Skip to main content
Back to Read
AI Agents17 April 2026Updated 6 September 202612 min read

Hermes Agent on Oracle Cloud Free Tier: A UK Guide (2026)

Deploy Hermes Agent on Oracle Cloud Free Tier with current Ampere A1 limits, UK region setup, network rules, backups, gateway service checks and recovery planning.

Sajad Saleem

Co-founder of Ampliflow. Builds AI automation, websites, SEO/AEO, and growth systems for UK SMEs.

Natural-light photograph: an older white British man with glasses and a plain jumper crouches in a small home study to plug a cable into a compact router on a low wooden shelf, a desktop tower nearby, soft daylight through a net curtain.
Illustrative scene.
  1. 01What Oracle currently publishes for Always Free Ampere A1
  2. 02Choose the UK region deliberately
  3. 03The clean Oracle setup path
  4. 04Backups before updates, and backups before migration
  5. 05When Oracle Free Tier is the right answer

Oracle Cloud Free Tier is still a credible place to test Hermes Agent, but it should be treated as a free-eligible pilot environment rather than a guaranteed production platform. Oracle's current Always Free documentation says Ampere A1 gives a monthly allowance equivalent to 2 OCPUs and 12 GB of memory in the tenancy home region, which can be allocated flexibly across one or two VM.Standard.A1.Flex instances. It also warns that capacity can be temporarily unavailable and that idle Always Free compute instances may be reclaimed.

That changes the shape of the advice. The useful answer is no longer "Oracle is free, therefore use it." The useful answer is: use Oracle Free Tier when you can tolerate capacity risk, keep the deployment narrow, back it up properly, and know when to move to a paid host.

Last updated: 6 September 2026. Checked against Oracle Always Free documentation and Hermes installation, messaging and updating docs on 6 September 2026.

TL;DR:

  • Oracle's Always Free Ampere A1 allowance is currently 1,500 OCPU hours and 9,000 GB hours per month, equivalent to 2 OCPUs and 12 GB memory, in the tenancy home region.
  • Capacity is not guaranteed. If Oracle returns "out of host capacity", try another availability domain, wait, or use a paid account/host.
  • Idle Always Free instances can be reclaimed when CPU, network and memory use stay below Oracle's published thresholds over a seven-day period.
  • For a Hermes-only pilot, start with one small Linux VM, install Hermes from the official installer, run the gateway as a managed service, and verify hermes doctor, hermes gateway status and logs before linking real workflows.
  • For business use, plan backups with hermes backup and hermes import, not a hand-rolled copy of random state files.

If you are deciding whether Hermes belongs in a business workflow, the server choice is only one decision. The wider work is scoping the workflow, permissions, approval points, logging, recovery and ownership. For that, start with the full Hermes deployment guide, AI automation, or get unstuck.

Decide whether Oracle is the right host

Oracle Cloud Free Tier is attractive because a Hermes gateway can run away from a laptop without creating an immediate server bill. That is enough for learning, a proof-of-concept, or a narrow internal pilot.

The decision should turn on operational risk:

QuestionIf yesIf no
Can the pilot tolerate a host migration?Oracle Free Tier is worth testingUse paid hosting
Have you confirmed Always Free capacity in the chosen home region?Create the VM and document limitsDo not assume capacity from a tutorial
Is the workflow internal and reviewable?Start narrowAvoid free-tier dependency
Has backup/import been tested?Continue the pilotFinish recovery before production
Does the workflow need provider support or SLA evidence?Use a paid routeFree tier may be acceptable

The server price is the least interesting part of a business deployment. The real questions are whether the workflow can stop safely, whether state can be restored, and whether a person knows how to recover it.

What Oracle currently publishes for Always Free Ampere A1

Oracle's Always Free documentation says all OCI accounts have Always Free resources in the tenancy home region for the life of the account. For Ampere A1 compute, Oracle currently describes:

ResourceCurrent Oracle documentation saysWhat it means for Hermes
Compute shape`VM.Standard.A1.Flex` Arm-based OCI Ampere A1Use ARM64-compatible packages and avoid x86-only binaries
AllowanceFirst 1,500 OCPU hours and 9,000 GB hours per monthEquivalent to 2 OCPUs and 12 GB memory if allocated all month
AllocationOne 2 OCPU VM or two 1 OCPU VMs, subject to boot-volume storageOne Hermes pilot usually wants one VM, not fragmented capacity
Storage200 GB combined boot/block Always Free storage in the home regionOften enough for a narrow pilot, but measure logs, backups and browser/runtime assets
Outbound transfer10 TB per monthUsually far above a narrow Hermes pilot's traffic
Capacity warning"Out of host capacity" can happenHave a paid fallback before a business depends on it
Idle reclamationLow CPU, network and A1 memory use over seven days can trigger reclamationKeep backups and monitor the instance, even if it costs nothing

The older version of this article described a single 1 OCPU / 6 GB ceiling as if that were the whole free allowance. That was too narrow for the current Oracle wording. A cautious pilot may still choose 1 OCPU / 6 GB to leave headroom for a second test instance, but the published allowance is larger.

