Guide
Hermes Agent on Synology NAS
A Synology NAS is already on 24/7, which makes it a natural home for a personal AI agent. Here is how to run Hermes Agent (by Nous Research) on one with Container Manager and a docker-compose project — the image, the volume, the ports, the permission traps — plus OpenClaw on the same box and an honest look at when managed hosting is the better call.
Can you run Hermes Agent on a Synology NAS?
Yes. Hermes Agent ships an official Docker image, nousresearch/hermes-agent, published for both amd64 and arm64. Synology's Container Manager (the package was called “Docker” before DSM 7.2) can run it, and its Project dashboard creates and manages multi-container projects from Compose files. Hermes does not run a model locally — it calls a hosted model API — so you do not need a GPU or a powerful CPU. You need a 64-bit model, a model provider API key, and a little RAM.
Which Synology models will work?
- Architecture. The image is amd64 and arm64 only. Intel/AMD models and 64-bit ARM models can pull it; look up your model's CPU in its spec sheet on synology.com before you start. If Container Manager is not offered in Package Center for your model, this guide does not apply to it.
- RAM. Upstream's Docker guide lists 1 GB as the minimum and 2–4 GB as recommended, and says the browser tools need at least 2 GB. That is for the container alone — DSM and your other packages come on top. A 2 GB NAS can host chat-only use; if you want the browser toolset, add RAM or pick a larger model. See Hermes Agent system requirements for measured figures.
- Disk. Upstream lists 500 MB minimum and 2 GB+ recommended. State (config, sessions, memories, skills, logs) all lives in one folder, so any volume works.
Step by step: Hermes in Container Manager
1. Create the data folder
In File Station, create a shared folder or subfolder such as /volume1/docker/hermes. Everything Hermes keeps — .env, config.yaml, SOUL.md, sessions, memories, skills, logs — will live here, mounted into the container at /opt/data. Keep it on a local volume.
2. Find your user ID
Hermes runs as a non-root hermes user (UID 10000 by default) and remaps it to HERMES_UID / HERMES_GID if you set them. Enable SSH in Control Panel, log in, and run id as the account that owns the folder. Use those two numbers in the compose file below — the values shown are placeholders.
3. Run the first-time setup wizard
Over SSH, run the interactive wizard once. It asks for your model provider key and writes it to .env in the data folder:
sudo docker run -it --rm \
-e HERMES_UID=1026 -e HERMES_GID=100 \
-v /volume1/docker/hermes:/opt/data \
nousresearch/hermes-agent:v2026.9.24 setupUpstream recommends connecting a chat platform during this step so the gateway has something to talk to. You can also change the model later with docker exec hermes hermes model.
4. Create the Project
In Container Manager open Project and click Create. Give it a name, set the path to a working folder (for example /volume1/docker/hermes-project), and choose to create a docker-compose.yml with the editor. Paste this, adjusting the IDs and password:
services:
hermes:
image: nousresearch/hermes-agent:v2026.9.24
container_name: hermes
restart: unless-stopped
command: gateway run
shm_size: "1gb"
ports:
- "127.0.0.1:9119:9119"
volumes:
- /volume1/docker/hermes:/opt/data
environment:
- HERMES_UID=1026 # numeric UID that owns /volume1/docker/hermes
- HERMES_GID=100 # numeric GID of the same account
- HERMES_DASHBOARD=1
- HERMES_DASHBOARD_BASIC_AUTH_USERNAME=admin
- HERMES_DASHBOARD_BASIC_AUTH_PASSWORD=change-me-long-and-random
- HERMES_DASHBOARD_BASIC_AUTH_SECRET=paste-output-of-openssl-rand-base64-32
# - TELEGRAM_BOT_TOKEN=123456:ABC...
deploy:
resources:
limits:
memory: 4GWhat each part does:
command: gateway runstarts the persistent gateway that serves Telegram, Discord, Slack and the other chat platforms. Inside the official image it is supervised by s6-overlay, so a crashed gateway restarts within seconds without losing the container.- The only published port is the dashboard, 9119, bound to
127.0.0.1on the NAS. Telegram and the other chat platforms need no inbound port. The OpenAI-compatible API server on 8642 is off by default; if you want it for a client such as Open WebUI, addAPI_SERVER_ENABLED=true,API_SERVER_HOST=0.0.0.0and anAPI_SERVER_KEY(generate one withopenssl rand -hex 32), then publish127.0.0.1:8642:8642. - The dashboard username, password and secret are required, not optional: the dashboard binds to
0.0.0.0inside the container, and upstream refuses to start it on a non-loopback bind without an auth provider. Generate the secret withopenssl rand -base64 32. shm_sizeis upstream's recommendation (--shm-size=1g) for browser tools.- To pair Telegram, uncomment
TELEGRAM_BOT_TOKENwith the token from BotFather. Our Telegram guide covers pairing in detail.
Confirm the summary and finish; Container Manager pulls the image and starts the project. Check the project's log tab for the gateway coming up. After any config change, restart the gateway with docker exec hermes hermes gateway restart.
One rule from upstream worth repeating: never run two Hermes gateway containers against the same data folder. Want the Compose details beyond Synology? See the Hermes docker-compose guide and the general Hermes Docker guide.
Keeping it running and up to date
- Always on.
restart: unless-stoppedbrings the container back after a DSM reboot or Container Manager update, as long as the project was not stopped by hand. - Updating. Pull the new image and recreate the container — either rebuild the Project from Container Manager, or in the project folder over SSH run
docker compose pullthendocker compose up -d. State is in/opt/data, so it survives. The compose file pins a release tag (v2026.9.24, the current release when this guide was written) so an update only happens when you change it; check the image tags for newer releases and avoidmain, which is the development build. - Backups. Add
/volume1/docker/hermesto Hyper Backup or your usual job. It holds your API keys, so treat the backup as sensitive.
Reaching it remotely without exposing it
Do not forward 9119 (or 8642, if you enabled the API) on your router. In June 2026 internet scanners reached exposed Hermes dashboards and API servers and used them to plant an SSH-key backdoor; upstream now fails closed on unauthenticated public binds. Safer options:
- Telegram and other chat platforms need no inbound ports. The gateway connects out, so for everyday use you do not need remote access to the NAS at all.
- Tailscale or a VPN to reach the NAS privately, then the SSH tunnel below over that private network. The dashboard port is bound to loopback, so a VPN on its own does not expose it — which is the point. See our Hermes with Tailscale guide.
- An SSH tunnel (upstream's own suggestion):
ssh -L 9119:localhost:9119 you@nas, then openhttp://localhost:9119.
Common problems on Synology
- Permission denied on /opt/data. The folder owner does not match
HERMES_UID/HERMES_GID. Fix the IDs (or the folder owner) and recreate the container. - “no matching manifest” or exec format error. Your CPU is not amd64 or arm64 (for example a 32-bit ARM model). The image is not published for it; use managed hosting or a different machine.
- Dashboard container exits at start. You enabled
HERMES_DASHBOARD=1without the basic-auth username, password and secret. - Slow, swapping or killed on a 2 GB model. Stop using the browser tools, remove other packages, or add RAM. The memory limit in the compose file only caps the container — it does not create memory.
- Can't reach the dashboard from another machine. That is deliberate; the compose file binds it to loopback. Use the SSH tunnel (over a VPN if you are away from home) rather than opening the DSM firewall or a public reverse proxy.
- Config edits ignored. Restart the gateway with
docker exec hermes hermes gateway restart.
Running OpenClaw on Synology instead
The same approach works for OpenClaw. Upstream publishes ghcr.io/openclaw/openclaw (pinned below to the current release, 2026.9.8, with a Docker Hub mirror at openclaw/openclaw) for linux/amd64 and linux/arm64. The control UI and gateway listen on port 18789, state lives in /home/node/.openclaw, and the container runs as UID 1000, so the mounted folder must be writable by that user — set the folder owner to 1000 or adjust its permissions in DSM. A minimal Project:
services:
openclaw:
image: ghcr.io/openclaw/openclaw:2026.9.8
container_name: openclaw
restart: unless-stopped
init: true
environment:
- OPENCLAW_GATEWAY_TOKEN=change-me-long-and-random
volumes:
- /volume1/docker/openclaw:/home/node/.openclaw
ports:
- "127.0.0.1:18789:18789"
command: ["node", "dist/index.js", "gateway", "--bind", "lan", "--port", "18789"]OPENCLAW_GATEWAY_TOKEN is the gateway authentication token, and /healthz is the liveness endpoint. Onboarding and channel login use OpenClaw's own CLI container — follow upstream's Docker install docs for that step. For the full walkthrough see our OpenClaw Docker guide, and if you use Synology Chat as a channel, the OpenClaw Synology Chat guide.
