# AgentOS on Azure Container Apps (/deploy/templates/azure/deploy)



**The [agentos-azure](https://github.com/agno-agi/agentos-azure) template is for teams that develop locally with Docker and deploy to production on Azure Container Apps.**

It includes:

* **Agno**, the team that coordinates platform work, also exposed as the `agno` MCP tool.
* **Platform Builder**, which creates and updates agents, teams, and workflows through the runtime.
* **Platform Manager**, which inspects the platform, eval history, deployment checks, and schedules.
* **Platform Engineer**, which inspects the project’s source code.
* **Eight [skills](/deploy/coding-agents)** for setting up, building, testing, reviewing, and deploying the project with a coding agent.

Coding agents can use these skills with the AgentOS API, evals, traces, and container logs to inspect and improve the platform.

Everything runs in your own Azure subscription, and one script provisions the network, database, registry, and app into a single resource group.

## Get started [#get-started]

Copy the prompt below into Claude Code, Cursor, or Codex to configure and run the template with a coding agent.

```txt
Help me set up my agent platform and build my first agent.

Clone https://github.com/agno-agi/agentos-azure into a folder called agent-platform, cd in, and run the setup-platform skill (in .agents/skills/).
```

Prefer to drive yourself? Follow the manual steps below.

## Manual setup [#manual-setup]

**Prerequisites:** [Docker](https://www.docker.com/get-started/) installed and running. An [OpenAI API key](https://platform.openai.com).

<Steps>
  <Step title="Clone and configure">
    ```bash
    git clone https://github.com/agno-agi/agentos-azure.git agentos
    cd agentos

    cp example.env .env
    ```

    Edit `.env` and set `OPENAI_API_KEY`.
  </Step>

  <Step title="Start the platform">
    ```bash
    docker compose up -d --build
    ```

    The first build takes a few minutes. Confirm the API is available at [localhost:8000/docs](http://localhost:8000/docs).
  </Step>

  <Step title="Verify end to end">
    ```bash
    ./scripts/mcp_check.sh
    ```

    Prints `MCP OK` with the tool count and a real agent answer through the MCP endpoint.
  </Step>

  <Step title="Connect the AgentOS UI">
    1. Open [os.agno.com](https://os.agno.com) and sign in.
    2. Click **Connect OS**, enter `http://localhost:8000`, and name it **Local AgentOS**.
  </Step>

  <Step title="Build your first agent">
    1. Chat with **Platform Builder**: "Build an agent that tracks AI news and writes a daily brief". Go through the agent development process.
    2. Once created, click **Refresh** on the top right, pick the new agent from the **Agents** dropdown, and ask: "What's new with Anthropic?"
    3. Ask **Platform Manager**: "How healthy is the platform?" It answers from eval history, deployment checks, schedules, and the agent you just built.
  </Step>
</Steps>

<Check>
  At this point, your AgentOS is running locally.
</Check>

## Connect your frontends [#connect-your-frontends]

| Frontend                    | How                                                                                                                                                                                                                       |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| MCP clients on your machine | `uvx agno connect` auto-detects Claude Code, Claude Desktop, Codex, and Cursor and registers `http://localhost:8000/mcp`. Verify from the app: "can you access my agentos mcp?"                                           |
| AgentOS UI                  | [os.agno.com](https://os.agno.com) → **Connect OS** → `http://localhost:8000`.                                                                                                                                            |
| claude.ai and ChatGPT       | Hosted sessions can't reach localhost. Deploy to production first, then add `https://<container-app-domain>/mcp` as a custom connector and approve the consent page with the `MCP_CONNECT_SECRET` that `up.sh` generates. |
| Slack                       | Set `SLACK_BOT_TOKEN` and `SLACK_SIGNING_SECRET`. See [Slack setup](/agent-os/interfaces/slack/setup).                                                                                                                    |
| Your product                | Call the AgentOS REST API with 80+ endpoints. Browse them at `/docs`.                                                                                                                                                     |

## Deploy to production [#deploy-to-production]

**Prerequisites:** [Azure CLI](https://learn.microsoft.com/cli/azure/install-azure-cli) installed with `az login` completed, Docker running, and OpenSSL available. The image is built locally.

