Skip to main content
The deploy scripts put everything in one resource group, agentos by default, and the container app is named agent-os. Override the group and region with AZURE_RESOURCE_GROUP and AZURE_LOCATION (default eastus).

Manage

env-sync.sh turns secret-shaped keys (OPENAI_API_KEY, DB_PASS, JWT_VERIFICATION_KEY, MCP_CONNECT_SECRET, AGENTOS_MCP_SIGNING_KEY, PARALLEL_API_KEY, SLACK_*) into Container Apps secrets and everything else into plain env vars, then applies it all in one revision roll. It skips AZURE_* keys; those configure the scripts, not the app. The app is pinned to one replica (--min-replicas 1 --max-replicas 1). Min 1 keeps the in-process scheduler and MCP streams alive; max 1 stops Azure from running two schedulers. Leave both pins in place.

Production auth

Token-Based Authorization is on by default. Without a JWT_VERIFICATION_KEY or JWT_JWKS_FILE, the app refuses to serve traffic in production. The platform’s job is to keep your data private, so the safe default is refuse to start. Token-Based Auth gives you three things:
  1. No public access. The server rejects requests without a valid token.
  2. Per-request identity. Middleware parses the token and extracts the user_id, session_id, and custom claims. Each request is tied to a user and session, giving you auditability and traceability.
  3. Granular permissions. User tokens can run an agent and view their own sessions. Admin tokens read everyone’s sessions and test any agent.
To opt out (not recommended), set authorization=False in app/main.py and redeploy. Use this only inside a private VPC behind another auth layer. Without it, anyone who guesses your Container Apps domain can access your platform.

Customize

Ask your coding agent to run /create-new-agent, or do it by hand. Create agents/my_agent.py:
Register it in app/main.py:
Local containers hot-reload on save. For production, run ./scripts/azure/redeploy.sh.
app/settings.py defines default_model(), used by every agent. Change it in one place:
Add anthropic to pyproject.toml, set the provider key in your env, and regenerate pins:
Rebuild locally with docker compose up -d --build. For production:
Agno ships 100+ toolkits. See Toolkits.
  1. Edit pyproject.toml.
  2. Regenerate pins: ./scripts/generate_requirements.sh (add upgrade to refresh every pin).
  3. Rebuild locally with docker compose up -d --build, or redeploy with ./scripts/azure/redeploy.sh.
Set both variables in your env file:
Sync with ./scripts/azure/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.
The deployment check runs daily by default (ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.

Format, validate, and run evals

The format, validate, and eval scripts run on the host and need a venv. Set it up once:
./scripts/mcp_check.sh runs inside the container, so it needs no venv.

Environment variables

up.sh also generates DB_PASS once and saves it to your env file. Don’t regenerate it; the server keeps the first password, and a new one would lock the app out.

Troubleshooting

Install the Azure CLI, then run az login.
The image is built locally and pushed to your registry, so both scripts need Docker running. Start Docker Desktop and retry.
Expected. Mint the key at os.agno.com: connect your OS (Connect OSLive, enter your Container Apps URL), then turn on Token-Based Authorization (JWT) under SettingsOS & Security and paste the full PEM. To do it later, skip the prompt, add JWT_VERIFICATION_KEY or JWT_JWKS_FILE to .env.production, and run ./scripts/azure/env-sync.sh.
JWT auth is on whenever RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY or JWT_JWKS_FILE and sync. To opt out inside a private VPC behind another auth layer, set authorization=False in app/main.py.
The revision is still converging. Wait a couple of minutes and check az containerapp logs show -g agentos -n agent-os --follow.
Run it again. The generated names (AZURE_ACR_NAME, AZURE_PG_NAME) and DB_PASS persist in your env file, so re-runs reuse the same registry and Postgres server instead of minting new ones.
AGENTOS_URL is still the localhost default. up.sh sets it to your Container Apps URL automatically; for a custom domain or tunnel, set it by hand and run ./scripts/azure/env-sync.sh.