NAS vs managed hosting
A NAS you already own costs nothing extra, and your data stays at home. The trade is that you are the sysadmin: updates, backups, remote access, power cuts and the occasional broken pull are yours.
| Synology NAS | OpenClaw Launch | |
|---|---|---|
| Cost | Hardware you own + electricity | Free 30-minute trial (no card); Lite $3 first month, then $6/mo; Pro $20/mo |
| Setup | SSH, folder permissions, compose file | Live in under a minute |
| Updates | You pull and recreate | Handled for you |
| Remote access | You build and secure it (VPN, tunnel, proxy) | Nothing to build or secure yourself |
| Frameworks | One compose file per framework | Hermes Agent or OpenClaw |
| Model usage | Your own API key, billed by the provider | Lite includes $1/mo AI credits, Pro $10/mo |
The managed alternative
OpenClaw Launch runs Hermes Agent or OpenClaw for you, so there is no Container Manager, no UID mapping and no port forwarding to get right. Start with the free 30-minute trial, no credit card required.
- Lite: $3 for the first month, then $6/month (or $60/year). 1 vCPU, 2 GB RAM, 10 GB storage, 1 instance, $1/month AI credits included.
- Pro: $20/month (or $200/year). 2 vCPU, 4 GB RAM, 40 GB storage, up to 3 instances, $10/month AI credits.
Plenty of people do both: the NAS for tinkering, a managed instance for the bot that has to stay up. Compare providers in best Hermes Agent hosting, or see how managed hosting works on the Hermes hosting page.
Frequently Asked Questions
Can I run Hermes Agent on a Synology NAS?
Yes, if your model can run Container Manager and has a 64-bit CPU. The official Hermes Agent Docker image (nousresearch/hermes-agent) is published for amd64 and arm64, so both Intel/AMD and 64-bit ARM Synology models can pull it. You create a Project in Container Manager from a docker-compose.yml, mount a folder at /opt/data, and start the gateway.
Does Hermes Agent need a GPU or a lot of RAM on a NAS?
No GPU. Hermes Agent calls a hosted model API, so the NAS only runs the agent itself. Upstream lists 1 GB of memory as the minimum and 2 to 4 GB as recommended, and says the browser tools need at least 2 GB. A 2 GB NAS can run chat-only use but is tight once the DSM and other packages are counted.
Which ports does Hermes Agent use on Synology?
Chat platforms such as Telegram need no inbound port at all, because the gateway connects out. Port 9119 is the web dashboard, which only runs when HERMES_DASHBOARD=1 is set. Port 8642 is the optional OpenAI-compatible API server, which is off unless you set API_SERVER_ENABLED=true with an API_SERVER_KEY. Do not forward either port on your router.
How do I update Hermes Agent on Synology?
Pull the new image and recreate the container. Your config, memories and sessions live in the folder mounted at /opt/data, so they survive the recreate. Never run two Hermes gateway containers against the same data folder at once.
Why does Hermes fail with permission errors on my Synology volume?
The container runs as a non-root hermes user (UID 10000 by default) and the folder you mounted is owned by a different DSM user. Set HERMES_UID and HERMES_GID in the compose file to the numeric ID and group ID of the account that owns the folder, which you can read with the id command over SSH.
Does this work for OpenClaw too?
Yes. OpenClaw also ships a multi-platform Docker image (ghcr.io/openclaw/openclaw) for linux/amd64 and linux/arm64. It listens on port 18789, keeps its state in /home/node/.openclaw, and runs as UID 1000, so the same Container Manager Project approach works with a different compose file.
Is a NAS or managed hosting better for Hermes Agent?
A NAS is cheap if you already own one and enjoy tinkering, but you handle updates, backups, remote access and uptime. OpenClaw Launch runs Hermes Agent or OpenClaw managed: free 30-minute trial with no credit card, Lite at $3 for the first month then $6/month, and Pro at $20/month.
Related Guides
- Hermes Hosting — how managed Hermes Agent hosting works
- Hermes Agent Docker — the general Docker guide
- Hermes Agent Docker Compose — compose setup with a reverse proxy
- Hermes Agent System Requirements — RAM, CPU and disk
- Best Hermes Agent Hosting Providers — all options compared
- OpenClaw Docker — the OpenClaw equivalent of this guide