Agent skill

Ragflow Runbook

by LeoYeAI in LeoYeAI/openclaw-master-skills

End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only).

MITAuto-check: notesDevOps & Cloud

Install Ragflow Runbook

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill ragflow-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills ragflow-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ragflow-runbook .claude/skills/ragflow-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ragflow-runbook
GitHub stars
2.2k
Token cost
~5.3k tokens
SKILL.md length
1,733 words
Files
13 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only).

  • Works in 12 steps: When To Use → What The Agent Must Ask First (Minimum… → Canonical Environment Variables… → …
  • Tasks that involve Runbooks and postmortems
  • SKILL.md covers 1) When To Use, 2) What The Agent Must Ask…, 3) Canonical Environment… and 4) Bootstrap (Fresh Install;…, plus 8 more sections
  • Runs Python and Shell scripts from its folder; calls docker, curl and git; reaches github.com and apple.com; needs RAGFLOW_API_KEY and ELASTIC_PASSWORD

What it does

Ragflow Runbook is an agent skill from LeoYeAI/openclaw-master-skills. End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only).

Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts (for example `CHANGELOG.md`, `README.md` and `_meta.json`).

It sits in DevOps & Cloud, covering Runbooks and postmortems. It works with Linux and Docker. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Tasks that involve Runbooks and postmortems

Example prompts

  • “/ragflow-runbook”

Requirements

  • Python 3
  • A Bash shell
  • Docker
  • A credential in RAGFLOW_API_KEY

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. When To Use
  2. What The Agent Must Ask First (Minimum Inputs)
  3. Canonical Environment Variables (Recommended)
  4. Bootstrap (Fresh Install; Windows/WSL2 + Linux)
  5. Quick Start (Ops Checklist)
  6. Service Management (Day-2 Operations)
  7. Health Checks (Common Root Causes)
  8. API Usage (Agent-Safe Patterns)
  9. Backup / Restore (Practical)
  10. Security Baseline (Minimum)
  11. Troubleshooting Flow (Agent Playbook)
  12. OpenClaw Ops Integration

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • curl
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • apple.com

    Also links to:

    • ragflow.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RAGFLOW_API_KEY
    • ELASTIC_PASSWORD
    • MYSQL_PASSWORD
    • MINIO_PASSWORD
    • REDIS_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ragflow Runbook loads about 5.3k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 1,733 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:109
    sudo sysctl -w vm.max_map_count=262144 || true
  • NoteMentions a .env fileSKILL.md:111
    # Default .env = elasticsearch + cpu
  • NoteMentions a .env fileSKILL.md:112
    ts/passwords/image versions: edit docker/.env
  • NoteRuns commands with sudoSKILL.md:123
    sudo mkdir -p /opt && cd /opt
  • NoteRuns commands with sudoSKILL.md:124
    sudo chown -R "$USER" /opt
  • NoteRuns commands with sudoSKILL.md:129
    sudo sysctl -w vm.max_map_count=262144 || true
  • NoteMentions a .env fileSKILL.md:154
    - `.env` (default ports/passwords; change for production)
  • NoteMentions a .env fileSKILL.md:164
    Upstream `.env` defaults:
  • NoteMentions a .env fileSKILL.md:168
    compose up -d` will pick profiles from `.env`.
  • NoteRuns commands with sudoSKILL.md:174
    sudo sysctl -w vm.max_map_count=262144 || true

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,733 words, ~5,293 tokens.

Download SKILL.mdSave it as .claude/skills/ragflow-runbook/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
ragflow-runbook
description
End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only).
version
0.1.4
env.required
RAGFLOW_BASE_URL
env.optional
RAGFLOW_API_KEY, OPENCLAW_PRIMARY_CHAT_ID

ragflow-runbook Skill

A practical runbook for deploying, operating, troubleshooting, and calling RAGFlow (Retrieval-Augmented Generation).

Goal: any agent should be able to bring RAGFlow up, diagnose failures, and call the API safely even without knowing the deployment details up front.


1) When To Use

  • Deploy RAGFlow (Docker / Windows / Linux / WSL2).
  • Troubleshoot failures: startup issues, unhealthy backend services, port conflicts, performance problems.
  • Use the API for operations purposes: validate liveness/readiness, verify auth, and check system endpoints.
  • Run health checks, automate smoke tests, or prepare backup/restore.

