# Golem's compose file exposes noVNC on every interface with an empty password

> Project Golem is a JavaScript AI workbench with a Next.js dashboard, long-term memory, and Telegram and Discord bridges. Its shipped Docker defaults contradict its own remote-access advice, and its version number appears three different ways.

**Arvincreator/project-golem** — OS-level autonomous AI agent with long-term memory, multi-agent coordination, Titan Chronos scheduler & Moltbot Social Core

- Repository: https://github.com/Arvincreator/project-golem
- Stars: 639 · Forks: 106
- Language: JavaScript
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/arvincreator-project-golem

## The version number appears three different ways

Three statements about the version sit in three files and none of them agrees with the others. The package manifest reads 9.7.9. That same manifest's description field says Project Golem v9.5, Ultimate Chronos plus MultiAgent Edition, two minor versions behind its own version field. The newest release tag is v9.6.14, published on 18 May 2026, so the manifest version sits ahead of the last tag rather than behind it. The tags are also inconsistent about their own prefix: v9.6.14 carries a lowercase v while V9.6.12 and V9.6.6 carry a capital one, so anything that sorts releases by tag or expects a leading v has to handle both spellings. The last push is dated 22 June 2026 and the repository is not archived.

## The licence is source-available and explicitly non-commercial

The licence is where this repository is most careful and most likely to be misread. The readme states that the project uses a Source-Available Non-Commercial licence and points at two files in the root, LICENSE and COMMERCIAL-LICENSE.md. The package manifest agrees in a machine-readable way, setting the license field to LicenseRef-Project-Golem-NonCommercial rather than a standard SPDX identifier, which is why the licence shows up as unrecognised on the hosting site. That is a custom licence rather than an OSI-approved one, so nothing here can be assumed reusable by default and commercial use needs the second file. The manifest's author field and the readme's sign-off both name one person, Arvin Chen, and the repository also carries CLA.md, CODE_OF_CONDUCT.md, and a NOTICE file.

## noVNC binds to every interface with an empty password

The container configuration and the security advice do not agree. The compose file ships a run of defaults: the VNC port defaults to 5900, the noVNC port defaults to 6080, the noVNC bind address defaults to 0.0.0.0, and the VNC password defaults to an empty string:

```
GOLEM_VNC_PORT=${GOLEM_VNC_PORT:-5900}
GOLEM_NOVNC_PORT=${GOLEM_NOVNC_PORT:-6080}
GOLEM_NOVNC_BIND=${GOLEM_NOVNC_BIND:-0.0.0.0}
```

A noVNC endpoint bound to every interface with no password is the out-of-the-box state of the shipped file. The readme's remote-access guidance says the opposite: to open remote access you must set a strong password, set a token, and pair it with a firewall or a VPN. The knobs it expects do exist in the example configuration:

```
ALLOW_REMOTE_ACCESS=false
REMOTE_ACCESS_PASSWORD=
SYSTEM_OP_TOKEN=
```

The default keeps remote access off, so the safe arrangement depends on editing values rather than on leaving them alone.

## The runner image copies the builder's dev dependencies

The Dockerfile is three stages built on Playwright's own Ubuntu 24.04 image, pinned at v1.50.0-noble, with xvfb, fluxbox, x11vnc, novnc, and websockify layered on so the Gemini browser session has a display to draw into even when no window is visible. The builder stage installs the root dependencies with no environment restriction, downloads Chromium through npx playwright install, then copies the dashboard's package files and installs those with NODE_ENV=development. The runner stage then copies node_modules wholesale from the builder, both the root tree and the dashboard's, with an inline comment explaining that it is to ensure binary compatibility against GLIBC. Copying development-installed trees into the final image is how the Playwright binary stays loadable, and it is also why the production image carries development dependencies that nothing at runtime imports.

## The first Gemini login has to happen with a visible browser

The example configuration is unusually candid about a chicken-and-egg problem. The headless switch makes Playwright run the browser entirely in the background with no window, and the file warns that first use of Gemini must log into a Google account and clear a CAPTCHA, so the switch has to be left empty on the first launch and only set to true once the golem_memory directory holds a login record. The honest ordering is interactive once and silent afterwards. Two neighbouring variables decide where that browser session lives:

```
GOLEM_TEST_MODE=false
PLAYWRIGHT_PROFILE=
USER_DATA_DIR=
```

PLAYWRIGHT_PROFILE takes a simple label such as default, work, or personal, and falls back to ./golem_memory when it is empty. USER_DATA_DIR overrides that path entirely when set. GOLEM_TEST_MODE is the third lever, and setting it true means only checking that the code can run, without opening a browser at all.

