an Hardened Hermes Agent on Hetzner VPS A developer released Hermzner, an open-source tool that provisions a hardened Hermes AI agent on a Hetzner VPS using rootless Podman and Tailscale. The setup includes Terraform and Ansible scripts for deployment, with security features like image digest pinning and firewall rules. It aims to provide a secure, disposable test environment for the Hermes agent before production use. Provision a hardened Hermes Agent on Hetzner with rootless Podman and Tailscale. Terraform https://developer.hashicorp.com/terraform/install = 1.5 Ansible https://docs.ansible.com/ansible/latest/installation guide/ = 2.15 Hetzner Cloud API token https://docs.hetzner.com/cloud/api/getting-started/generating-api-token Tailscale pre-auth key https://tailscale.com/kb/1085/auth-keys reusable or ephemeral 1. Copy and edit Terraform variables cp terraform/terraform.tfvars.example terraform/terraform.tfvars vim terraform/terraform.tfvars 2. Copy and override Ansible defaults vim ansible/inventory/group vars/all.yml Required: set hermes image ref to a pinned digest Resolve the latest digest: curl -s "https://hub.docker.com/v2/repositories/nousresearch/hermes-agent/tags/main" | jq -r '.images | select .architecture == "amd64" and .os == "linux" | .digest' Then set: hermes image ref: 'docker.io/nousresearch/hermes-agent@sha256: