Skip to content

feat(ci): promote Hermes managed image pointers alongside OpenClaw - #11310

Closed
ericksoa wants to merge 2 commits into
mainfrom
replay/11298-publish-hermes-managed-image
Closed

ericksoa wants to merge 2 commits into
mainfrom
replay/11298-publish-hermes-managed-image

Conversation

@ericksoa

@ericksoa ericksoa commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Outcome

NemoClaw publishes Hermes revision and release aliases from the same validated managed-image cohort as OpenClaw. Downstream Hermes images can resolve a release alias and pin its digest without rebuilding the NemoClaw Hermes Dockerfile.

Reason

The workflow already builds, validates, attests, and publishes the complete Hermes image under cohort tags. The missing consumer aliases make that supported image difficult to discover and use from downstream custom images.

Related issues

Resolves #11228.

Replays #11298 on a same-repository branch so trusted CI can qualify the contribution. The commit retains Zac Wang as its author.

Changes

  • Record revision and release aliases in the exact OpenClaw and Hermes platform contracts.
  • Validate both shipped-agent contracts and exact cohort bytes before any pointer write.
  • Publish and verify OpenClaw and Hermes aliases while keeping Deep Agents Code cohort-only.
  • Document the complete digest-pinned Hermes image as the custom Dockerfile base.
  • Extend the existing workflow tests for Hermes publication and fail-closed validation.

Verification

  • npx vitest run test/inference/managed/managed-image-publication-promotion.test.ts test/inference/managed/managed-image-publication-workflow.test.ts — 39 tests passed.
  • npm run docs — passed with zero errors.
  • NODE_OPTIONS=--max-old-space-size=8192 npm run validate:pr — passed after installing and building both current-main package workspaces required by the fresh checkout.
  • Diff inspection confirmed that no secrets, API keys, or credentials are present.

Review notes

The accepted product decision is recorded on #11228. NemoClaw managed-image and release maintainers own the release aliases and first-release validation.

This PR changes .github/workflows/managed-images.yaml. The completed nine-category security review found no credential, authorization, dependency, cryptography, sandbox, or policy regression. Both agents are validated before publication. GHCR cannot update two image repositories atomically, so a registry failure can leave an earlier alias moved; rerunning the same release job reconciles every alias to the same immutable cohort.

Live pointer promotion runs only from trusted main or release-tag workflows. The first shipping release must inspect the published Hermes manifest and run managed-image activation against the published release alias.


Signed-off-by: Aaron Erickson aerickson@nvidia.com

Summary by CodeRabbit

  • New Features

    • Hermes is now included as a shipped managed agent, with commit and release aliases tied to validated cohort manifests.
    • Promotion verifies agent contracts and exact image contents before updating aliases.
  • Documentation

    • Updated Hermes sandbox guidance to use the complete, digest-pinned published image and clarify required managed layers.
  • Tests

    • Expanded publication and promotion coverage for Hermes alongside OpenClaw.

The managed-images promote lane already builds, validates, attests, and
stages ghcr.io/nvidia/nemoclaw/hermes-sandbox in the same six-candidate
cohort barrier as openclaw-sandbox, and the durable cohort contract
already records all three agents. Only the consumer pointers were
OpenClaw-only, so Hermes never received a :<revision> or :<release> tag
and downstream Hermes images had to rebuild agents/hermes/Dockerfile
from a version-matched checkout (#11228).

Generalize both pointer sites to a shipped_agents list of openclaw and
hermes: the staging step records each shipped agent's consumer aliases
in its exact per-platform contract, and the pointer step validates every
shipped agent's contract and exact cohort bytes before moving any
pointer, then creates and byte-verifies each agent's aliases. Deep
Agents Code intentionally stays cohort-only.

The publication tests execute the actual workflow bash and now prove the
Hermes pointer moves only after all cohort aliases stage, that a barrier
failure moves no pointer for either agent, and that Deep Agents Code
receives no consumer pointer. The Hermes plugin guide documents starting
custom images FROM the published complete image instead of reproducing
the managed Dockerfile.