<Steps>
  <Step title="Create a production env">
    ```bash
    cp .env .env.production
    ```

    Edit `.env.production` with production values: a different OpenAI key, production-only credentials, a different Slack workspace.
  </Step>

  <Step title="Deploy">
    ```bash
    ./scripts/azure/up.sh
    ```

    The first run takes 15-20 minutes (Postgres Flexible Server is the long pole) and creates everything inside one dedicated resource group, `agentos` by default: a VNet with private DNS, a container registry with the locally built image, PostgreSQL 17 Flexible Server with private access and pgvector allowlisted, the Container Apps environment, and the `agent-os` app configured with one always-running replica. The app URL is only known after create. Once the app is up, the script writes `AGENTOS_URL` back to your env file so scheduled jobs reach the platform. It also generates `MCP_CONNECT_SECRET`, the OAuth consent secret for connecting chat apps, into the same file.
  </Step>

  <Step title="Mint your JWT key">
    The script pauses for a `JWT_VERIFICATION_KEY`. Token-Based Authorization is on by default. Production startup requires that verification key or a readable JWKS file at the container path in `JWT_JWKS_FILE`; otherwise the process exits.

    1. Open [os.agno.com](https://os.agno.com), click **Connect OS** → **Live**, and enter your Container Apps URL.
    2. Name it **Live AgentOS**, turn on &#x2A;*Token-Based Authorization (JWT)** on the connection panel, and connect. The UI generates the public key. If the OS is already connected, enable the setting under **Settings** → **OS & Security**.
    3. Copy the public key and paste the full PEM into the `up.sh` prompt. The script saves it to your env file, stores it as a Container Apps secret, and applies it together with `AGENTOS_URL` in a second revision.

    If your env file already sets `JWT_JWKS_FILE`, the script skips the pause, but it only applies the path. Bake or mount the file before deployment. If you skip the prompt, add `JWT_VERIFICATION_KEY` to `.env.production` and run `./scripts/azure/env-sync.sh`. Adding JWKS later requires an image rebuild or mount plus a redeploy. Env sync alone is insufficient.

    <Note>
      Live AgentOS connections are a paid feature. Use code 

      `PLATFORM30`

       for one month off.
    </Note>
  </Step>

  <Step title="Connect your MCP clients">
    Re-run `uvx agno connect`, this time pointed at your deployed domain:

    ```bash
    uvx agno connect --url https://<container-app-domain>
    ```

    For claude.ai and ChatGPT on the web: add `https://<container-app-domain>/mcp` as a custom connector in the chat app's connector settings. Leave the form's optional OAuth fields (client ID / client secret) empty. Click **Connect** and, on the consent page, enter the `MCP_CONNECT_SECRET` that `up.sh` generated during deploy (saved in `.env.production`).
  </Step>

  <Step title="Confirm it's live">
    ```bash
    az containerapp logs show -g agentos -n agent-os --follow
    ```

    The script prints your app URL. Give the revision a couple of minutes to converge, then open `https://<container-app-domain>/docs` to confirm the API is serving.
  </Step>
</Steps>

<Check>
  Your AgentOS is live on Azure Container Apps.
</Check>

For a custom resource group, export `AZURE_RESOURCE_GROUP` in your shell before redeploy, env-sync, or teardown. Setting it only in `.env.production` does not configure those lifecycle commands.

### Redeploy after code changes [#redeploy-after-code-changes]

```bash
./scripts/azure/redeploy.sh
```

### Sync environment variables [#sync-environment-variables]

```bash
./scripts/azure/env-sync.sh
```

### Tear down [#tear-down]

```bash
./scripts/azure/down.sh
```

<Warning>
  Deletes the entire resource group, `agentos` by default: the `agent-os` app, the Container Apps environment, the Postgres server and all its data, the container registry, the VNet, and the private DNS zone. The script lists the group's resources and asks you to type the group name before deleting. It also comments out the stale `AGENTOS_URL` in your env files so a future `up.sh` derives a fresh domain; custom domains are left alone.
</Warning>

## Next steps [#next-steps]

<CardGroup cols="2">
  <Card title="Build with coding agents" icon="wand-magic-sparkles" href="/deploy/coding-agents">
    Skills to create → improve → evaluate your platform using coding agents.
  </Card>

  <Card title="Azure Container Apps reference" icon="book" href="/deploy/templates/azure/reference">
    Commands, environment variables, troubleshooting.
  </Card>
</CardGroup>
