Switch default stack to native DeepSeek (deepseek-v4-flash)

Use DEEPSEEK_API_KEY + provider deepseek instead of OpenRouter for
client onboarding skill, helper script, docs, and troubleshooting.
This commit is contained in:
domfelipe 2026-08-02 23:57:16 -03:00
parent ee5e29e1fd
commit 89b036652c
4 changed files with 57 additions and 49 deletions

View file

@ -2,7 +2,7 @@
One-liner + skill conversacional para deixar o **Hermes Agent** pronto no cliente em minutos: One-liner + skill conversacional para deixar o **Hermes Agent** pronto no cliente em minutos:
- OpenRouter + `deepseek/deepseek-v4-flash` - DeepSeek nativo + `deepseek-v4-flash` (V4 Flash 0731)
- Telegram (gateway como serviço) - Telegram (gateway como serviço)
- Personalidade em `SOUL.md` - Personalidade em `SOUL.md`
- Setup guiado por LLM (Codex ou Hermes) - Setup guiado por LLM (Codex ou Hermes)
@ -96,7 +96,9 @@ Só se embutir a skill no script. Prefira GitHub raw.
| Item | Valor | | Item | Valor |
|------|--------| |------|--------|
| Modelo | `deepseek/deepseek-v4-flash` via OpenRouter | | Provider | `deepseek` (API nativa) |
| Modelo | `deepseek-v4-flash` (V4 Flash 0731) |
| Secret | `DEEPSEEK_API_KEY` |
| Canal | Telegram | | Canal | Telegram |
| Gateway | `hermes gateway install` (systemd/launchd) | | Gateway | `hermes gateway install` (systemd/launchd) |
| Soul | `~/.hermes/SOUL.md` | | Soul | `~/.hermes/SOUL.md` |
@ -128,11 +130,19 @@ hermes gateway status
```bash ```bash
~/.hermes/skills/hermes-client-onboarding/scripts/apply-core-config.sh \ ~/.hermes/skills/hermes-client-onboarding/scripts/apply-core-config.sh \
--openrouter-key "$OPENROUTER_API_KEY" \ --deepseek-key "$DEEPSEEK_API_KEY" \
--telegram-token "$TELEGRAM_BOT_TOKEN" \ --telegram-token "$TELEGRAM_BOT_TOKEN" \
--allowed-users "123456789" --allowed-users "123456789"
``` ```
Equivalente manual:
```bash
hermes config set DEEPSEEK_API_KEY "sk-..."
hermes config set model.provider deepseek
hermes config set model.default deepseek-v4-flash
```
Não imprime secrets. Não imprime secrets.
## Licença ## Licença

View file

@ -1,13 +1,13 @@
--- ---
name: hermes-client-onboarding name: hermes-client-onboarding
description: Use when setting up Hermes for a client, install Hermes + Telegram + OpenRouter, run a demo setup, or launch client onboarding. Conducts guided conversational onboarding on a clean Linux VM (deepseek/deepseek-v4-flash, Telegram gateway, systemd, SOUL.md). description: Use when setting up Hermes for a client, install Hermes + Telegram + DeepSeek, run a demo setup, or launch client onboarding. Conducts guided conversational onboarding on a clean Linux VM (deepseek-v4-flash, Telegram gateway, systemd, SOUL.md).
version: 1.0.0 version: 1.1.0
author: DomHubs author: DomHubs
license: MIT license: MIT
platforms: [linux, macos] platforms: [linux, macos]
metadata: metadata:
hermes: hermes:
tags: [onboarding, client, telegram, openrouter, deepseek, gateway, demo] tags: [onboarding, client, telegram, deepseek, gateway, demo]
related_skills: [] related_skills: []
--- ---
@ -15,14 +15,14 @@ metadata:
## Overview ## Overview
You are conducting a professional, step-by-step onboarding of Hermes Agent on a clean Ubuntu/Debian VM so a client can start using it immediately (primarily via Telegram). The goal is a working agent in minutes, with OpenRouter + DeepSeek V4 Flash as the default model, Telegram as the primary channel, and the gateway running as a persistent service. You are conducting a professional, step-by-step onboarding of Hermes Agent on a clean Ubuntu/Debian VM so a client can start using it immediately (primarily via Telegram). The goal is a working agent in minutes, with **native DeepSeek** (`DEEPSEEK_API_KEY`, provider `deepseek`) and model **`deepseek-v4-flash`** (V4 Flash 0731 family) as the default, Telegram as the primary channel, and the gateway running as a persistent service.