Signed-off-by: Zac Wang <zacw@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 49039ef0-bbf5-4798-831f-43fb6958f88d

📥 Commits

Reviewing files that changed from the base of the PR and between 7e4bdf2 and 7687fbb.

📒 Files selected for processing (4)
  • .github/workflows/managed-images.yaml
  • docs/manage-sandboxes/install-plugins-hermes.mdx
  • test/inference/managed/managed-image-publication-promotion.test.ts
  • test/inference/managed/managed-image-publication-workflow.test.ts

Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Walkthrough

The managed-image workflow now promotes OpenClaw and Hermes commit and release aliases from exact cohort manifests. Deep Agents Code remains cohort-only. Tests cover both shipped agents, and Hermes documentation uses the complete published image with a digest pin.

Changes

Managed image promotion

Layer / File(s) Summary
Shipped-agent alias contract
.github/workflows/managed-images.yaml, test/inference/managed/managed-image-publication-workflow.test.ts
The workflow and publication tests define OpenClaw and Hermes as shipped agents. Deep Agents Code remains excluded from root aliases.
Validated pointer promotion
.github/workflows/managed-images.yaml, test/inference/managed/managed-image-publication-promotion.test.ts
Promotion validates each shipped agent’s cohort contract, registry reference, digest, and manifest size. Tests verify Hermes pointer staging, promotion, and stale-pointer handling.
Hermes image extension guidance
docs/manage-sandboxes/install-plugins-hermes.mdx
The documentation directs custom Dockerfiles to extend the complete digest-pinned hermes-sandbox image instead of hermes-sandbox-base. Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Workflow as managed-images workflow
  participant Manifest as cohort manifest
  participant Registry as image registry
  Workflow->>Manifest: validate OpenClaw and Hermes references
  Workflow->>Registry: promote commit and release aliases
  Workflow->>Registry: verify exact alias bytes
Loading

Suggested reviewers: prekshivyas, cv, apurvvkumaria

Priority: ➖ Normal

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to ed95c

The Hermes alias promotion, validation barriers, tests, and documentation are aligned with the managed-image publication contract.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the primary change: promoting Hermes managed image pointers alongside OpenClaw.
Linked Issues check ✅ Passed The changes satisfy issue #11228 by publishing Hermes revision and release aliases from the validated managed-image cohort, adding exact-byte and contract validation, extending workflow tests, and doc…
Out of Scope Changes check ✅ Passed The workflow, test, and documentation changes are directly related to Hermes managed-image publication. No unrelated code or runtime changes are present.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch replay/11298-publish-hermes-managed-image

Comment @coderabbitai help to get the list of available commands.

@ericksoa
ericksoa marked this pull request as ready for review September 9, 2026 16:58
@github-code-quality

github-code-quality Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit ed95cf4 in the replay/11298-publish... branch remains at 96%, unchanged from commit 00c8506 in the main branch.


Updated September 09, 2026 18:49 UTC

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

@wscurran wscurran added area: ci CI workflows, checks, release automation, or GitHub Actions area: packaging Packages, images, registries, installers, or distribution feature PR adds or expands user-visible functionality integration: dcode LangChain Deep Code integration behavior integration: hermes Hermes integration behavior labels Sep 9, 2026
@ericksoa

ericksoa commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

Closing the same-repository qualification replay because the original contributor PR #11298 was approved and merged as f8f9a1b240cdd4e830869277b2361c633864833d.

@ericksoa ericksoa closed this Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci CI workflows, checks, release automation, or GitHub Actions area: packaging Packages, images, registries, installers, or distribution feature PR adds or expands user-visible functionality integration: dcode LangChain Deep Code integration behavior integration: hermes Hermes integration behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish release tags for the Hermes managed image (ghcr.io/nvidia/nemoclaw/hermes-sandbox) like openclaw-sandbox

3 participants