← 返回主頁
🌐 繁體中文 English 简体中文 العربية
Nous Research · MIT 開源 · 2026

如何在 Oracle VM 免費部署 Hermes Agent

OCI Free Tier ARM 實戰 · Always Free 2 vCPU / 12GB RAM 永久免費(2026-06-15 起)· PAYG 4 OCPU / 24GB 唔受減半影響(見 §15)· systemd 24/7 運行
零成本嘅雲端 AI Agent,所有踩坑已經替你踩平

⚡ 本指南持續更新(最新實測 2026-09)。所有資源必須維持喺「Always Free」額度內,超出會收費;PAYG 帳戶唔受 2026-06-15 減半影響(見 §15)。
0%
Nous Research · MIT 開源

Oracle 免費 VM 部署
Hermes Agent

Always Free ARM · 零成本 24/7 AI Agent

2vCPU
12GB RAM
200GB 磁碟
0每月($)
24/7運行
📝
註冊 OCI
🖥
建立 ARM VM
️
SSH 初始化
🔑
安裝 Hermes
📦
接模型 API
🧠
systemd 上線
✅
部署完成
24/7 免費運行 · 斷線自動重啟
HERMES AGENT · ORACLE FREE TIER
起步 · 0–4 0 架構 1 註冊帳號 2 建立 VM 3 SSH 初始化 4 安裝 Hermes
部署 · 5–10 5 初始化設定 6 模型 API Key 7 systemd Gateway 8 Telegram Bot 9 中文回覆 10 防火牆
進階與運維 · 11–16 11 命令速查 12 踩坑合集 13 WebUI 14 備份維護 15 免費額度減半 16 免費額度監控 附錄

0 點解要咁部署(架構概覽)

Hermes Agent 係 Nous Research 開發嘅開源 AI Agent 框架(MIT 協議)——喺終端度讀檔案、寫程式碼、執行命令、操控瀏覽器,唔綁定任何模型廠商,仲內建 Telegram Gateway。放喺 Oracle 永久免費 VM 上,就變成 24/7 唔斷線嘅雲端 AI Agent。

Telegram 訊息→ Hermes Gateway→ DeepSeek API→ AI 回覆→ Telegram 聊天

systemd 服務管理:開機自啟、崩潰自動重啟、斷開 SSH 都照常運行。

💰

永久免費

ARM 2 vCPU + 12GB RAM + 200GB 磁碟(Always Free,2026-06-15 起);PAYG 可續用 4 OCPU / 24GB(見 §15)

🔄

模型自由

DeepSeek / OpenAI / Anthropic / Google 任揀,換供應商改 config 就得

💬

Telegram 原生

內建 Gateway,一條 systemd 服務即 24/7 自動回覆

🖥️

零運維焦慮

崩潰自動重啟 + journald 日誌 + 遠端備份,瞓覺都唔使理

1 註冊 Oracle Cloud Free Tier 帳號

前往註冊頁面

https://signup.cloud.oracle.com/

填姓名、電郵、國家/地區。

揀 Home Region 關鍵

務必揀支援 Ampere ARM 實例嘅區域(Home Region 之後唔改得):
Osaka / Tokyo / Paris / Frankfurt / Ashburn / Phoenix 都支援。

Home Region 揀錯咗就冇 ARM 實例 — 呢個決定咗你之後有冇 2 vCPU 免費機用。

信用卡驗證

要提供有效信用卡或扣帳卡。Oracle 會暫時扣約 $1 美元驗證,幾日後退還。唔接受虛擬卡或預付卡。

等啟用

通常幾分鐘至幾小時。收到啟用郵件即可登入 cloud.oracle.com。

⚠️ 免費唔等於無限:資源超出「Always Free」限制會產生費用。建議升級做 Pay-As-You-Go(仍 $0,但容量不足時可以解決,亦係免費 ARM 搶唔到容量嘅解藥)。

2 建立 OCI 運算實例(VM)