This skill is designed for live demos in front of the client and for commercial handoff. Be clear, structured, and efficient. Always confirm critical values before applying them. This skill is designed for live demos in front of the client and for commercial handoff. Be clear, structured, and efficient. Always confirm critical values before applying them.
## When to Use ## When to Use
- User asks to set up Hermes for a client - User asks to set up Hermes for a client
- Demo setup of Hermes + Telegram + OpenRouter - Demo setup of Hermes + Telegram + DeepSeek
- Launch of the DomHubs client onboarding flow - Launch of the DomHubs client onboarding flow
- Fresh VM that needs Hermes ready end-to-end - Fresh VM that needs Hermes ready end-to-end
@ -33,8 +33,8 @@ Don't use for: day-to-day Hermes coding tasks after onboarding is done; multi-te
The onboarding is complete only when all of the following are true: The onboarding is complete only when all of the following are true:
- Hermes is installed and `hermes` command works - Hermes is installed and `hermes` command works
- Model is set to `deepseek/deepseek-v4-flash` via OpenRouter - Model is set to `deepseek-v4-flash` with provider `deepseek`
- `OPENROUTER_API_KEY` is configured - `DEEPSEEK_API_KEY` is configured
- Telegram bot token and at least one allowed user ID are set - Telegram bot token and at least one allowed user ID are set
- Gateway is installed as a systemd service and is running - Gateway is installed as a systemd service and is running
- A test message sent to the Telegram bot receives a coherent reply - A test message sent to the Telegram bot receives a coherent reply
@ -48,14 +48,14 @@ Run these checks silently or with minimal output before starting the dialogue:
1. Confirm you are on Linux (preferably Ubuntu 22.04/24.04 or Debian). On macOS, warn that gateway persistence differs (launchd) and demos still work. 1. Confirm you are on Linux (preferably Ubuntu 22.04/24.04 or Debian). On macOS, warn that gateway persistence differs (launchd) and demos still work.
2. Check if `hermes` is already in PATH. If yes, note the version with `hermes --version`. 2. Check if `hermes` is already in PATH. If yes, note the version with `hermes --version`.
3. Check available disk space and RAM (`df -h /` and `free -h`). Warn if RAM < 2 GB or free disk < 5 GB. 3. Check available disk space and RAM (`df -h /` and `free -h`). Warn if RAM < 2 GB or free disk < 5 GB.
4. Verify internet connectivity (can reach `https://hermes-agent.nousresearch.com` and `https://openrouter.ai`). 4. Verify internet connectivity (can reach `https://hermes-agent.nousresearch.com` and `https://api.deepseek.com`).
If Hermes is missing, install it with: If Hermes is missing, install it with:
```bash ```bash
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser
source ~/.bashrc 2>/dev/null || true source ~/.bashrc 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH" export PATH="$HOME/.local/bin:/usr/local/bin:$PATH"
``` ```
After install, confirm with `hermes --version` and `hermes doctor`. After install, confirm with `hermes --version` and `hermes doctor`.
@ -77,16 +77,16 @@ Ask:
**Done when:** demo vs handoff, company name, language, and channel intent confirmed. **Done when:** demo vs handoff, company name, language, and channel intent confirmed.
### Phase 2 — OpenRouter Credentials ### Phase 2 — DeepSeek Credentials
1. Ask for the OpenRouter API key (format usually starts with `sk-or-v1-`). 1. Ask for the DeepSeek API key from https://platform.deepseek.com/ (usually starts with `sk-`).