## Telegram has two engines and a breaker with three thresholds

The messaging configuration is the densest part of the example environment file. The Telegram engine is chosen by TG_ENGINE, which takes grammy or legacy; the recommendation is grammy because of its circuit breaker and guard behaviour, with legacy as the downgrade when compatibility breaks. That breaker has three thresholds of its own:

```
TG_ENGINE=grammy
CB_TG_TIMEOUT_MS=10000
CB_TG_RESET_MS=15000
CB_TG_ERROR_PCT=30
```

A polling loop that trips an error-rate threshold disconnects instead of hammering a failing endpoint, and the reset interval decides when it retries. Access control is kept separate from credentials: TG_AUTH_MODE is ADMIN or CHAT, meaning answer only administrators or answer everyone in the group, and it is paired with ADMIN_ID and TG_CHAT_ID. Discord has its own token and administrator id, and the whole bridge layer is optional in both directions.

## Three backends, three env blocks, two memory modes

The backend choice is a single variable with three accepted values, and each one brings its own block of addresses and model names. Gemini is the default and is driven through a browser rather than an API. Ollama points at a local server:

```
GOLEM_BACKEND=ollama
GOLEM_OLLAMA_BASE_URL=http://127.0.0.1:11434
GOLEM_OLLAMA_BRAIN_MODEL=llama3.1:8b
```

The Ollama block also sets the embedding provider to ollama and names nomic-embed-text as the embedding model, which puts retrieval and reasoning on the same local server. LM Studio instead points at its OpenAI-compatible endpoint on port 1234, names the brain model local-model, and ships an empty API key. Memory has its own switch, GOLEM_MEMORY_MODE, accepting lancedb-pro or native, with summary compression and a retrieval flow on top. The default example pairs gemini with lancedb-pro and turns Playwright stealth on.

## Two compatibility entry points sit at the root

The layout keeps two shims for callers that predate the current structure. index.js is the manifest's main entry and is described as a compatibility shim that hands off to apps/runtime, while dashboard.js does the same for the dashboard start path. Behind them sit apps/ with a runtime core and a dashboard plugin layer, src/ for the brain, manager, services, and bridges, web-dashboard/ as the Next.js front end, and packages/ for the shared memory, protocol, and security modules. The dashboard exposes eighteen routes under /dashboard, from the unified console and chat through diary, persona, prompt pool, prompt trends, stocks, calendar, the text RPG, skills, MCP, an action gate for approving risky operations, agents, office, memory, a memory firewall, reference files, and settings. It listens on port 3000 by default.

## Conclusion

Project Golem is worth reading if you want a single dashboard covering chat, memory, skills, MCP servers, stocks, and a calendar, with the choice of a browser-driven Gemini session or a local Ollama or LM Studio model. It is not a fit for commercial use without reading COMMERCIAL-LICENSE.md, since the licence is explicitly non-commercial, and it is not a fit to deploy on a public host without editing the compose file. Before exposing anything, set the VNC password and the noVNC bind address, set SYSTEM_OP_TOKEN, keep ALLOW_REMOTE_ACCESS false, and decide whether to accept dev dependencies in the production image.

## FAQ

### What is Project Golem?

It is a JavaScript AI work system rather than a chat bot, with a Next.js dashboard at localhost:3000 covering chat, long-term memory, skills, MCP servers, stocks, a calendar, and a text RPG. It can also bridge out to Telegram and Discord.

### What does Project Golem need in order to run?

Node.js from version 20 up to but not including 23, npm, and Chromium or Google Chrome for Gemini Web mode. Installation runs ./setup.sh from the project folder, which then offers an install or launch menu once you press Enter.

### Which language backends can Project Golem use?

Three, chosen with GOLEM_BACKEND: gemini, ollama, or lmstudio. The Ollama block points at http://127.0.0.1:11434 with llama3.1:8b as the brain model and nomic-embed-text for embeddings, and LM Studio uses its OpenAI-compatible endpoint on port 1234.

### Is Project Golem open source?

It uses a Source-Available Non-Commercial licence, with LICENSE and COMMERCIAL-LICENSE.md in the repository root. The package manifest records LicenseRef-Project-Golem-NonCommercial rather than a standard SPDX identifier, so the hosting site reports no recognised licence.

### How do you deploy Project Golem?

Run it directly on Node.js for local use, or with docker compose up -d --build for a server. The compose file maps port 3000, mounts golem_memory and logs, mounts .env read-only, and defaults the noVNC port to 6080 with a bind address of 0.0.0.0 and an empty VNC password.

## Sources

- [Arvincreator/project-golem on GitHub](https://github.com/Arvincreator/project-golem)
- [Issues](https://github.com/Arvincreator/project-golem/issues)
- [README](https://github.com/Arvincreator/project-golem/blob/main/README.md)
- [Releases](https://github.com/Arvincreator/project-golem/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/arvincreator-project-golem