Choose the UK region deliberately

For a UK business, choose UK South (London) as the home region if you want the VM and local Hermes state in the UK. Oracle's Always Free compute resources have to be created in the tenancy home region, so this choice matters at account setup.

The business reason is not that London magically makes Hermes faster. In most agent sessions, the model provider call dominates latency. The region matters because it keeps the host and local state closer to the operator. It does not prove the whole data flow stays in the UK; model providers, messaging channels, backup destinations and monitoring tools still need separate checks.

Before you rely on London Free Tier capacity, verify three things in the Oracle console:

  1. The home region is UK South.
  2. The shape is marked Always Free-eligible.
  3. The Limits, Quotas and Usage page shows enough Ampere A1, boot-volume and backup capacity for the instance you are creating.

If any of those checks fail, stop and choose a paid VPS or a paid OCI shape. Do not build a production workflow around a capacity error you hope will disappear.

The clean Oracle setup path

  1. 01Step 1 — Sign up for Oracle Cloud
  2. 02Step 2 — Create the Ampere A1 instance
  3. 03Step 3 — SSH in and update
  4. 04Step 4 — Open the network rules
  5. 05Step 5 — Install Hermes
  6. 06Step 6 — Test the gateway

Create the VM in Oracle Cloud, then follow the Hermes docs rather than an old copied unit file.

In the Oracle console:

  1. Create a Linux compute instance in the home region.
  2. Use an Always Free-eligible Ubuntu or Oracle Linux image.
  3. Pick VM.Standard.A1.Flex.
  4. Allocate the smallest shape that fits the pilot, then measure real memory.
  5. Use a 50 GB boot volume unless you have a clear storage reason to allocate more.
  6. Add your SSH public key and keep the private key somewhere controlled.
  7. Put the instance in a public subnet only if SSH access is intentionally exposed.

On first login to an Ubuntu image:

bashssh ubuntu@<server-ip>
sudo apt update
sudo apt upgrade -y

If you choose Oracle Linux or another image, use that distribution's package manager and default user instead of copying Ubuntu commands.

Then install Hermes using the current official command:

bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash

For a production-like server, run Hermes as a dedicated unprivileged user. The current installation docs support that pattern and call out the browser-dependency step separately. If the workflow does not need browser automation, install with:

bashcurl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash -s -- --skip-browser

That keeps the pilot smaller and removes a browser runtime you may not need.

Install the gateway as a managed service

After hermes setup, check the install:

bashhermes --version
hermes doctor

For the messaging gateway, the current Hermes docs expose service commands directly:

bashhermes gateway install
hermes gateway start
hermes gateway status
journalctl --user -u hermes-gateway -f

For a headless VM, the Hermes messaging docs recommend a system service:

bashsudo hermes gateway install --system
sudo hermes gateway start --system
sudo hermes gateway status --system
journalctl -u hermes-gateway -f

If your operating model uses a user service instead, enable lingering so the service can survive logout:

bashsudo loginctl enable-linger $USER

The current updating docs also note that user services can be restarted by hermes update without root prompts. Avoid running both user and system gateway units unless you mean to. Status, restart and update behaviour becomes ambiguous.

Firewall rules that actually matter

Keep the inbound surface small.

RuleRecommendationWhy
SSHAllow port 22 only from your fixed IP or via Oracle Bastion/VPNSSH is the real admin boundary
DashboardDo not expose port 9119 publiclyUse SSH tunnelling or a protected tunnel if the dashboard is needed
Gateway callbacksOpen only the exact port and source required by the channelAvoid "temporary" public rules that nobody removes
Outbound HTTPSAllow only the model provider, messaging provider and approved APIs where policy requires itReduces exfiltration risk if the agent is compromised

Oracle Network Security Lists can handle the cloud-side rules. ufw can add another host-level guard. The important thing is that the rule list matches the workflow, not a tutorial.

Backups before updates, and backups before migration

The biggest freshness correction is backups. Older Hermes guides, including older versions of our own cluster, described bespoke zip/export scripts. The current Hermes docs have stronger native options.

For routine updates:

bashhermes update --check
hermes update --plan
hermes update --backup

The current update docs say hermes update creates pre-update snapshots by default, can take a full HERMES_HOME backup with --backup, writes update receipts, validates critical files after pulling code, and restarts running gateways. That means a separate 100-line auto-update script is no longer the default recommendation.

For moving to a new server, use the native full backup path:

bashhermes backup
hermes import <backup-file>

That matters for Oracle Free Tier because the two realistic failure modes are capacity loss and outgrowing the pilot. A backup that cannot restore onto Hetzner, DigitalOcean, paid OCI or another Linux VM is not a backup.