2) What The Agent Must Ask First (Minimum Inputs)

Before running any commands, confirm the following (missing any of these often leads to wrong assumptions):

  • Deployment environment: Windows / WSL2 / Linux / macOS (client only)
  • Install directory (the directory that contains docker-compose.yml)
  • Access method:
    • RAGFLOW_BASE_URL (e.g. http://localhost:9380 or an internal/Tailscale address)
    • Whether there is an Nginx/reverse proxy in front (and whether Web UI uses port 80/8080)
  • Whether an API key already exists (do NOT paste secrets into chat; use env vars / secret manager)
  • Current symptom:
    • "does not start" vs "starts but UI/API errors" vs "retrieval quality is poor"

Security: never store or share API keys / DB passwords in plaintext (docs, repo, or chat).


Use environment variables so all agents can run the same commands:

  • RAGFLOW_BASE_URL: prefer an internal/Tailscale URL, e.g. http://100.x.y.z:9380
  • RAGFLOW_API_KEY: Bearer token (created in the RAGFlow Web UI)

Quick verification (separate liveness / readiness / auth; tolerate path differences across versions):

  • Liveness (usually no auth; try in order, any 200 is OK):
    • GET $RAGFLOW_BASE_URL/openapi.json
    • GET $RAGFLOW_BASE_URL/api/v1/openapi.json
    • GET $RAGFLOW_BASE_URL/v1/system/ping
  • Readiness (often requires auth; try in order):
    • GET $RAGFLOW_BASE_URL/v1/system/status
    • GET $RAGFLOW_BASE_URL/v1/system/ping

If these do not match your deployment: treat the returned openapi.json as the source of truth.

This skill ships with its own ops helpers under scripts/:

  • scripts/ragflow_ping.py: liveness + readiness
  • scripts/ragflow_smoke.py: auth + API smoke (system-level only)
  • scripts/ragflow_status.py: compact status summary
  • scripts/ragflow_alert.py: send an ops alert via OpenClaw messaging

This skill is intentionally decoupled from any workspace-specific application content. It focuses only on RAGFlow runtime operations.


4) Bootstrap (Fresh Install; Windows/WSL2 + Linux)

This section targets a brand-new machine. Goal: get to a working UI + API quickly: clone upstream docker bundle -> start -> create API key in UI -> validate via curl/scripts.

4.1 Choose Install Mode (Default)
  • Primary path (best for most desktop / Windows users): Windows + WSL2
  • Alternate path: a Linux server (Ubuntu/Debian/CentOS/etc.)
4.1.1 Fresh Install: Copy/Paste (WSL2 / Linux)

WSL2 (recommended: store files on a Windows drive like D:; run commands inside WSL2):

bash
# WSL2
cd /mnt/d

git clone https://github.com/infiniflow/ragflow.git
cd ragflow/docker

# Common requirement for some document engine profiles
sudo sysctl -w vm.max_map_count=262144 || true

# Default .env = elasticsearch + cpu
# To change ports/passwords/image versions: edit docker/.env

docker compose up -d

docker compose ps

Linux:

bash
# Linux
sudo mkdir -p /opt && cd /opt
sudo chown -R "$USER" /opt

git clone https://github.com/infiniflow/ragflow.git
cd ragflow/docker

sudo sysctl -w vm.max_map_count=262144 || true

docker compose up -d

docker compose ps

Next: open Web UI (default http://<host>:80), finish initialization, create an API key, then validate using ## 3 + ## 8.

4.2 Get The Official Docker Compose Bundle (Robust; Verified Against Upstream)

To avoid missing files or mismatched versions, use git clone and run from the upstream docker/ directory:

bash
git clone https://github.com/infiniflow/ragflow.git
cd ragflow/docker

# Optional: pin to a tag/commit for production
# git checkout <tag-or-commit>

The upstream docker/ folder typically includes:

  • docker-compose.yml (often include: ./docker-compose-base.yml)
  • docker-compose-base.yml (backend services: database + cache + object storage + document engine)
  • .env (default ports/passwords; change for production)
  • service_conf.yaml.template (used to generate service_conf.yaml at container startup)
  • entrypoint.sh (commonly started with flags like --enable-adminserver / --enable-mcpserver)
  • nginx/ (for built-in Web UI / reverse proxy)
  • README.md (docker-specific docs)

Note: upstream explicitly warns that some compose variants (e.g. docker-compose-macos.yml) are not actively maintained. Do not use them unless you know why.