2. Confirm the key is present and looks valid (do not echo the full key back). 2. Confirm the key is present and looks valid (do not echo the full key back).
3. Apply it (prefer `scripts/apply-core-config.sh` when you already have Telegram values too; otherwise set now): 3. Apply it (prefer `scripts/apply-core-config.sh` when you already have Telegram values too; otherwise set now):
```bash ```bash
hermes config set OPENROUTER_API_KEY "THE_KEY" hermes config set DEEPSEEK_API_KEY "THE_KEY"
hermes config set model.provider openrouter hermes config set model.provider deepseek
hermes config set model.default deepseek/deepseek-v4-flash hermes config set model.default deepseek-v4-flash
``` ```
4. Verify with: 4. Verify with:
@ -96,9 +96,9 @@ hermes config get model.default
hermes config get model.provider hermes config get model.provider
``` ```
Optional: Offer to set a fallback model (e.g. another cheap OpenRouter model) if the user wants resilience. Optional: Offer fallback model `deepseek-v4-pro` if the user wants a stronger model (higher cost).
**Done when:** provider=openrouter, model=deepseek/deepseek-v4-flash, key set without printing it. **Done when:** provider=deepseek, model=deepseek-v4-flash, key set without printing it.
### Phase 3 — Telegram Bot ### Phase 3 — Telegram Bot
@ -175,7 +175,7 @@ Then instruct the user to send a test message to the Telegram bot (“oi” ou
Final checklist to present to the user: Final checklist to present to the user:
- [ ] Hermes installed and in PATH - [ ] Hermes installed and in PATH
- [ ] Model = deepseek/deepseek-v4-flash via OpenRouter - [ ] Model = deepseek-v4-flash via provider deepseek (native API)
- [ ] Telegram bot responding - [ ] Telegram bot responding
- [ ] Gateway running as service (survives reboot) - [ ] Gateway running as service (survives reboot)
- [ ] SOUL.md personalized - [ ] SOUL.md personalized
@ -197,7 +197,7 @@ hermes update
- If `hermes config set` fails, check file permissions on `~/.hermes/.env` and `~/.hermes/config.yaml`. - If `hermes config set` fails, check file permissions on `~/.hermes/.env` and `~/.hermes/config.yaml`.
- If Telegram does not respond: verify token with a direct `getMe` call, confirm Allowed Users, restart gateway, check logs for connection errors. - If Telegram does not respond: verify token with a direct `getMe` call, confirm Allowed Users, restart gateway, check logs for connection errors.
- If OpenRouter returns auth errors: re-validate the key and model name (`deepseek/deepseek-v4-flash`). - If DeepSeek returns auth errors: re-validate `DEEPSEEK_API_KEY` and model name (`deepseek-v4-flash`). See `references/troubleshooting.md`.
- Prefer fixing issues yourself when possible, then explain what was wrong in plain language. - Prefer fixing issues yourself when possible, then explain what was wrong in plain language.
- Never leave the system in a half-configured state. Either finish a phase or clearly roll back. - Never leave the system in a half-configured state. Either finish a phase or clearly roll back.
@ -212,7 +212,7 @@ hermes update
## Optional Extensions (only if requested) ## Optional Extensions (only if requested)
- Add Discord or WhatsApp after Telegram is working. - Add Discord or WhatsApp after Telegram is working.
- Switch to native DeepSeek provider later (`DEEPSEEK_API_KEY` + provider `deepseek`). - Switch to OpenRouter later (`OPENROUTER_API_KEY` + provider `openrouter` + OpenRouter model slug).
- Enable extra tools or change terminal backend. - Enable extra tools or change terminal backend.
- Create additional allowlisted users. - Create additional allowlisted users.
- Set up a simple cron job or home channel for proactive messages. - Set up a simple cron job or home channel for proactive messages.
