* feat(api): support global API key from config.yaml (api.global_api_key) Accept a config-defined global API key anywhere a web-UI key is accepted (X-API-Key / Bearer), with no login session and no DB record. Useful for automated deployments and AI agents (HTTP API + MCP). Defaults to empty (disabled); does not require the lbk_ prefix. - templates/config.yaml: add api.global_api_key with security notes - service/apikey.py: verify_api_key checks global key first (constant-time) - docs/API_KEY_AUTH.md: document the global key + security guidance - tests: cover global-key match, prefix-free, fallback-to-db, disabled * feat(mcp): expose LangBot management as an MCP server at /mcp Add an MCP (Model Context Protocol) server so external AI agents can manage a LangBot instance. Reuses the same API-key auth as the HTTP API (including the config.yaml global API key). - pkg/api/mcp/server.py: FastMCP server wrapping the service layer; 21 curated tools across system/bots/pipelines/models/knowledge/mcp-servers/skills - pkg/api/mcp/mount.py: ASGI dispatcher fronting Quart; authenticates /mcp requests with an API key, runs the streamable-HTTP session manager lifespan - controller/main.py: serve the wrapped ASGI app via hypercorn (was run_task) - web: new 'MCP' tab in the API integration dialog showing endpoint, auth, and client config; i18n for 8 locales - tests/manual/mcp_smoke.py: e2e check (401 unauth, list tools, call tools) Tool surface is intentionally curated (not all ~25 route groups) to keep the agent surface small, safe, and maintainable. Extend deliberately. * feat(skills): add in-repo skills/ as the single source of truth Migrate the agent skills + QA/e2e test harness from the (now archived) langbot-app/langbot-skills repo into LangBot/skills/, and add four new skills. Migrated: - langbot-plugin-dev, langbot-testing (e2e), langbot-env-setup, langbot-skills-maintenance, langbot-eba-adapter-dev - the bin/lbs CLI (src/, test/, scripts/, schemas/, qa-agent-docs/) New: - langbot-dev core backend + web development - langbot-deploy Docker/K8s deployment + config.yaml + global API key - langbot-mcp-ops operating the LangBot MCP server (/mcp) - langbot-space-ops operating the Space marketplace MCP server - src/cli.ts repoRoot(): recognize the skills assets root (skills.index.json + bin/lbs) so the CLI works when nested inside the LangBot repo - README.md: unified skill catalog; skills.index.json regenerated Parity with source verified: bin/lbs validate + node test suite match the source repo (only the uncommitted .lbpkg build-artifact fixture differs). * docs(agents): document agent-facing surfaces + API/MCP/skills sync rule * docs(readme): add 'Built for AI Agents' section across all locales Highlight MCP server, in-repo skills (single source of truth), AGENTS.md sync rule, and llms.txt. Cross-link LangBot Space MCP marketplace. * style(mcp): fix ruff format + prettier lint in MCP server and API panel * style(web): prettier format MCP i18n locale entries * docs(skills): note MCP instance control in dev/testing skills All development-guidance skills now point to the LangBot instance MCP server (/mcp) and the Space marketplace MCP server, reusing API keys.
3.5 KiB
name, description
| name | description |
|---|---|
| langbot-deploy | Deploy and configure a LangBot instance — Docker / Docker Compose, Kubernetes, the config.yaml model, the Box sandbox runtime, the plugin runtime, and the global API key. Use when installing, deploying, upgrading, or configuring LangBot in production or self-hosted environments. Triggers on "deploy langbot", "langbot docker", "langbot compose", "langbot kubernetes", "langbot config.yaml", "langbot box runtime", "langbot global api key". |
LangBot Deployment & Configuration
Covers running LangBot in production. For development see langbot-dev.
Docker Compose (recommended)
git clone https://github.com/langbot-app/LangBot
cd LangBot/docker
# Full stack (sandbox/Box + stdio MCP hosting + skill add/edit enabled)
docker compose --profile all up
# Basic (no Box runtime)
docker compose up
The all / box profile starts three services:
langbot— main app, serves API + UI on:5300.langbot_plugin_runtime— plugin runtime (control:5400, debug:5401).langbot_box— Box sandbox runtime (:5410). Uses the host Docker socket to spawn sandbox containers, so the Box root host path and in-container path must be identical (BOX__LOCAL__HOST_ROOT=${LANGBOT_BOX_ROOT:-${PWD}/data/box}).
With Box off, the dashboard/skills list stays visible (read-only) but sandbox
tools, skill add/edit, and stdio MCP are disabled. Set box.enabled: false
(or BOX__ENABLED=false) to match.
Kubernetes
See docker/kubernetes.yaml and the deployment guide at
https://docs.langbot.app. docker/deploy-k8s-test.sh is a test helper.
config.yaml (generated at data/config.yaml on first run)
Top-level sections: api, system, command, concurrency, proxy,
database, vdb, storage, plugin, monitoring, box, space.
Key settings:
| Key | Meaning |
|---|---|
api.port |
HTTP API + UI port (default 5300) |
api.global_api_key |
Global API key for the HTTP API + MCP server. Non-empty = accepted with no login/DB record; no lbk_ prefix required. Empty = disabled. Plaintext — trusted/internal only, serve over HTTPS. |
plugin.runtime_ws_url |
Standalone plugin runtime WS URL (e.g. ws://langbot_plugin_runtime:5400/control/ws) |
box.enabled |
Master switch for the Box sandbox runtime |
box.backend |
local (Docker/nsjail autopick) / docker / nsjail / e2b; env override BOX__BACKEND |
box.runtime.endpoint |
External Box runtime URL (e.g. ws://127.0.0.1:5410); empty = local auto-managed |
Many keys have ENV__SUBKEY overrides (e.g. BOX__BACKEND, BOX__ENABLED).
Runtimes & flags
- LangBot started directly spawns the plugin runtime over stdio.
- In containers it connects to a standalone runtime over WebSocket; start
with
--standalone-runtime. - Box has a parallel
--standalone-boxflag; the Docker box host islangbot_box:5410.
Global API key — enabling for agents/automation
# data/config.yaml
api:
port: 5300
global_api_key: 'a-strong-secret' # empty disables it
This key authenticates both the HTTP API and the MCP server (/mcp) without a
login session. See langbot-mcp-ops for using it, and docs/API_KEY_AUTH.md.
Pitfalls
- "No supported sandbox backend (Docker / nsjail / E2B)" with Docker running
usually means the user isn't in the
dockergroup →sudo usermod -aG docker <user>and restart in a new shell. - Box root host/container path mismatch breaks sandbox container creation.
- Don't commit a non-empty
api.global_api_keyto version control.