開建立頁面

OCI Console → Compute → Instances → Create Instance。區域應顯示「Always Free-eligible」標籤。

揀映像檔

Change image → 揀 Ubuntu 22.04 LTS 或 24.04 LTS。

揀實例規格 ARM Ampere 推薦

方案規格建議
ARM Ampere A1VM.Standard.A1.Flex — 2 OCPU + 12GB RAM(2026-06-15 前係 4/24)✅ 主力(免費額度內最大配置)
x86 MicroVM.Standard.E2.1.Micro — 1/8 OCPU + 1GB❌ 太細,僅適合測試

網絡 + SSH 金鑰

用預設 VCN/子網,勾選「Assign a public IPv4 address」。SSH 揀「Paste public keys」,貼上你嘅公鑰(本地未有就先產生):

ssh-keygen -t rsa -b 4096 -C "your_email@example.com"

加大開機磁碟到 200GB 免費上限

Show advanced options → Boot volume → 自訂大小 → 輸入 200(GB)。預設得 50GB,遲下裝嘢先嚟擴充冇咁方便。

Create 並記低 Public IP

等狀態變「Running」,記低 Public IP(例如 130.123.45.67)。

3 連線 VM 與系統初始化

SSH 連線

ssh -i ~/.ssh/id_rsa ubuntu@<你的Public IP>

Ubuntu 預設用戶係 ubuntu;Oracle Linux 先係 opc。

更新系統

sudo apt update && sudo apt upgrade -y

裝基本工具 + 設時區

sudo apt install -y curl git wget nano vim ufw build-essential sudo timedatectl set-timezone Asia/Hong_Kong

開 UFW 防火牆(第一層)

sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow ssh sudo ufw allow 80/tcp sudo ufw allow 443/tcp sudo ufw enable

⚠️ 記住:Oracle 有兩層防火牆 — VM 入面嘅 UFW/iptables 之外,仲有 OCI VCN 嘅 Security List(第 10 節會講)。兩層都要開先通。

4 安裝 Hermes Agent

一鍵安裝

curl -fsSL https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash

自動完成:安裝 uv → 建 Python 3.11 venv → 裝 100+ 依賴 → 裝 Node.js → 裝 cua-driver。

重新載入 + 驗證

source ~/.bashrc hermes --version

出到版本號(例如 hermes 0.14.0)即成功。安裝路徑喺 ~/.local/bin/hermes,設定喺 ~/.hermes/。

⚠️ ARM 實測坑:HTTP/2 下載失敗。安裝腳本喺 Node.js 下載時可能報 curl: (92) HTTP/2 stream error。解法:Ctrl+C 終止 → 手動用 HTTP/1.1 下載 ARM 版 Node.js:
curl --http1.1 -L "https://nodejs.org/dist/v22.11.0/node-v22.11.0-linux-arm64.tar.gz" -o /tmp/node.tar.gz mkdir -p ~/.hermes/node tar -xzf /tmp/node.tar.gz -C ~/.hermes/node --strip-components=1 rm /tmp/node.tar.gz
再重新執行安裝腳本,會跳過已下載嘅 Node.js。

5 初始化設定(setup 嚮導)

啟動嚮導

hermes setup

選項一覽

  • 設定模式:Quick setup(快速)或 Custom setup(詳細)
  • 終端後端:local backend
  • 訊息平台:揀「Skip — set up later」,Telegram 之後單獨設(第 7-8 節)

完成

設定寫入 ~/.hermes/config.yaml,密鑰寫入 ~/.hermes/.env。

6 設定模型供應商與 API Key

Hermes 支援任意供應商。以下用 DeepSeek 做例(性價比高、無需海外支付)。

攞 DeepSeek API Key

platform.deepseek.com → 註冊/登入 → API Keys → 建立 Key(sk- 開頭)。新用戶有免費額度。

確認 config.yaml

nano ~/.hermes/config.yaml
provider: deepseek model: deepseek-v4-pro base_url: https://api.deepseek.com/v1

寫入 .env

DEEPSEEK_API_KEY=sk-你的deepseek密鑰

驗證連線

hermes chat

輸入「你好」收到回覆即成功,Ctrl+C 退出。

⚠️ 踩坑:DeepSeek Key 有兩種!用過 Claude Code + DeepSeek 嘅人可能攞錯 — 一個係 Claude Code 用嘅 ANTHROPIC_AUTH_TOKEN,一個係 DeepSeek 平台原生 Key,兩者格式相同但值唔同。用平台原始 Key;報 401 就係 Key 錯。快速測試:
curl https://api.deepseek.com/v1/chat/completions \ -H "Authorization: Bearer sk-你的key" \ -H "Content-Type: application/json" \ -d '{"model":"deepseek-v4-pro","messages":[{"role":"user","content":"hi"}]}'
200 = 有效,401 = 無效。

7 安裝 Hermes Gateway(systemd 服務)

喺 Linux 伺服器上,Gateway 必須行 systemd 先做到:開機自啟、崩潰自動重啟、24/7 唔斷線、斷開 SSH 照跑。

安裝 Gateway

hermes gateway install

手動建立 systemd 服務檔 核心步驟

⚠️ 最易中嘅大坑:systemd 唔會讀 .env 檔!環境變數必須直接寫入服務檔,否則 Bot 會話「No messaging platforms enabled」。

sudo nano /etc/systemd/system/hermes-gateway.service
[Unit] Description=Hermes Gateway Service After=network.target [Service] Type=simple User=ubuntu WorkingDirectory=/home/ubuntu ExecStart=/home/ubuntu/.local/bin/hermes gateway Restart=always RestartSec=10 Environment=PATH=/home/ubuntu/.local/bin:/usr/local/bin:/usr/bin:/bin # 關鍵:systemd 唔讀 .env,環境變數要直接寫喺呢度! Environment=DEEPSEEK_API_KEY=sk-你的deepseek密鑰 Environment=TELEGRAM_BOT_TOKEN=你的Bot Token Environment=TELEGRAM_ALLOWED_USERS=你的Telegram數字ID Environment=TELEGRAM_HOME_CHANNEL=你的Telegram數字ID Environment=GATEWAY_ALLOW_ALL_USERS=true [Install] WantedBy=multi-user.target

修改重點:User / WorkingDirectory / ExecStart 按實際路徑改;五個 Environment= 全部要填真值。

啟動 + 開機自啟

sudo systemctl daemon-reload sudo systemctl enable hermes-gateway sudo systemctl start hermes-gateway

驗證 + 睇日誌

sudo systemctl status hermes-gateway sudo journalctl -u hermes-gateway -f

狀態顯示 active (running),日誌見到 ✓ telegram connected 即成功。

設日誌輪替(防磁碟爆)

sudo nano /etc/systemd/journald.conf
SystemMaxUse=200M SystemKeepFree=500M RuntimeMaxUse=100M
sudo systemctl restart systemd-journald
實測教訓(我哋部機):改服務檔可以喺本地寫好先上傳 — sudo cp 入 /etc/systemd/system/ 再 daemon-reload 就得。另外 Bot 上 systemd 之前一定要 pkill 舊嘅 polling 進程,否則 Telegram 會報 409 Conflict(兩個 getUpdates 同時爭同一個 Bot)。最後 hermes git pull --rebase 更新完記得重啟服務。

8 接入 Telegram Bot

用 @BotFather 建 Bot

Telegram 搜尋 @BotFather → /newbot → 設名稱/用戶名 → 攞 Bot Token(格式 123456:ABC-DEF1234ghiJKL)。妥善保存,唔好洩漏。

攞你嘅 Telegram 數字 ID

搜尋 @userinfobot → /start → 攞數字 ID(例如 123456789)。

更新 systemd 服務檔

sudo nano /etc/systemd/system/hermes-gateway.service
Environment=TELEGRAM_BOT_TOKEN=123456:ABC-DEF1234ghiJKL Environment=TELEGRAM_ALLOWED_USERS=123456789 Environment=TELEGRAM_HOME_CHANNEL=123456789 Environment=GATEWAY_ALLOW_ALL_USERS=true
sudo systemctl daemon-reload sudo systemctl restart hermes-gateway

驗證

日誌見到 ✓ telegram connected,然後喺 Telegram 同你嘅 Bot 講嘢,有回覆即成。

故障排查口訣:Bot 冇反應 → ① sudo systemctl status hermes-gateway 係咪 running → ② 日誌 journalctl -u hermes-gateway -f → ③ 見到 No messaging platforms enabled = Token 冇讀到 → ④ 檢查服務檔 Environment → ⑤ daemon-reload + restart → ⑥ 再驗證。

9 設定中文回覆(SOUL.md)

編輯 SOUL.md

cp ~/.hermes/SOUL.md ~/.hermes/SOUL.md.backup nano ~/.hermes/SOUL.md

喺頂部加入語言規則:

CRITICAL LANGUAGE RULE: You MUST reply in Chinese (繁體中文) at all times. The user speaks Chinese. Never use English unless the user explicitly asks.

(可選)注入項目知識

SOUL.md 可以寫入身份、技能、項目結構、程式碼規範、常用命令 — 成為 Hermes 嘅「長期記憶」,每次對話都引用。

重啟生效

sudo systemctl restart hermes-gateway

改完 SOUL.md 必須重啟 Gateway 先生效。

10 防火牆與安全規則(兩層都要開)

Oracle VM 有兩層防火牆:OCI VCN 嘅 Security List(雲端層)+ 實例內嘅 UFW(系統層)。兩層都唔放行先會通。

▎10.1 OCI Security List(雲端層)

開入站規則

OCI Console → Networking → Virtual Cloud Networks → 揀 VCN → Subnets → Security Lists → 預設安全清單 → Add Ingress Rules:

來源類型來源 CIDR連接埠用途
CIDR0.0.0.0/022SSH
CIDR0.0.0.0/080HTTP
CIDR0.0.0.0/0443HTTPS

若安裝 WebUI 仲要開對應連接埠(如 8787)。

▎10.2 實例防火牆(系統層)

sudo ufw status verbose

應見到 22 / 80 / 443 ALLOW IN。Oracle Linux 用戶如果 UFW 冇反應,可能要直接改 iptables。

⚠️ 實測教訓:OCI 嘅「NSG ≠ iptables」。如果喺 Console 開咗安全清單但仍然連唔到,唔好淨係喺 VM 入面查 iptables — 先確認 OCI 嗰層(Security List / NSG)有冇放行。兩層係獨立嘅,任何一層擋住都係失敗。仲有:443 好多時已經俾其他服務(例如 sing-box 代理)佔用,開 port 前先 ss -tlnp 睇下邊個喺度用緊。

11 常用指令速查表

指令作用
hermes chat啟動終端對話模式
hermes --tui啟動 TUI 介面
hermes setup重新執行設定嚮導
hermes update更新 Hermes Agent(源碼版用 git pull --rebase)
hermes gateway install / status / restartGateway 安裝 / 狀態 / 重啟
hermes cron list / status列出 / 查看排程任務
sudo systemctl status hermes-gateway查看服務狀態
sudo systemctl enable hermes-gateway開機自動啟動
sudo journalctl -u hermes-gateway -f即時睇服務日誌
tail -f ~/.hermes/logs/gateway.log即時睇 Hermes 日誌
df -h / free -h磁碟 / 記憶體使用

12 踩坑合集(全部親測)

Q:Bot 上 systemd 後報 409 Conflict?

原因:舊嘅 polling 進程仲喺度同 Gateway 爭同一個 Bot Token。
解決:起服務前先 pkill -f "hermes" 或直接 pkill -f polling,再 systemctl start hermes-gateway。

Q:Gateway 啟動咗但 Bot 完全冇反應?

