Steel Browser vs Camoufox

Purpose

Compare the two browser-automation backends available to Hermes, including the Jul 29–30 experiment and the decision to revert.

At a glance

Steel Browser (CT201)Camoufox (CT450)
In useDisabled since 2026-07-30Yes — primary backend
EngineChromium 140 (Playwright)Camoufox (Firefox-based)
ConnectionCDP (ws:// via port 9223)REST API (localhost:9093)
APIREST at :3000 — create/destroy/query sessionsCamoufox REST + CDP WebSocket
HeadlessNative headlessXvfb + VNC (headed, anti-fingerprint)
ContainerDocker on CT201Systemd service on CT450
StealthStandard ChromiumAnti-detection fingerprinting
Session viewerBuilt-in UI at /steelVNC at /vnc-camofox
Pluginbrowser-steel plugin (disabled)Native Hermes browser.cloud_provider: camofox

The Steel Experiment (Jul 29–30)

Why it was tried

  • Steel promised full CDP access for richer browser control
  • Built-in session viewer and management UI
  • Docker-based, clean separation from Hermes host

Timeline

  1. Jul 29: Steel deployed on CT201 via Docker Compose, Chromium 140. Hermes configured with browser.cloud_provider: steel, browser-steel plugin enabled.
  2. Jul 29 (later): CDP connectivity issues surfaced — Hermes was reaching 0.0.0.0 from the plugin’s internal CDP URL. Required _normalize_cdp_url() patch in the Steel plugin to remap to 100.96.244.39.
  3. Jul 30: DeepSeek V4 Flash 0731 went live and rejected tool names that didn’t match ^[a-zA-Z0-9_-]+$. The Steel plugin’s tools (steel_scrape, steel_session_options) were fine, but the route through OmniRoute → Steel → CDP was unreliable with empty-stream errors.
  4. Jul 30 (evening): Decision to revert — Camoufox re-enabled, browser-steel plugin disabled, CAMOFOX_URL and CAMOFOX_API_KEY uncommented in .env. Steel left running on CT201 but Hermes no longer routes through it.

What broke

  • CDP URL normalization required a plugin patch to handle Docker’s internal networking
  • Empty-stream errors from opencode-go/deepseek-v4-flash provider path — the combo strategy does NOT iterate on empty responses, they pass to Hermes’s own fallback chain (the #1 cause of “combo works but Hermes falls back”)
  • Tool name validation on DeepSeek 0731 was stricter — this affected all providers, not just Steel

Lesson learned

Steel is a capable backend but adds a network hop and another plugin layer. Camoufox runs locally on CT450 with fewer failure modes. The browser-steel plugin still exists (disabled) if needed in future.

Detail

Camoufox (current primary)

  • Deployed: Persistent systemd service on CT450
  • Connection: REST API at localhost:9093, profile anthony, sessionKey anthony
  • Key advantage: Runs on the same host as Hermes — no network hop, no container networking to debug
  • Auth: Already authenticated into services (Uber Eats, LinkedIn, etc.) — no cookie files needed
  • Limitation: Headed via Xvfb, consumes display resources

Steel Browser (disabled but available)

  • Deployed: 2026-07-29 on CT201, Docker, custom steel-browser-api:fixed image
  • Status: Still running on CT201, Hermes not connected
  • CDP endpoint: http://100.96.244.39:9223
  • REST API: http://100.96.244.39:3000
  • UI: https://runtipi.kangaroo-eel.ts.net/steel
  • Plugin: browser-steel at /home/hermes/.hermes/plugins/browser-steel/ — disabled, plugin_steel toolset flagged requires_health=steel