Agent skill

LangBot Deployment Guide

by langbot-app in langbot-app/LangBot

Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

Apache-2.0Auto-check: notesDevOps & Cloud

Install LangBot Deployment Guide

skills CLI
$ npx skills add langbot-app/LangBot --skill langbot-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbot-app/LangBot langbot-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbot-app/LangBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skills/langbot-deploy .claude/skills/langbot-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
langbot-deploy
GitHub stars
18k
Token cost
~1.2k tokens
SKILL.md length
495 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

  • Installing LangBot with Docker Compose for self-hosting
  • SKILL.md covers Docker Compose (recommended), Kubernetes, config.yaml (generated at… and Runtimes & flags, plus 2 more sections
  • Calls docker, openssl and git; needs LANGBOT_BOX_CONTROL_TOKEN and LANGBOT_PLUGIN_RUNTIME_CONTROL_TOKEN
  • Deploying LangBot to Kubernetes

What it does

This covers production use; development is left to `langbot-dev`. Docker Compose is the recommended route: clone the repository and work in its `docker` folder. The `all` or `box` profile starts three services: `langbot`, serving the API and UI on port 5300, `langbot_plugin_runtime`, with control on 5400 and debug on 5401, and `langbot_box`, the sandbox runtime on 5410. Box spawns sandbox containers through the host Docker socket, so its root path must be identical on the host and inside the container.

Control tokens are optional in the open-source setup, but an exposed Box endpoint should get the same token of at least 32 characters on both sides, generated with `openssl rand -hex 32` and never committed. The plugin runtime token must likewise be set on both sides or the connection fails. `data/config.yaml` is generated on first run; `api.global_api_key`, when non-empty, accepts requests to the HTTP API and MCP server without login, so use it only internally over HTTPS. Kubernetes uses `docker/kubernetes.yaml`.

When your agent uses it

  • Installing LangBot with Docker Compose for self-hosting
  • Deploying LangBot to Kubernetes
  • Securing the Box and plugin runtime control connections
  • Setting the global API key or editing config.yaml

Example prompts

  • “Deploy LangBot with Docker Compose using the box profile and tell me which ports it opens.”
  • “Set up a shared control token for the Box runtime before I expose it.”
  • “Turn the Box sandbox off in my LangBot config and explain what stops working.”
  • “Enable the global API key in config.yaml for my internal MCP clients.”

Requirements

  • Docker and Docker Compose, or a Kubernetes cluster
  • `openssl` for generating control tokens

What it can do on your machine

Read from SKILL.md and the folder at commit de886ed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • openssl
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • langbot.app

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LANGBOT_BOX_CONTROL_TOKEN
    • LANGBOT_PLUGIN_RUNTIME_CONTROL_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LangBot Deployment Guide loads about 1.2k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 495 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:99
    `sudo usermod -aG docker <user>` and restart in a new shell.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbot-app/LangBot at commit de886ed, republished under its Apache-2.0 licence (© langbot-app). 495 words, ~1,217 tokens.

Download SKILL.mdSave it as .claude/skills/langbot-deploy/SKILL.md (or your agent's skills folder).
name
langbot-deploy
description
Deploy and configure a LangBot instance — Docker / Docker Compose, Kubernetes, the config.yaml model, the Box sandbox runtime, the plugin runtime, and the global API key. Use when installing, deploying, upgrading, or configuring LangBot in production or self-hosted environments. Triggers on "deploy langbot", "langbot docker", "langbot compose", "langbot kubernetes", "langbot config.yaml", "langbot box runtime", "langbot global api key".

LangBot Deployment & Configuration

Covers running LangBot in production. For development see langbot-dev.

bash
git clone https://github.com/langbot-app/LangBot
cd LangBot/docker

# Full stack (sandbox/Box + stdio MCP hosting + skill add/edit enabled)
docker compose --profile all up

# Basic (no Box runtime)
docker compose up

The all / box profile starts three services:

  • langbot — main app, serves API + UI on :5300.
  • langbot_plugin_runtime — plugin runtime (control :5400, debug :5401).
  • langbot_box — Box sandbox runtime (:5410). Uses the host Docker socket to spawn sandbox containers, so the Box root host path and in-container path must be identical (BOX__LOCAL__HOST_ROOT=${LANGBOT_BOX_ROOT:-${PWD}/data/box}). OSS allows its RPC and managed-process relay to run without a token when both sides leave LANGBOT_BOX_CONTROL_TOKEN unset. For an exposed endpoint, set the same value of at least 32 non-whitespace characters in both the LangBot and Box containers. Generate it once with openssl rand -hex 32; never put it in box.runtime.endpoint or commit it to config.