@ -220,7 +220,7 @@ hermes update
## Supporting Resources ## Supporting Resources
- `references/troubleshooting.md` — detailed fixes for the most common failures (Telegram not replying, auth errors, service problems, PATH issues). - `references/troubleshooting.md` — detailed fixes for the most common failures (Telegram not replying, auth errors, service problems, PATH issues).
- `scripts/apply-core-config.sh` — safe helper to apply OpenRouter key + model + Telegram token + allowed users in one go. Prefer using it when you already have all three values confirmed. - `scripts/apply-core-config.sh` — safe helper to apply DeepSeek key + model + Telegram token + allowed users in one go. Prefer using it when you already have all three values confirmed.
## Reference Commands (quick lookup) ## Reference Commands (quick lookup)
@ -229,9 +229,9 @@ hermes update
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser
# Core config (or use the helper script) # Core config (or use the helper script)
hermes config set OPENROUTER_API_KEY "sk-or-..." hermes config set DEEPSEEK_API_KEY "sk-..."
hermes config set model.provider openrouter hermes config set model.provider deepseek
hermes config set model.default deepseek/deepseek-v4-flash hermes config set model.default deepseek-v4-flash
hermes config set TELEGRAM_BOT_TOKEN "..." hermes config set TELEGRAM_BOT_TOKEN "..."
hermes config set TELEGRAM_ALLOWED_USERS "123456789" hermes config set TELEGRAM_ALLOWED_USERS "123456789"

View file

@ -3,9 +3,9 @@
## PATH / `hermes: command not found` ## PATH / `hermes: command not found`
```bash ```bash
export PATH="$HOME/.local/bin:$PATH" export PATH="$HOME/.local/bin:/usr/local/bin:$PATH"
# persist # persist
grep -q '.local/bin' ~/.bashrc 2>/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc grep -q '.local/bin' ~/.bashrc 2>/dev/null || echo 'export PATH="$HOME/.local/bin:/usr/local/bin:$PATH"' >> ~/.bashrc
hash -r hash -r
hermes --version hermes --version
``` ```
@ -16,15 +16,15 @@ Re-run install if still missing:
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser
``` ```
## OpenRouter auth errors ## DeepSeek auth errors
1. Confirm key format (`sk-or-v1-...`) without pasting full key into chat. 1. Confirm key is from https://platform.deepseek.com/ (do not paste full key into chat).
2. Re-set: 2. Re-set:
```bash ```bash
hermes config set OPENROUTER_API_KEY "THE_KEY" hermes config set DEEPSEEK_API_KEY "THE_KEY"
hermes config set model.provider openrouter hermes config set model.provider deepseek
hermes config set model.default deepseek/deepseek-v4-flash hermes config set model.default deepseek-v4-flash
``` ```
3. Check: 3. Check:
@ -35,7 +35,9 @@ hermes config get model.provider
# key lives in ~/.hermes/.env — never cat full file in front of client # key lives in ~/.hermes/.env — never cat full file in front of client
``` ```
4. Test connectivity: `curl -sI https://openrouter.ai | head -1` 4. Test connectivity: `curl -sI https://api.deepseek.com | head -1`
5. If the model name is rejected, stick to Hermes-supported IDs: `deepseek-v4-flash` or `deepseek-v4-pro` (legacy `deepseek-chat` / `deepseek-reasoner` were retired).
## Telegram bot does not reply ## Telegram bot does not reply

View file

@ -1,5 +1,5 @@
#!/usr/bin/env bash #!/usr/bin/env bash
# Apply OpenRouter + model + Telegram core config for Hermes client onboarding. # Apply DeepSeek native + model + Telegram core config for Hermes client onboarding.
