Skip to main content
The Cloud Run service is agent-os, the Cloud SQL instance is agentos-db, and the Artifact Registry repo is agentos. The scripts target the current gcloud project and us-central1; override them with GCP_PROJECT_ID and GCP_REGION. Start with Deploy AgentOS on Google Cloud for prerequisites and the first deployment. Export overrides before running direct gcloud commands; the template scripts also read them from the selected env file.

Manage

up.sh sets one minimum instance and no maximum. Cloud Run can add instances under load. AgentOS claims due schedules through PostgreSQL. Simultaneous schedule registration and long-lived MCP streams still need validation. Add --max-instances 1 to the Cloud Run deploy command when you need a single-process topology.

Production auth

Token-Based Authorization protects AgentOS routes by default in production. Startup requires JWT_VERIFICATION_KEY or a readable JWKS file at the container path in JWT_JWKS_FILE; otherwise the process exits. Token-Based Auth gives you three things:
  1. Protected API access. Requests to protected AgentOS routes require a valid token. /, /health, /info, /docs, /redoc, /openapi.json, and /docs/oauth2-redirect remain public.
  2. Per-request identity. Middleware validates the token and exposes its user_id, optional session_id, scopes, and claims to the request.
  3. Scope-based permissions. Token scopes control access to AgentOS routes and resources.
The templates do not enable per-user data isolation. To scope non-admin session, memory, trace, and run access to the JWT subject, pass authorization_config=AuthorizationConfig(user_isolation=True) to AgentOS. See User Isolation. To disable JWT authentication, set authorization=False in app/main.py, remove JWT_VERIFICATION_KEY and JWT_JWKS_FILE from the Cloud Run service, and redeploy. authorization=False disables AgentOS scope enforcement. Configured JWT environment variables continue to enable JWT validation. MCP OAuth remains active when MCP_CONNECT_SECRET is set. Only do this when another layer protects the service.

Customize

Ask your coding agent to run /create-new-agent, or do it by hand. Create agents/my_agent.py:
Register it in app/main.py:
Local containers hot-reload on save. For production, run ./scripts/gcp/redeploy.sh.
app/settings.py defines default_model(), used by every agent. Change it in one place:
Add anthropic to pyproject.toml. Set ANTHROPIC_API_KEY in .env for local runs and .env.production for production, then regenerate pins:
Before production sync, add ANTHROPIC_API_KEY to the is_secret_key() allowlist in scripts/gcp/env-sync.sh. This stores the key in Secret Manager. Then rebuild and deploy:
Agno ships 100+ toolkits. See Toolkits.
  1. Edit pyproject.toml.
  2. Regenerate pins: ./scripts/generate_requirements.sh (add upgrade to refresh every pin).
  3. Rebuild locally with docker compose up -d --build, or redeploy with ./scripts/gcp/redeploy.sh.
Set both variables in your env file:
Sync with ./scripts/gcp/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.
The deployment check runs daily by default (ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.

Format, validate, and run evals

The format, validate, and eval scripts run on the host and need a venv. Set it up once:
./scripts/mcp_check.sh runs inside the container, so it needs no venv.

Environment variables

Troubleshooting

Install the Google Cloud SDK, then run gcloud auth login and gcloud config set project <id>.
Expected. The script deploys first because Cloud Run only reveals the URL once the service exists, then pauses so you can mint the key against it. Mint the key at os.agno.com: connect your OS (Connect OSLive, enter your Cloud Run URL), then turn on Token-Based Authorization (JWT) under SettingsOS & Security and paste the full PEM. To add a PEM later, set JWT_VERIFICATION_KEY in .env.production and run ./scripts/gcp/env-sync.sh. To use JWT_JWKS_FILE, add the file to the image build context and run ./scripts/gcp/redeploy.sh, or configure a mount. Then add the container path to .env.production and run ./scripts/gcp/env-sync.sh. The scripts do not upload or mount the file.
AgentOS scope enforcement is on whenever RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY and sync. For JWKS, add the file to the image build context and run ./scripts/gcp/redeploy.sh, or configure a mount. Then set JWT_JWKS_FILE to its container path in .env.production and run ./scripts/gcp/env-sync.sh. To disable JWT, set authorization=False in app/main.py, remove both JWT variables from the Cloud Run service, and redeploy. MCP OAuth remains active when MCP_CONNECT_SECRET is set.
Your organization likely enforces Domain Restricted Sharing (constraints/iam.allowedPolicyMemberDomains), which silently rejects the allUsers binding that --allow-unauthenticated needs. The deploy still succeeds; the service just ships private. up.sh prints a warning when it detects this. Grant roles/run.invoker to specific principals, or ask an org admin for an allUsers exception.
Check that billing is enabled on the project. up.sh warns when it can’t confirm billing. Cloud SQL and Cloud Run creation require billing.
AGENTOS_URL is still the localhost default. up.sh sets it to your Cloud Run URL automatically; for a custom domain or tunnel, set it by hand and run ./scripts/gcp/env-sync.sh.
down.sh is targeting a different region than the one you deployed to. up.sh records GCP_REGION in your env file and down.sh reads it from there; if the file is gone, rerun with GCP_REGION=<region> ./scripts/gcp/down.sh. A wrong-region teardown looks clean while the real resources keep billing.