A Compose deployment may optionally set LANGBOT_PLUGIN_RUNTIME_CONTROL_TOKEN on both langbot and langbot_plugin_runtime when port 5400 needs shared-secret protection. OSS defaults to leaving it unset on both sides. If enabled, generate one value with openssl rand -hex 32; configuring only one side causes the control connection to fail. Kubernetes may use the langbot-plugin-runtime-control Secret shown in docker/kubernetes.yaml.

With Box off, the dashboard/skills list stays visible (read-only) but sandbox tools, skill add/edit, and stdio MCP are disabled. Set box.enabled: false (or BOX__ENABLED=false) to match.

Kubernetes

See docker/kubernetes.yaml and the deployment guide at https://langbot.app/docs. docker/deploy-k8s-test.sh is a test helper.

config.yaml (generated at data/config.yaml on first run)

Top-level sections: api, system, command, concurrency, proxy, database, vdb, storage, plugin, monitoring, box, space.

Key settings:

KeyMeaning
api.portHTTP API + UI port (default 5300)
api.global_api_keyGlobal API key for the HTTP API + MCP server. Non-empty = accepted with no login/DB record; no lbk_ prefix required. Empty = disabled. Plaintext — trusted/internal only, serve over HTTPS.
plugin.runtime_ws_urlStandalone plugin runtime WS URL (e.g. ws://langbot_plugin_runtime:5400/control/ws)
box.enabledMaster switch for the Box sandbox runtime
box.backendlocal (Docker/nsjail autopick) / docker / nsjail / e2b / explicit unsafe host; env override BOX__BACKEND
box.runtime.endpointExternal Box runtime URL (e.g. ws://127.0.0.1:5410); empty = local auto-managed

Many keys have ENV__SUBKEY overrides (e.g. BOX__BACKEND, BOX__ENABLED).

Show full SKILL.md (171 more words)Show less

Runtimes & flags

  • LangBot started directly spawns the plugin runtime over stdio.
  • In containers it connects to a standalone runtime over WebSocket; start with --standalone-runtime.
  • Box has a parallel --standalone-box flag; the Docker box host is langbot_box:5410.
  • box.backend: host runs commands directly as the Box Runtime system user. It is never auto-selected, provides no sandbox isolation, and is only for trusted local development. A WebSocket-controlled host backend requires LANGBOT_BOX_CONTROL_TOKEN; local stdio control is allowed.

Global API key — enabling for agents/automation

yaml
# data/config.yaml
api:
    port: 5300
    global_api_key: 'a-strong-secret'   # empty disables it

This key authenticates both the HTTP API and the MCP server (/mcp) without a login session. See langbot-mcp-ops for using it, and docs/API_KEY_AUTH.md.

Pitfalls

  • "No supported sandbox backend (Docker / nsjail / E2B)" with Docker running usually means the user isn't in the docker group → sudo usermod -aG docker <user> and restart in a new shell.
  • Do not use box.backend: host as a production fallback. It cannot enforce image, filesystem, network, PID, CPU, memory, or storage isolation.
  • Box root host/container path mismatch breaks sandbox container creation.
  • Don't commit a non-empty api.global_api_key to version control.

© langbot-app, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/skills/langbot-deploy of langbot-app/LangBot.

Open the folder on GitHubat commit de886ed

Compare with similar skills

LangBot Deployment Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LangBot Deployment Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LangBot Deployment Guide this skilllangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Deploymentmatrixorigin/memoria607—~1.6kAutomated safety check: NotesApache-2.0
Debug Openshell ClusterNVIDIA/OpenShell15k—~19kAutomated safety check: NotesApache-2.0
Onboarding Validationopen-edge-platform/edge-ai-suites140—~3.3kAutomated safety check: PassApache-2.0
Agenticx DeployerDemonDamon/AgenticX279—~866Automated safety check: PassApache-2.0
Vss Deploy Warehouse HelmNVIDIA-AI-Blueprints/video-search-and-summarization1.9k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Deployment

    matrixorigin/memoria

    Deploy Memoria with Docker Compose or Kubernetes. An agent skill from matrixorigin/memoria.

    607 GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    15k GitHub stars~19k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Onboarding Validation

    open-edge-platform/edge-ai-suites

    Validate the get-started experience of Open Edge Platform (OEP) software components from the perspective of a first-time user.