# Does not print secrets. Requires: hermes on PATH. # Does not print secrets. Requires: hermes on PATH.
set -euo pipefail set -euo pipefail
@ -7,26 +7,26 @@ usage() {
cat <<'EOF' cat <<'EOF'
Usage: Usage:
apply-core-config.sh \ apply-core-config.sh \
--openrouter-key KEY \ --deepseek-key KEY \
--telegram-token TOKEN \ --telegram-token TOKEN \
--allowed-users ID1,ID2 \ --allowed-users ID1,ID2 \
[--model deepseek/deepseek-v4-flash] \ [--model deepseek-v4-flash] \
[--provider openrouter] [--provider deepseek]
Env fallbacks (if flags omitted): Env fallbacks (if flags omitted):
OPENROUTER_API_KEY, TELEGRAM_BOT_TOKEN, TELEGRAM_ALLOWED_USERS DEEPSEEK_API_KEY, TELEGRAM_BOT_TOKEN, TELEGRAM_ALLOWED_USERS
EOF EOF
} }
MODEL="deepseek/deepseek-v4-flash" MODEL="deepseek-v4-flash"
PROVIDER="openrouter" PROVIDER="deepseek"
OR_KEY="${OPENROUTER_API_KEY:-}" DS_KEY="${DEEPSEEK_API_KEY:-}"
TG_TOKEN="${TELEGRAM_BOT_TOKEN:-}" TG_TOKEN="${TELEGRAM_BOT_TOKEN:-}"
TG_USERS="${TELEGRAM_ALLOWED_USERS:-}" TG_USERS="${TELEGRAM_ALLOWED_USERS:-}"
while [[ $# -gt 0 ]]; do while [[ $# -gt 0 ]]; do
case "$1" in case "$1" in
--openrouter-key) OR_KEY="${2:-}"; shift 2 ;; --deepseek-key|--openrouter-key) DS_KEY="${2:-}"; shift 2 ;; # --openrouter-key kept as alias
--telegram-token) TG_TOKEN="${2:-}"; shift 2 ;; --telegram-token) TG_TOKEN="${2:-}"; shift 2 ;;
--allowed-users) TG_USERS="${2:-}"; shift 2 ;; --allowed-users) TG_USERS="${2:-}"; shift 2 ;;
--model) MODEL="${2:-}"; shift 2 ;; --model) MODEL="${2:-}"; shift 2 ;;
@ -42,21 +42,17 @@ if ! command -v hermes >/dev/null 2>&1; then
fi fi
missing=0 missing=0
[[ -z "$OR_KEY" ]] && { echo "error: missing OpenRouter key" >&2; missing=1; } [[ -z "$DS_KEY" ]] && { echo "error: missing DeepSeek API key" >&2; missing=1; }
[[ -z "$TG_TOKEN" ]] && { echo "error: missing Telegram bot token" >&2; missing=1; } [[ -z "$TG_TOKEN" ]] && { echo "error: missing Telegram bot token" >&2; missing=1; }
[[ -z "$TG_USERS" ]] && { echo "error: missing TELEGRAM_ALLOWED_USERS" >&2; missing=1; } [[ -z "$TG_USERS" ]] && { echo "error: missing TELEGRAM_ALLOWED_USERS" >&2; missing=1; }
[[ "$missing" -eq 1 ]] && exit 1 [[ "$missing" -eq 1 ]] && exit 1
# light validation (no secret echo)
if [[ ! "$OR_KEY" =~ ^sk-or- ]]; then
echo "warn: OpenRouter key does not start with sk-or- (continuing)" >&2
fi
if [[ ! "$TG_USERS" =~ ^[0-9]+(,[0-9]+)*$ ]]; then if [[ ! "$TG_USERS" =~ ^[0-9]+(,[0-9]+)*$ ]]; then
echo "error: allowed users must be numeric IDs, comma-separated" >&2 echo "error: allowed users must be numeric IDs, comma-separated" >&2
exit 1 exit 1
fi fi
hermes config set OPENROUTER_API_KEY "$OR_KEY" hermes config set DEEPSEEK_API_KEY "$DS_KEY"
hermes config set model.provider "$PROVIDER" hermes config set model.provider "$PROVIDER"
hermes config set model.default "$MODEL" hermes config set model.default "$MODEL"
hermes config set TELEGRAM_BOT_TOKEN "$TG_TOKEN" hermes config set TELEGRAM_BOT_TOKEN "$TG_TOKEN"