Files
LangBot/skills/skills/langbot-deploy/SKILL.md
T
Junyan Chin e9dd584792 feat: MCP server + in-repo skills (agent-friendly platform) (#2269)
* feat(api): support global API key from config.yaml (api.global_api_key)

Accept a config-defined global API key anywhere a web-UI key is accepted
(X-API-Key / Bearer), with no login session and no DB record. Useful for
automated deployments and AI agents (HTTP API + MCP). Defaults to empty
(disabled); does not require the lbk_ prefix.

- templates/config.yaml: add api.global_api_key with security notes
- service/apikey.py: verify_api_key checks global key first (constant-time)
- docs/API_KEY_AUTH.md: document the global key + security guidance
- tests: cover global-key match, prefix-free, fallback-to-db, disabled

* feat(mcp): expose LangBot management as an MCP server at /mcp

Add an MCP (Model Context Protocol) server so external AI agents can manage a
LangBot instance. Reuses the same API-key auth as the HTTP API (including the
config.yaml global API key).

- pkg/api/mcp/server.py: FastMCP server wrapping the service layer; 21 curated
  tools across system/bots/pipelines/models/knowledge/mcp-servers/skills
- pkg/api/mcp/mount.py: ASGI dispatcher fronting Quart; authenticates /mcp
  requests with an API key, runs the streamable-HTTP session manager lifespan
- controller/main.py: serve the wrapped ASGI app via hypercorn (was run_task)
- web: new 'MCP' tab in the API integration dialog showing endpoint, auth, and
  client config; i18n for 8 locales
- tests/manual/mcp_smoke.py: e2e check (401 unauth, list tools, call tools)

Tool surface is intentionally curated (not all ~25 route groups) to keep the
agent surface small, safe, and maintainable. Extend deliberately.

* feat(skills): add in-repo skills/ as the single source of truth

Migrate the agent skills + QA/e2e test harness from the (now archived)
langbot-app/langbot-skills repo into LangBot/skills/, and add four new skills.

Migrated:
- langbot-plugin-dev, langbot-testing (e2e), langbot-env-setup,
  langbot-skills-maintenance, langbot-eba-adapter-dev
- the bin/lbs CLI (src/, test/, scripts/, schemas/, qa-agent-docs/)

New:
- langbot-dev      core backend + web development
- langbot-deploy   Docker/K8s deployment + config.yaml + global API key
- langbot-mcp-ops  operating the LangBot MCP server (/mcp)
- langbot-space-ops operating the Space marketplace MCP server

- src/cli.ts repoRoot(): recognize the skills assets root (skills.index.json +
  bin/lbs) so the CLI works when nested inside the LangBot repo
- README.md: unified skill catalog; skills.index.json regenerated

Parity with source verified: bin/lbs validate + node test suite match the
source repo (only the uncommitted .lbpkg build-artifact fixture differs).

* docs(agents): document agent-facing surfaces + API/MCP/skills sync rule

* docs(readme): add 'Built for AI Agents' section across all locales

Highlight MCP server, in-repo skills (single source of truth), AGENTS.md
sync rule, and llms.txt. Cross-link LangBot Space MCP marketplace.

* style(mcp): fix ruff format + prettier lint in MCP server and API panel

* style(web): prettier format MCP i18n locale entries

* docs(skills): note MCP instance control in dev/testing skills

All development-guidance skills now point to the LangBot instance MCP
server (/mcp) and the Space marketplace MCP server, reusing API keys.
2026-06-20 15:14:47 +08:00

3.5 KiB

name, description
name description
langbot-deploy Deploy and configure a LangBot instance — Docker / Docker Compose, Kubernetes, the config.yaml model, the Box sandbox runtime, the plugin runtime, and the global API key. Use when installing, deploying, upgrading, or configuring LangBot in production or self-hosted environments. Triggers on "deploy langbot", "langbot docker", "langbot compose", "langbot kubernetes", "langbot config.yaml", "langbot box runtime", "langbot global api key".

LangBot Deployment & Configuration

Covers running LangBot in production. For development see langbot-dev.

git clone https://github.com/langbot-app/LangBot
cd LangBot/docker

# Full stack (sandbox/Box + stdio MCP hosting + skill add/edit enabled)
docker compose --profile all up

# Basic (no Box runtime)
docker compose up

The all / box profile starts three services:

  • langbot — main app, serves API + UI on :5300.
  • langbot_plugin_runtime — plugin runtime (control :5400, debug :5401).
  • langbot_box — Box sandbox runtime (:5410). Uses the host Docker socket to spawn sandbox containers, so the Box root host path and in-container path must be identical (BOX__LOCAL__HOST_ROOT=${LANGBOT_BOX_ROOT:-${PWD}/data/box}).

With Box off, the dashboard/skills list stays visible (read-only) but sandbox tools, skill add/edit, and stdio MCP are disabled. Set box.enabled: false (or BOX__ENABLED=false) to match.

Kubernetes

See docker/kubernetes.yaml and the deployment guide at https://docs.langbot.app. docker/deploy-k8s-test.sh is a test helper.

config.yaml (generated at data/config.yaml on first run)

Top-level sections: api, system, command, concurrency, proxy, database, vdb, storage, plugin, monitoring, box, space.

Key settings:

Key Meaning
api.port HTTP API + UI port (default 5300)
api.global_api_key Global API key for the HTTP API + MCP server. Non-empty = accepted with no login/DB record; no lbk_ prefix required. Empty = disabled. Plaintext — trusted/internal only, serve over HTTPS.
plugin.runtime_ws_url Standalone plugin runtime WS URL (e.g. ws://langbot_plugin_runtime:5400/control/ws)
box.enabled Master switch for the Box sandbox runtime
box.backend local (Docker/nsjail autopick) / docker / nsjail / e2b; env override BOX__BACKEND
box.runtime.endpoint External Box runtime URL (e.g. ws://127.0.0.1:5410); empty = local auto-managed

Many keys have ENV__SUBKEY overrides (e.g. BOX__BACKEND, BOX__ENABLED).

Runtimes & flags

  • LangBot started directly spawns the plugin runtime over stdio.
  • In containers it connects to a standalone runtime over WebSocket; start with --standalone-runtime.
  • Box has a parallel --standalone-box flag; the Docker box host is langbot_box:5410.

Global API key — enabling for agents/automation

# data/config.yaml
api:
    port: 5300
    global_api_key: 'a-strong-secret'   # empty disables it

This key authenticates both the HTTP API and the MCP server (/mcp) without a login session. See langbot-mcp-ops for using it, and docs/API_KEY_AUTH.md.

Pitfalls

  • "No supported sandbox backend (Docker / nsjail / E2B)" with Docker running usually means the user isn't in the docker group → sudo usermod -aG docker <user> and restart in a new shell.
  • Box root host/container path mismatch breaks sandbox container creation.
  • Don't commit a non-empty api.global_api_key to version control.