    140 GitHub stars~3.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Agenticx Deployer

    DemonDamon/AgenticX

    Guide for deploying AgenticX agents to production including Docker containerization, Kubernetes orchestration, Volcengine AgentKit cloud deployment, and API server setup.

    279 GitHub stars~866 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Vss Deploy Warehouse Helm

    NVIDIA-AI-Blueprints/video-search-and-summarization

    A skill your agent uses when the user asks to deploy, upgrade, or size the VSS warehouse blueprint (2D / 3D / MV3DT) on Kubernetes via Helm — as opposed to Docker Compose, which is covered by…

    1.9k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Aspire Deployment

    CommunityToolkit/Aspire

    WORKFLOW SKILL — Deploy Aspire apps from AppHost models to Docker Compose, Kubernetes, Azure, AWS, or preview Radius.

    629 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from langbot-app/LangBot

All 9 skills in this repo
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • LangBot Core Development

    langbot-app/LangBot

    Covers developing the LangBot core backend and web UI: dev setup, repo layout, API auth types, adding endpoints, migrations and keeping the MCP server in step.

    18k GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Guides building, migrating and testing LangBot messaging-platform adapters for the Event-Based Agents layout, with unified event and message conversion.

    18k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • LangBot MCP Operations

    langbot-app/LangBot

    Manages a LangBot instance over its built-in MCP server: endpoint, API-key authentication, client config and the tool set for bots, processors and more.

    18k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • LangBot Space MCP

    langbot-app/LangBot

    Browses and searches the LangBot Space marketplaces for plugins, MCP servers and skills through its read-only MCP server, authenticated with a personal access token.

    18k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • LangBot Environment Setup

    langbot-app/LangBot

    Prepares a LangBot development and testing environment for an agent, covering service startup, proxy settings and browser access through Computer Use or Playwright MCP.

    18k GitHub stars~496 tokensUpdated today
    Auto-check: notes

Categories

Questions about LangBot Deployment Guide

What does LangBot Deployment Guide do?

Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key. This covers production use; development is left to `langbot-dev`. Docker Compose is the recommended route: clone the repository and work in its `docker` folder.

When should I use LangBot Deployment Guide?

LangBot Deployment Guide fits situations like: installing LangBot with Docker Compose for self-hosting; deploying LangBot to Kubernetes; securing the Box and plugin runtime control connections; setting the global API key or editing config.yaml.

How do I install LangBot Deployment Guide in Claude Code?

Run `npx skills add langbot-app/LangBot --skill langbot-deploy -a claude-code`. Or copy the skill folder (skills/skills/langbot-deploy in langbot-app/LangBot) into .claude/skills/langbot-deploy in your project. Claude Code loads it when a task matches its description.

How do I install LangBot Deployment Guide in Codex?

Run `npx skills add langbot-app/LangBot --skill langbot-deploy -a codex`. Or copy the skill folder (skills/skills/langbot-deploy in langbot-app/LangBot) into .agents/skills/langbot-deploy in your project. Codex loads it when a task matches its description.

Can I use LangBot Deployment Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbot-app/LangBot --skill langbot-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langbot-deploy, .gemini/skills/langbot-deploy, .github/skills/langbot-deploy and .opencode/skills/langbot-deploy in your project.

What does LangBot Deployment Guide need to run?

Going by SKILL.md and its folder, LangBot Deployment Guide needs the command-line tools its instructions call (docker, openssl and git) and credentials named LANGBOT_BOX_CONTROL_TOKEN and LANGBOT_PLUGIN_RUNTIME_CONTROL_TOKEN. Our summary lists: Docker and Docker Compose, or a Kubernetes cluster; `openssl` for generating control tokens.

Does LangBot Deployment Guide access the network?

SKILL.md names 1 domain. As links in the text: langbot.app. This is read from the text; nothing was executed.

Is LangBot Deployment Guide safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does LangBot Deployment Guide use?

LangBot Deployment Guide is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does LangBot Deployment Guide use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to LangBot Deployment Guide?

Skills that share tags, products or a category with LangBot Deployment Guide: Deployment (matrixorigin/memoria, 607 stars), Debug Openshell Cluster (NVIDIA/OpenShell, 15k stars), Onboarding Validation (open-edge-platform/edge-ai-suites, 140 stars) and Agenticx Deployer (DemonDamon/AgenticX, 279 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LangBot Deployment Guide?

langbot-app (a GitHub organization) maintains it in langbot-app/LangBot, which has 18,033 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbot-app/LangBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.