Use the Hermes backup and migration guide for the full move-server sequence, including credential protection and checks to prevent duplicate jobs after cutover.

When Oracle Free Tier is the right answer

Use Oracle Free Tier when all of these are true:

  • The first workflow is narrow: one gateway, one messaging channel, one or two skills.
  • Downtime during the pilot would be inconvenient, not commercially damaging.
  • The operator can SSH in, inspect logs and restore from backup.
  • You have confirmed current account limits, home-region capacity and Always Free labels.
  • You have a paid fallback host ready before the workflow becomes important.

Do not use it as the only production home when:

  • The agent handles customer-facing messages.
  • A missed run has contractual, clinical, legal, financial or safety impact.
  • You need provider support with an SLA.
  • The workflow needs predictable CPU, RAM or storage growth.
  • The business owner cannot explain who owns updates, monitoring and recovery.

The free server saves money. It does not remove operational responsibility.

Oracle Free Tier versus a small paid VPS

DecisionOracle Free TierSmall paid VPS
Monthly infrastructure cost£0 inside Always Free limitsCurrent provider quote
CapacityGood when available, but not guaranteedBought capacity is simpler to plan around
RegionUK South possible if selected as home regionDepends on provider
SupportFree-tier/account support limitations applyDepends on plan
Migration riskHigher if capacity or idle rules biteLower if billing and provider terms are stable
Best useLearning, proof-of-concept, narrow internal pilotBusiness workflow that needs predictable uptime

The practical path is to start on Oracle only if the pilot can tolerate being moved. The moment a founder, sales team or support process depends on Hermes, re-evaluate whether the free saving is worth the recovery risk.

Common setup mistakes

Picking the wrong shape

Only use the shape and image combination that the Oracle console marks Always Free-eligible. AMD/Intel shapes may be billable. Do not rely on a blog post screenshot from May when the console in front of you says something different in September.

Forgetting that Arm is different

Ampere A1 is Arm. Hermes itself is fine with modern Python and Node paths, but any x86-only binary, browser dependency, native package or Docker image needs checking. If a command fails with an architecture error, rebuild or install the ARM64 version.

Treating systemd as optional

A long-running gateway should be managed by the service manager. Use hermes gateway install, check the status command, then test restart and reboot. A background shell session is not an operated deployment.

Exposing the dashboard

The dashboard is useful for operators. It should not be a public internet surface. Tunnel it or put it behind a proper access policy.

Not testing restore

Backups are comforting until the first restore fails. Create a backup, restore it onto a clean test VM or profile, and document the exact command sequence.

Frequently asked questions

Is Oracle Cloud Free Tier enough for Hermes Agent?

For a narrow pilot, yes, when capacity is available and the workflow is measured. For a business-critical workflow, treat it as a test environment unless you have a recovery owner, monitoring, backups and a paid fallback.

What size should I choose?

Start small, then measure. Oracle's current Always Free Ampere A1 allowance is 2 OCPUs and 12 GB memory in total, but a single Hermes pilot does not need to consume the whole allowance unless measured memory and concurrency justify it.

Can Oracle reclaim my Hermes instance?

Oracle's documentation says idle Always Free compute instances may be reclaimed when CPU, network and memory utilisation stay below published thresholds over a seven-day period. Design as if the instance can disappear: monitor it, keep backups, and keep migration instructions ready.

Is it really free?

Always Free resources are free inside Oracle's published limits and eligibility rules. You can still create billable resources by choosing the wrong shape, region, storage or service. Check the Always Free label and the Limits, Quotas and Usage screen before provisioning.

Should I put customer data through this setup?

Not until the security and governance work is done. Read the Hermes Agent Security & GDPR guide before connecting CRM, email, support, finance or personal data.

How do I move off Oracle later?

Use hermes backup, provision the new Linux host and run hermes import into an isolated destination. Verify state, credentials and jobs before enabling the new gateway, then update DNS/tunnels and monitoring. Keep the source stopped so it cannot repeat the same actions. Follow the backup and restore checklist for the complete cutover.

What should you do next?

If you are still proving the idea, Oracle Free Tier is worth testing. If the agent will touch live business operations, treat the server as one line in a runbook: monitored, backed up, recoverable and owned.

Need help deciding whether Oracle Free Tier is enough for your Hermes workflow? Get unstuck →

Hermes setup help

Deployment, skills and day-two reliability

Get help setting up your Hermes agent

We deploy, harden and maintain Hermes Agent for UK businesses — cloud hosting, gateways, skills, approvals, monitoring and recovery included.

Cloud deployment & hardening
WhatsApp, Slack & email
Safe, repeatable skills
Monitoring & recovery
Scope my Hermes setup

Bring the use case or the setup you already have. We will tell you the smallest sensible next step.