Skip to main content
The deploy scripts put everything in one resource group, agentos by default, and the container app is named agent-os. Override the group and region with AZURE_RESOURCE_GROUP and AZURE_LOCATION (default eastus). Start with Deploy AgentOS on Azure for prerequisites and the first deployment.

Manage

env-sync.sh turns secret-shaped keys (OPENAI_API_KEY, DB_PASS, JWT_VERIFICATION_KEY, MCP_CONNECT_SECRET, AGENTOS_MCP_SIGNING_KEY, PARALLEL_API_KEY, SLACK_*) into Container Apps secrets and everything else into plain env vars, then applies it all in one revision roll. It skips AZURE_* keys; those configure the scripts, not the app. The app is pinned to one replica (--min-replicas 1 --max-replicas 1). Min 1 keeps the service available for scheduled work and MCP streams. The template has been validated with this single-process topology. Validate schedule registration and MCP streams before changing the maximum.
Use a dedicated AZURE_RESOURCE_GROUP. down.sh deletes the entire selected group and every resource in it.

Production auth

Token-Based Authorization protects AgentOS routes by default in production. Startup requires JWT_VERIFICATION_KEY or a readable JWKS file at the container path in JWT_JWKS_FILE; otherwise the process exits. Token-Based Auth gives you three things:
  1. Protected API access. Requests to protected AgentOS routes require a valid token. /, /health, /info, /docs, /redoc, /openapi.json, and /docs/oauth2-redirect remain public.
  2. Per-request identity. Middleware validates the token and exposes its user_id, optional session_id, scopes, and claims to the request.
  3. Scope-based permissions. Token scopes control access to AgentOS routes and resources.
The templates do not enable per-user data isolation. To scope non-admin session, memory, trace, and run access to the JWT subject, pass authorization_config=AuthorizationConfig(user_isolation=True) to AgentOS. See User Isolation. To disable JWT authentication, set authorization=False in app/main.py, remove JWT_VERIFICATION_KEY and JWT_JWKS_FILE from the Container App, and redeploy. authorization=False disables AgentOS scope enforcement. Configured JWT environment variables continue to enable JWT validation. MCP OAuth remains active when MCP_CONNECT_SECRET is set. Only do this when another layer protects the service.

Customize

Ask your coding agent to run /create-new-agent, or do it by hand. Create agents/my_agent.py:
Register it in app/main.py:
Local containers hot-reload on save. For production, run ./scripts/azure/redeploy.sh.
app/settings.py defines default_model(), used by every agent. Change it in one place:
Add anthropic to pyproject.toml. Set ANTHROPIC_API_KEY in .env for local runs and .env.production for production, then regenerate pins:
Before production sync, add ANTHROPIC_API_KEY to the is_secret_key() allowlist in scripts/azure/env-sync.sh. This stores the key as a Container Apps secret. Then rebuild and deploy:
Agno ships 100+ toolkits. See Toolkits.
  1. Edit pyproject.toml.
  2. Regenerate pins: ./scripts/generate_requirements.sh (add upgrade to refresh every pin).
  3. Rebuild locally with docker compose up -d --build, or redeploy with ./scripts/azure/redeploy.sh.
Set both variables in your env file:
Sync with ./scripts/azure/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.
The deployment check runs daily by default (ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.

Format, validate, and run evals

The format, validate, and eval scripts run on the host and need a venv. Set it up once:
./scripts/mcp_check.sh runs inside the container, so it needs no venv.

Environment variables

up.sh also generates DB_PASS once and saves it to your env file. Don’t regenerate it; the server keeps the first password, and a new one would lock the app out.

Troubleshooting

Install the Azure CLI, then run az login.
The image is built locally and pushed to your registry, so both scripts need Docker running. Start Docker Desktop and retry.
Expected. Mint the key at os.agno.com: connect your OS (Connect OSLive, enter your Container Apps URL), then turn on Token-Based Authorization (JWT) under SettingsOS & Security and paste the full PEM. To add a PEM later, set JWT_VERIFICATION_KEY and run ./scripts/azure/env-sync.sh. To use JWKS, add the file to the image build context and rebuild, or configure a mount. Set JWT_JWKS_FILE to its container path, then redeploy or roll the service. Env sync alone only updates the path.
AgentOS scope enforcement is on whenever RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY and sync. For JWKS, verify the file exists inside the container at JWT_JWKS_FILE; changing the variable alone does not deliver it. To disable JWT, set authorization=False in app/main.py, remove both JWT variables from the Container App, and redeploy. MCP OAuth remains active when MCP_CONNECT_SECRET is set.
The revision is still converging. Wait a couple of minutes and check az containerapp logs show -g "${AZURE_RESOURCE_GROUP:-agentos}" -n agent-os --follow.
Run it again. The generated names (AZURE_ACR_NAME, AZURE_PG_NAME) and DB_PASS persist in your env file, so re-runs use the same registry and Postgres server.
AGENTOS_URL is still the localhost default. up.sh sets it to your Container Apps URL automatically; for a custom domain or tunnel, set it by hand and run ./scripts/azure/env-sync.sh.