# Random Password Implementation for Hermes Instances

## Summary
Each new Hermes instance now gets a unique, randomly generated password instead of using the default "change-me-now" password.

## Changes Made

### 1. Updated `src/lib/runtime-credentials.ts`

Added `generateRandomPassword()` function:
- Generates 16-character passwords
- Includes uppercase, lowercase, numbers, and symbols
- Ensures at least one character from each category
- Randomly shuffles characters for better security

Updated `defaultHermesCredentials()`:
- Now calls `generateRandomPassword(16)` instead of using "change-me-now"

### 2. Updated `src/lib/dokploy.ts`

- Imported `generateRandomPassword` function
- Modified `provisionLocalDocker()` to always generate new random credentials:
  ```typescript
  const credentials: RuntimeCredentials = {
    username: process.env.HERMES_ADMIN_USERNAME || "admin",
    password: generateRandomPassword(16)
  };
  ```
- Updated `makeLocalHermesCompose()` to accept credentials as a parameter
- Credentials are stored in the `deploy_payload` field in the database

## How It Works

When a user creates a new Hermes instance:

1. **Instance Creation** starts via `/dashboard/instances`
2. **Random password generated** using `generateRandomPassword(16)`
3. **Docker container created** with the generated credentials as environment variables:
   - `ADMIN_USERNAME`: admin (or custom from HERMES_ADMIN_USERNAME env)
   - `ADMIN_PASSWORD`: <random 16-character password>
4. **Credentials saved** in the `deploy_payload` field of the instances table
5. **Credentials returned** in the job result for display to the user

## Security Benefits

- **Unique passwords per instance**: No shared passwords across instances
- **Strong passwords**: 16 characters with mixed case, numbers, and symbols
- **No default password vulnerability**: Eliminates "change-me-now" security risk
- **User isolation**: Each user's instances have separate credentials

## Example Generated Passwords

Examples of passwords generated by the function:
- `WYvWA$yIzU8n+YhX`
- `aPzWb9x70M+X_Lfp`
- `0PQC=Mosm7MT6cXD`

**Note**: Passwords use safe symbols (`!+$?=-_`) to avoid YAML escaping issues.

## Database Storage

Credentials are stored in the `instances` table:
```json
{
  "deploy_payload": {
    "credentials": {
      "username": "admin",
      "password": "xK9#mP2!nL5@qR8*"
    },
    "gatewayPort": 8642,
    "mode": "local-docker",
    ...
  }
}
```

## API Response

When an instance is created, the response includes:
```json
{
  "instance": {
    "id": 10,
    "name": "My Instance",
    "slug": "my-instance-abc123",
    ...
  },
  "credentials": {
    "username": "admin",
    "password": "xK9#mP2!nL5@qR8*"
  }
}
```

## Testing

To test the implementation:
1. Create a new instance via the dashboard
2. Check the response for the generated credentials
3. Verify the docker-compose.yml has the correct password
4. Login to the Hermes instance using the generated credentials

## Notes

- Existing instances keep their current passwords (not automatically updated)
- Only new instances get random passwords
- Admin username can be customized via HERMES_ADMIN_USERNAME environment variable
- Passwords are returned in the API response and should be displayed to the user
