agentos into the agentos namespace. Override with AGENTOS_RELEASE and AGENTOS_NAMESPACE.
Manage
Production auth
Token-Based Authorization is on by default. Without aJWT_VERIFICATION_KEY or JWT_JWKS_FILE, the app refuses to serve traffic in production. The platform’s job is to keep your data private, so the safe default is refuse to start.
Token-Based Auth gives you three things:
- No public access. The server rejects requests without a valid token.
- Per-request identity. Middleware parses the token and extracts the
user_id,session_id, and custom claims. Each request is tied to a user and session, giving you auditability and traceability. - Granular permissions. User tokens can run an agent and view their own sessions. Admin tokens read everyone’s sessions and test any agent.
authorization=False in app/main.py, then build and push a new image tag and roll to it with IMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh. Use this only inside a private VPC behind another auth layer. Without it, anyone who guesses your AgentOS URL can access your platform.
Customize
Add an agent
Add an agent
Ask your coding agent to run Register it in Local containers hot-reload on save. For production, build and push a new image tag, then run
/create-new-agent, or do it by hand. Create agents/my_agent.py:app/main.py:IMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh. If the release still runs the official image, point it at your registry first: IMAGE_REPOSITORY=<registry>/agentos IMAGE_TAG=<tag> ./scripts/k8s/up.sh.Change the model
Change the model
app/settings.py defines default_model(), used by every agent. Change it in one place:anthropic to pyproject.toml, set the provider key in your env, and regenerate pins:docker compose up -d --build. For production:Add tools
Add tools
Agno ships 100+ toolkits. See Toolkits.
Add dependencies
Add dependencies
- Edit
pyproject.toml. - Regenerate pins:
./scripts/generate_requirements.sh(addupgradeto refresh every pin). - Rebuild locally with
docker compose up -d --build, or build and push a new tag and roll to it withIMAGE_TAG=<tag> ./scripts/k8s/redeploy.sh.
Enable Slack
Enable Slack
Set both variables in your env file:Sync with
./scripts/k8s/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.Toggle scheduled workflows
Toggle scheduled workflows
The deployment check runs daily by default (
ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.In the cluster these are chart values. Set them via extraEnv and helm upgrade; ./scripts/k8s/env-sync.sh syncs only the connection and secret keys.Format, validate, and run evals
The format, validate, and eval scripts run on the host and need a venv. Set it up once:./scripts/mcp_check.sh runs inside the container, so it needs no venv.
Environment variables
Troubleshooting
kubectl or helm: command not found
kubectl or helm: command not found
up.sh exits: no context or cluster not reachable
up.sh exits: no context or cluster not reachable
up.sh deploys into your current kubectl context and verifies it can reach the cluster first. Point kubectl at the target cluster and confirm kubectl get namespace works, then rerun.up.sh pauses asking for a JWT key
up.sh pauses asking for a JWT key
Expected. Mint the key at os.agno.com: connect your OS (Connect OS → Live, enter your AgentOS URL), then turn on Token-Based Authorization (JWT) under Settings → OS & Security and paste the full PEM. To do it later, skip the prompt, add
JWT_VERIFICATION_KEY or JWT_JWKS_FILE to .env.production, and run ./scripts/k8s/env-sync.sh.App refuses to serve in production
App refuses to serve in production
JWT auth is on whenever
RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY or JWT_JWKS_FILE and sync. To opt out inside a private VPC behind another auth layer, set authorization=False in app/main.py and roll out your own image build.Pods stuck in ImagePullBackOff
Pods stuck in ImagePullBackOff
The cluster can’t pull the image. Confirm the tag was pushed and the cluster has access to your registry; for private registries, set
imagePullSecrets in charts/agentos/values.yaml. On kind, kind load docker-image the tag and deploy with IMAGE_PULL_POLICY=Never.Database rejects the app after a password change
Database rejects the app after a password change
The Postgres volume reads its password only on first initialization, so a lost or regenerated
DB_PASS locks the app out of an existing volume. Restore the DB_PASS that up.sh saved to your env file and sync, fix the database in place with ALTER USER, or delete the PVC to reinitialize. Deleting the PVC deletes all data.Scheduled jobs never fire
Scheduled jobs never fire
AGENTOS_URL resolves automatically: explicit value, then ingress URL, then in-cluster service DNS. If you set it by hand, make sure the pod can reach that URL, then run ./scripts/k8s/env-sync.sh.claude.ai or ChatGPT can't connect to /mcp
claude.ai or ChatGPT can't connect to /mcp
up.sh generates MCP_CONNECT_SECRET only when the deploy has a public URL (INGRESS_HOST or an explicit AGENTOS_URL). Deployed without one? Set MCP_CONNECT_SECRET and a public AGENTOS_URL in .env.production and run ./scripts/k8s/env-sync.sh.