Skip to main content
The scripts install the Helm release agentos into the agentos namespace. Override with AGENTOS_RELEASE and AGENTOS_NAMESPACE.
The scripts use the active kubectl context and do not persist its name. Run kubectl config current-context before every lifecycle command and confirm the cluster. For a custom target, also export AGENTOS_RELEASE and AGENTOS_NAMESPACE in the shell before env-sync.sh, redeploy.sh, or down.sh. Those scripts resolve the release and namespace before reading an env file, or do not read one.

Manage

Production auth

Token-Based Authorization is on by default. Production startup requires JWT_VERIFICATION_KEY or a readable JWKS file at the pod path in JWT_JWKS_FILE; otherwise the process exits. Token-Based Auth gives you three things:
  1. Protected application routes. AgentOS routes require a valid token. The operational and documentation routes /, /health, /info, /docs, /redoc, /openapi.json, and /docs/oauth2-redirect remain public.
  2. Per-request identity. Middleware validates the token and exposes its user_id, optional session_id, scopes, and claims to the request.
  3. Scope-based permissions. Token scopes control access to AgentOS routes and resources.
The templates do not enable per-user data isolation. To scope non-admin session, memory, trace, and run access to the JWT subject, pass authorization_config=AuthorizationConfig(user_isolation=True) to AgentOS. See User Isolation. To opt out (not recommended), set authorization=False in app/main.py, then build and push a new image tag and roll to it with IMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh. Use this only inside a private VPC behind another auth layer. Without it, anyone who guesses your AgentOS URL can access your platform.

Customize

Ask your coding agent to run /create-new-agent, or do it by hand. Create agents/my_agent.py:
Register it in app/main.py:
Local containers hot-reload on save. For production, build and push a new image tag, then run IMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh. If the release still runs the official image, point it at your registry first: IMAGE_REPOSITORY=<registry>/agentos IMAGE_TAG=<tag> ./scripts/k8s/up.sh.
app/settings.py defines default_model(), used by every agent. Change it in one place:
Add anthropic to pyproject.toml, set the provider key in your env, and regenerate pins:
Rebuild locally with docker compose up -d --build. For production, build and push a new tag, then roll to it:
env-sync.sh uses a fixed allowlist that includes RUNTIME_ENV, AGENTOS_URL, the JWT_JWKS_FILE path, the template’s supported secrets, and DB_PASS. It does not deliver the referenced JWKS file or sync a new provider key such as ANTHROPIC_API_KEY. Provide the JWKS file through a custom image or chart volume. Deliver a new provider key via extraEnv and helm upgrade.
Agno ships 100+ toolkits. See Toolkits.
  1. Edit pyproject.toml.
  2. Regenerate pins: ./scripts/generate_requirements.sh (add upgrade to refresh every pin).
  3. Rebuild locally with docker compose up -d --build, or build and push a new tag and roll to it with IMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh.
Set both variables in your env file:
Sync with ./scripts/k8s/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.
The deployment check runs daily by default (ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.In the cluster these are chart values. Set them via extraEnv and helm upgrade; env-sync.sh does not sync ENABLE_DEPLOY_CHECK, ENABLE_SCHEDULED_EVALS, or EVALS_*.

Format, validate, and run evals

The format, validate, and eval scripts run on the host and need a venv. Set it up once:
./scripts/mcp_check.sh runs inside the container, so it needs no venv.

Environment variables

Troubleshooting

Install kubectl and Helm 3+. The scripts check for both before doing anything.
up.sh deploys into your current kubectl context and verifies it can reach the cluster first. Point kubectl at the target cluster and confirm kubectl get namespace works, then rerun.
Expected. Mint the key at os.agno.com: connect your OS (Connect OSLive, enter your AgentOS URL), then turn on Token-Based Authorization (JWT) under SettingsOS & Security and paste the full PEM. To add a PEM later, set JWT_VERIFICATION_KEY and run ./scripts/k8s/env-sync.sh. To use JWKS, first provide the file through a custom image or chart volume, then set JWT_JWKS_FILE to its pod path and sync.
JWT auth is on whenever RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY and sync. JWT_JWKS_FILE works only when a custom image or chart mount already provides a readable file at that pod path. To opt out inside a private VPC behind another auth layer, set authorization=False in app/main.py and roll out your own image build.
The cluster can’t pull the image. Confirm the tag was pushed and the cluster has access to your registry; for private registries, set imagePullSecrets in charts/agentos/values.yaml. On kind, kind load docker-image the tag and deploy with IMAGE_PULL_POLICY=Never.
The Postgres volume reads its password only on first initialization, so a lost or regenerated DB_PASS locks the app out of an existing volume. Restore the DB_PASS that up.sh saved to your env file and sync, fix the database in place with ALTER USER, or delete the PVC to reinitialize. Deleting the PVC deletes all data.
AGENTOS_URL resolves automatically: explicit value, then ingress URL, then in-cluster service DNS. If you set it by hand, make sure the pod can reach that URL, then run ./scripts/k8s/env-sync.sh.
up.sh generates MCP_CONNECT_SECRET only when the deploy has a public URL (INGRESS_HOST or an explicit AGENTOS_URL). Deployed without one? Set MCP_CONNECT_SECRET and a public AGENTOS_URL in .env.production and run ./scripts/k8s/env-sync.sh.