原因:9 成係 systemd 冇讀到環境變數。日誌出現 No messaging platforms enabled 即係 Token 未載入。
解決:確認服務檔嘅 Environment= 五個變數全部填咗 → daemon-reload + restart → 再睇日誌。

Q:DeepSeek API 報 401 Authentication Fails?

原因:用錯 Key(Claude Code 嗰個)或者 Key 過期。
解決:用 curl 測 Key(見 §6)→ 去平台重建 → 更新服務檔 DEEPSEEK_API_KEY → daemon-reload + restart。

Q:SSH 連唔到/超時?

檢查順序:① OCI Security List 有冇開 22 → ② Public IP 啱唔啱 → ③ 金鑰權限 chmod 400 ~/.ssh/id_rsa → ④ 用戶名(Ubuntu 用 ubuntu)。

Q:記憶體不足(OOM)?

用 ARM 2 vCPU / 12GB 實例基本上唔會遇到。x86 micro 先要加 Swap:
sudo fallocate -l 4G /swapfile && sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
再加入 /etc/fstab 永久生效。

Q:Oracle 會唔會回收我部機?

Oracle 會回收長期低活動嘅免費實例。Gateway 24/7 運行本身就係持續活動;想更穩陣可以加 keepalive:
crontab -e → 加入 */30 * * * * echo "keepalive $(date)" >> ~/keepalive.log

Q:更新完要重啟嗎?

apt upgrade 更新咗 kernel 之後要 sudo reboot 先生效;hermes git pull --rebase 更新源碼之後要 sudo systemctl restart hermes-gateway。

13 進階:Hermes WebUI(可選)

想用瀏覽器介面同 Agent 互動、唔使 SSH?裝 WebUI 就得。

克隆 + 設密碼

cd ~ git clone https://github.com/nesquena/hermes-webui.git hermes-webui cd hermes-webui echo "HERMES_WEBUI_PASSWORD=設置一個強密碼" > .env

建 systemd 服務

sudo nano /etc/systemd/system/hermes-webui.service
[Unit] Description=Hermes WebUI After=network.target [Service] Type=simple User=ubuntu WorkingDirectory=/home/ubuntu/hermes-webui ExecStart=/home/ubuntu/hermes-webui/start.sh Restart=always RestartSec=5 [Install] WantedBy=multi-user.target

啟動 + 訪問

sudo systemctl daemon-reload sudo systemctl enable hermes-webui sudo systemctl start hermes-webui

瀏覽器開 http://<Public IP>:8787,用 .env 密碼登入。記住 OCI Security List 要放行 8787。

(可選)Nginx 反代 + HTTPS

sudo apt install nginx certbot python3-certbot-nginx -y sudo nano /etc/nginx/sites-available/hermes-webui
server { listen 80; server_name ai.yourdomain.com; client_max_body_size 500M; location / { proxy_pass http://127.0.0.1:8787; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } }
sudo ln -s /etc/nginx/sites-available/hermes-webui /etc/nginx/sites-enabled/ sudo nginx -t && sudo systemctl restart nginx sudo certbot --nginx -d ai.yourdomain.com

14 備份與維護建議

▎14.1 定期備份(最重要嘅檔案)

tar -czvf hermes-backup-$(date +%Y%m%d).tar.gz \ ~/.hermes/config.yaml ~/.hermes/.env ~/.hermes/SOUL.md \ ~/.hermes/logs/ /etc/systemd/system/hermes-gateway.service # 拉返落本地 scp ubuntu@<Public IP>:~/hermes-backup-*.tar.gz ./

config.yaml(設定)、.env(密鑰)、SOUL.md(長期記憶)、systemd 服務檔 — 呢四樣加埋就係成部機嘅「靈魂」,冇咗佢哋等於由頭嚟過。

▎14.2 維護節奏

頻率做咩
每週sudo apt update && sudo apt upgrade -y + sudo apt autoremove -y
每月sudo journalctl --vacuum-time=30d;df -h / free -h 檢查
每 3-6 個月rotation API Key、檢查 Drive/遠端備份完整性
⚠️ 唔好當 apt 升級「一定安全」:升級 docker-ce / containerd 會重啟 Docker daemon,所有容器一齊 bounce。實測(2026-09-16):daemon 重啟時 Pi-hole 綁唔到 host port,靜靜死掉 → 依賴佢做 DNS 嘅代理全部 handshake 失敗,客戶端顯示「port 沒開」,其實 443/853 一直有聽。升級後必驗三樣:docker ps 容器齊唔齊、systemctl status sing-box、真係連一次代理(見 §16 監控寫法)。

