agentos by default, and the container app is named agent-os. Override the group and region with AZURE_RESOURCE_GROUP and AZURE_LOCATION (default eastus).
Manage
env-sync.sh turns secret-shaped keys (OPENAI_API_KEY, DB_PASS, JWT_VERIFICATION_KEY, MCP_CONNECT_SECRET, AGENTOS_MCP_SIGNING_KEY, PARALLEL_API_KEY, SLACK_*) into Container Apps secrets and everything else into plain env vars, then applies it all in one revision roll. It skips AZURE_* keys; those configure the scripts, not the app.
The app is pinned to one replica (--min-replicas 1 --max-replicas 1). Min 1 keeps the in-process scheduler and MCP streams alive; max 1 stops Azure from running two schedulers. Leave both pins in place.
Production auth
Token-Based Authorization is on by default. Production startup requiresJWT_VERIFICATION_KEY or a readable JWKS file at the container path in JWT_JWKS_FILE; otherwise the process exits.
Token-Based Auth gives you three things:
- No public access. The server rejects requests without a valid token.
- Per-request identity. Middleware validates the token and exposes its
user_id, optionalsession_id, scopes, and claims to the request. - Scope-based permissions. Token scopes control access to AgentOS routes and resources.
authorization_config=AuthorizationConfig(user_isolation=True) to AgentOS. See User Isolation.
To opt out (not recommended), set authorization=False in app/main.py and redeploy. Use this only inside a private VPC behind another auth layer. Without it, anyone who guesses your Container Apps domain can access your platform.
Customize
Add an agent
Add an agent
Ask your coding agent to run Register it in Local containers hot-reload on save. For production, run
/create-new-agent, or do it by hand. Create agents/my_agent.py:app/main.py:./scripts/azure/redeploy.sh.Change the model
Change the model
app/settings.py defines default_model(), used by every agent. Change it in one place:anthropic to pyproject.toml, set the provider key in your env, and regenerate pins:docker compose up -d --build. For production:Add tools
Add tools
Agno ships 100+ toolkits. See Toolkits.
Add dependencies
Add dependencies
- Edit
pyproject.toml. - Regenerate pins:
./scripts/generate_requirements.sh(addupgradeto refresh every pin). - Rebuild locally with
docker compose up -d --build, or redeploy with./scripts/azure/redeploy.sh.
Enable Slack
Enable Slack
Set both variables in your env file:Sync with
./scripts/azure/env-sync.sh. The interface activates automatically and routes messages to Agent Builder; change the agent= argument in app/main.py to point at another agent. See Slack setup.Toggle scheduled workflows
Toggle scheduled workflows
The deployment check runs daily by default (
ENABLE_DEPLOY_CHECK=True); it is deterministic and free. Scheduled evals are off by default (ENABLE_SCHEDULED_EVALS=False) because they use model calls. Both workflows stay runnable on demand regardless.Format, validate, and run evals
The format, validate, and eval scripts run on the host and need a venv. Set it up once:./scripts/mcp_check.sh runs inside the container, so it needs no venv.
Environment variables
up.sh also generates DB_PASS once and saves it to your env file. Don’t regenerate it; the server keeps the first password, and a new one would lock the app out.
Troubleshooting
az: command not found
az: command not found
Install the Azure CLI, then run
az login.up.sh or redeploy.sh says Docker is required
up.sh or redeploy.sh says Docker is required
The image is built locally and pushed to your registry, so both scripts need Docker running. Start Docker Desktop and retry.
up.sh pauses asking for a JWT key
up.sh pauses asking for a JWT key
Expected. Mint the key at os.agno.com: connect your OS (Connect OS → Live, enter your Container Apps URL), then turn on Token-Based Authorization (JWT) under Settings → OS & Security and paste the full PEM. To add a PEM later, set
JWT_VERIFICATION_KEY and run ./scripts/azure/env-sync.sh. To use JWKS, add the file to the image build context and rebuild, or configure a mount. Set JWT_JWKS_FILE to its container path, then redeploy or roll the service. Env sync alone only updates the path.App fails to start in production
App fails to start in production
JWT auth is on whenever
RUNTIME_ENV is not dev. Set JWT_VERIFICATION_KEY and sync. For JWKS, verify the file exists inside the container at JWT_JWKS_FILE; changing the variable alone does not deliver it. To opt out inside a private VPC behind another auth layer, set authorization=False in app/main.py.Nothing at the app URL right after deploy
Nothing at the app URL right after deploy
The revision is still converging. Wait a couple of minutes and check
az containerapp logs show -g agentos -n agent-os --follow.up.sh failed partway through
up.sh failed partway through
Run it again. The generated names (
AZURE_ACR_NAME, AZURE_PG_NAME) and DB_PASS persist in your env file, so re-runs reuse the same registry and Postgres server instead of minting new ones.Scheduled jobs never fire
Scheduled jobs never fire
AGENTOS_URL is still the localhost default. up.sh sets it to your Container Apps URL automatically; for a custom domain or tunnel, set it by hand and run ./scripts/azure/env-sync.sh.