▎14.3 安全建議

15 ⚠️ 2026-06-15:Oracle 免費額度靜靜雞減半

2026-06-15 Oracle 冇公告、冇電郵,靜靜雞改文件將 Always Free ARM 額度減半:4 OCPU / 24GB → 2 OCPU / 12GB(每月上限 3,000 OCPU-hrs + 18,000 GB-hrs → 1,500 + 9,000)。外送流量維持 10TB/月(未變)。

配置(長開一個月)消耗新額度 1,500 + 9,000
4 OCPU / 24GB(舊)2,920 OCPU-hrs + 17,520 GB-hrs❌ 超額成倍
2 OCPU / 12GB(新)1,460 OCPU-hrs + 8,760 GB-hrs✅ 啱啱好

▎15.1 純免費 vs PAYG 命運唔同

⚠️ 唯一風險(官方有提):實例正常停止 → 可以再啟動;但若被終止(terminate),重建同配置要視乎大阪區當時 ARM 容量。保險已就緒:OCI boot volume backup + Drive 異地備份。

▎15.2 官方政策原文(關鍵段落)

來源:docs.oracle.com — Always Free Resources

"All tenancies get the first 1,500 OCPU hours and 9,000 GB hours per month for free for VM instances using the VM."
"you can create one or two OCI Ampere A1 Compute instances, 2 OCPUs total."

▎15.3 官方客服回覆原文(2026-08-03,PAYG 帳戶查詢)

"Thank you for providing the details. Since your tenancy is a Pay As You Go (PAYG) account, you do not need to worry about the recent Always Free Ampere A1 resource limit update. Your existing 4 OCPU / 24 GB A1 instance does not need to be resized as a result of this policy change. You will not be billed for your existing 4 OCPU / 24 GB A1 instance solely because of the Always Free limit update. The reduction to 2 OCPUs / 12 GB RAM applies only to Always Free tenancies, not to PAYG accounts. There is no deadline requiring PAYG customers to resize existing A1 instances because of this change. If your instance is stopped, you can start it again normally. However, if it is terminated, the ability to recreate an instance with the same configuration depends on current capacity availability in your selected region. The reduction in the Always Free Ampere A1 allocation applies only to Always Free tenancies. PAYG and other paid tenancy types are not affected by this specific policy change. Based on the information available, your existing 4 OCPU / 24 GB A1 instance on your PAYG tenancy will continue to operate under the terms applicable to your paid account and will not incur charges solely because of this Always Free policy update."

▎15.4 社群共識(2026-07)

▎15.5 保險三寶(親測)

  1. OCI Boot Volume Backup:Console → 運算 → 實例 → 開機磁碟區 → 建立備份(雲端整機還原,~10 分鐘 Available)
  2. Drive 異地備份:配置 tar.gz(~/.hermes、nginx、systemd、crontab)每日自動 → Google Drive(見 §14)
  3. 唔好亂停機:grandfather 期間一旦終止,可能永遠開唔返

▎15.6 替代方案(萬一 Oracle 玩完)

需要方案成本
日本 IP + 最平保留 Oracle 2/12$0
日本 IP 付費Contabo 大阪 4vCPU/8GB | Vultr Tokyo 1-2GB~€7/月 | $5-6/月
唔使日本 IPRackNerd 1GB | GCP e2-micro~$1/月 | $0
GFW 用途VLESS/REALITY(任何 VPS 都行)+ CF Worker 後備$0 起

💡 GFW 提示:Oracle/Contabo datacenter IP 用耐咗容易被 GFW 封,REALITY 可頂主動探測;CF Worker(edgetunnel)係免費後備線。

16 免費額度監控 + 每日賬單推送(OCI Usage API)

Oracle 唔會主動通知你額度用咗幾多 —— 通常等到出咗費用先發現。呢節用 OCI 官方 Usage API 每日自動拉「用咗幾多 + 月底預測」,過 90% 就響警報,再由 Hermes 推去 Telegram。所有數字即時由 API 拎,唔係人手填。

▎16.1 裝 OCI CLI + API Key

bash -c "$(curl -L https://raw.githubusercontent.com/oracle/oci-cli/master/scripts/install/install.sh)" ~/bin/oci setup config # 互動:Tenancy OCID / User OCID / Region / 產生 keypair

之後去 Console 右上頭像 → My profile → API keys → Add API key → 貼上 ~/.oci/oci_api_key_public.pem 內容。順手記低 Tenancy OCID(就係下面 --tenant-id 要嘅值)。之後所有查詢直接讀 ~/.oci/config,唔使再登入。

文件 vs 現實:呢個 CLI 版本 oci limits / oci iam limit* 唔存在,免費額度唔可以靠 quota API 查 —— 要用下面嘅 Usage API 反推。

▎16.2 兩條關鍵命令(實測,官網文件唔齊)

TENANCY=ocid1.tenancy.oc1..xxxx # 你嘅 Tenancy OCID S=$(date -d "$(date +%Y-%m-01)" +%Y-%m-%d) # 本月 1 號 E=$(date -d tomorrow +%Y-%m-%d) # ① 費用(本月 / 昨日) ~/bin/oci usage-api usage-summary request-summarized-usages \ --tenant-id $TENANCY \ --time-usage-started ${S}T00:00:00Z --time-usage-ended ${E}T00:00:00Z \ --granularity MONTHLY --query-type COST --output json # ② 免費額度用量(按 service + skuName 分組) ~/bin/oci usage-api usage-summary request-summarized-usages \ --tenant-id $TENANCY \ --time-usage-started ${S}T00:00:00Z --time-usage-ended ${E}T00:00:00Z \ --granularity MONTHLY --query-type USAGE \ --group-by '["service","skuName"]' --output json
API 回傳(service · skuName)對應免費額度單位
Compute · Standard - A1ARM 運算OCPU·時
Compute · Standard - A1 - MemoryARM 記憶體GB·時
Block Storage · Block Volume - Free塊存總量GB
Virtual Cloud Network · Outbound Data Transfer*出站流量GB
⚠️ 三個實測坑:
  • 正確路徑係 usage-api usage-summary request-summarized-usages。寫 usage-api request-summarized-usages 或者 usage-api query ...(後者只管 saved query)一律 Error: No such command。
  • oci ... list 冇結果時係 rc=0 + stdout 完全空白(唔係 {"data": []})→ json.loads 直接炸。helper 要 if not out: return {"data": []}。
  • 關鍵字 Standard - A1 會連記憶體條目一齊中 → OCPU·時 = qty("A1") − qty("A1 - Memory"),唔減就會大咗一倍。

▎16.3 接上 Hermes:每日 08:00 自動推 Telegram

# 1) 報告 script(印出嘅 stdout 就係 Telegram 訊息內容) nano /home/ubuntu/oci-billing/oci_billing_report.py # 2) Hermes cron 只認 ~/.hermes/scripts/ 下面嘅檔,所以要一個 thin wrapper echo '#!/bin/bash' > ~/.hermes/scripts/oci_billing_report.sh echo 'exec python3 /home/ubuntu/oci-billing/oci_billing_report.py' >> ~/.hermes/scripts/oci_billing_report.sh chmod +x ~/.hermes/scripts/oci_billing_report.sh # 3) 建立 no_agent job(零 token,script stdout 直接送出) hermes cron create "0 8 * * *" --name "OCI 賬單日報" \ --script oci_billing_report.sh --no-agent --deliver origin # 4) 即刻試一次(唔等明早) hermes cron run <job_id>

--no-agent = 唔叫 LLM,script 印咩就送咩(stdout 空白 = 靜默唔發,適合 watchdog);想改時間就改 cron 表達式,例如 "30 7 * * 1" = 逢星期一 07:30。系統 crontab 都做到同一件事,但 hermes cron 多咗執行紀錄同失敗通知。

▎16.4 實測輸出(大阪 A1 · 4 OCPU / 24GB · PAYG)

-- 甲骨文 OCI 賬單日報 -- 📅 2026-09-16 · 大阪 ap-osaka-1 -- 💰 費用 (HKD) -- 昨日: 0.00 本月: 0.00 -- 🎁 本月免費額度用量 -- ARM 計算: 1,484.0 / 3,000 OCPU·時 (49%) ARM 內存: 8,904.0 / 18,000 GB·時 (49%) 出站流量: 53.6 / 10,240 GB (1%) 塊存: 85.7 / 200 GB (43%) -- 📈 月底預測 (至 9月30日) -- ARM 計算: ~2,782.5 / 3,000 OCPU·時 (93%) ARM 內存: ~16,695.0 / 18,000 GB·時 (93%) 出站流量: ~100.5 / 10,240 GB (1%) 塊存: ~160.7 / 200 GB (80%) ⚠️ 接近上限: ARM 計算, ARM 內存 -- 🖥️ 實例 -- 運行中: 1 台 · instance-20260508-2242 · VM.Standard.A1.Flex 4.0 OCPU / 24.0 GB -- 💡 免費額度還能用 -- AMD 小實例: 仲可開 2 台 (E2.1.Micro · 1/8 核 / 1GB) 自治數據庫: 2 個未用 負載均衡: 1 個未用

▎16.5 免費上限寫喺邊(設定一次)

上限係官方固定值(只做分母),寫喺 script 頂部常數就得;用量本身永遠係 API live 數字:

LIMITS = { "arm_ocpu": 3000.0, # OCPU·時/月(Always Free 戶請改 1500) "arm_mem": 18000.0, # GB·時/月(Always Free 戶請改 9000) "egress": 10240.0, # GB/月(10TB,兩種帳戶一樣) "block": 200.0, # GB 總量(兩種帳戶一樣) } WARN_PCT = 90.0 # 月底預測達 90% → 出警告

附 附錄:檔案路徑 + 資源限制 + 完成清單

▎A.1 檔案路徑總覽

路徑說明
~/.local/bin/hermesHermes 主程式
~/.hermes/config.yaml主設定檔
~/.hermes/.env環境變數 / 密鑰
~/.hermes/SOUL.md系統提示詞(長期記憶)
~/.hermes/logs/gateway.logGateway 日誌
/etc/systemd/system/hermes-gateway.serviceGateway systemd 服務檔

▎A.2 OCI Always Free 資源上限

資源限制
ARM Ampere A1 實例2 OCPU + 12GB RAM(2026-06-15 減半;舊帳戶可續跑 4/24 直至實例終止)
x86 AMD 實例最多 2 個 E2.1.Micro(各 1/8 OCPU + 1GB)
開機磁碟總容量200GB(所有實例共享)
公有 IPv4最多 6 個
網路頻寬每 vCPU 1 Gbps

▎A.3 部署完成清單

✅檢查項
□VM 已建立(ARM 2 OCPU / 12GB)並 SSH 連到
□hermes --version 有輸出
□DeepSeek API Key 有效(curl 200)
□systemd 服務 active + enabled,日誌見 ✓ telegram connected
□Telegram 實測有回覆
□SOUL.md 已設繁中回覆
□OCI Security List + UFW 兩層防火牆已開
□備份策略已建立(tar.gz + 拉返本地)

鍾意呢份指南?請我飲杯咖啡 ☕

☕ 請我喝杯咖啡