4.3 First Bring-Up (Upstream COMPOSE_PROFILES)

Upstream .env defaults:

  • COMPOSE_PROFILES is derived from selected backend profiles (e.g. document engine + compute device)

So you typically do not need to pass --profile manually. docker compose up -d will pick profiles from .env.

Before starting (Linux/WSL2, for some document engine profiles):

bash
cat /proc/sys/vm/max_map_count || true
sudo sysctl -w vm.max_map_count=262144 || true

Start:

bash
# In ragflow/docker
# Optional: explicit profiles if you do not want to rely on COMPOSE_PROFILES
# docker compose --profile elasticsearch --profile cpu up -d

docker compose up -d

docker compose ps

Switch CPU/GPU (examples):

bash
# Option 1: edit docker/.env
# DEVICE=gpu

# Option 2: override temporarily (do not modify files)
DEVICE=gpu docker compose up -d

Enable embeddings service (TEI): upstream suggests adding a tei profile to COMPOSE_PROFILES:

bash
# Example:
# COMPOSE_PROFILES=${COMPOSE_PROFILES},tei-cpu
# or:
# COMPOSE_PROFILES=${COMPOSE_PROFILES},tei-gpu

docker compose up -d

Validation: wait for key services to be running/healthy in docker compose ps, then run liveness/readiness (## 3) and API prefix detection (## 8).

4.4 First-Time Setup Checklist (Aligned With Upstream .env)

In upstream docker/.env (main branch), exposed ports typically mean:

  • Web UI / WebServer: SVR_WEB_HTTP_PORT (default 80), SVR_WEB_HTTPS_PORT (default 443)
  • API (RAGFlow HTTP): SVR_HTTP_PORT (default 9380)
  • Admin Server: ADMIN_SVR_HTTP_PORT (default 9381)
  • MCP: SVR_MCP_PORT (default 9382)

Shortest path to a usable setup:

  1. Open Web UI: http://<host>:${SVR_WEB_HTTP_PORT} (default http://<host>:80)
  2. Complete initialization (admin/org setup depending on version)
  3. Create an API key (usually under Settings/System/API Keys)
  4. Set on the client side (recommended env vars):
  • RAGFLOW_BASE_URL=http://<host>:${SVR_HTTP_PORT} (default http://<host>:9380)
  • RAGFLOW_API_KEY=ragflow-... (Bearer token; do not paste secrets into chat)

Then validate with liveness/readiness in ## 3.

Production warning: upstream .env explicitly warns against using default passwords. At minimum change ELASTIC_PASSWORD, MYSQL_PASSWORD, MINIO_PASSWORD, and REDIS_PASSWORD.


5) Quick Start (Ops Checklist)

5.1 Prerequisites
  • Docker Engine + Docker Compose v2 (docker compose ...)
  • Resources (rule of thumb):
    • CPU >= 4 cores, RAM >= 16GB (32GB recommended)
    • Disk >= 50GB (depends on document volume + vector index size)
  • Linux/WSL2: vm.max_map_count >= 262144 (required by some document engine profiles)

Checks:

bash
docker --version
docker compose version

# Linux/WSL2 only
cat /proc/sys/vm/max_map_count

Temporary fix (Linux/WSL2):

bash
sudo sysctl -w vm.max_map_count=262144
5.2 Bring-Up (Docker Compose)

Prereq: you are in the directory that contains docker-compose.yml.

bash
docker compose up -d
docker compose ps

Tail logs:

bash
docker compose logs -f

6) Service Management (Day-2 Operations)

bash
# Status
docker compose ps

# Start/stop
docker compose up -d
docker compose down

# Restart
docker compose restart

# Logs (all / last N lines / last 1h)
docker compose logs
docker compose logs --tail=200
docker compose logs --since=1h

# Resource usage
docker stats

Note: service names differ across compose versions. If you see "no such service", run docker compose ps and use the actual service name.


7) Health Checks (Common Root Causes)

7.1 Document engine unhealthy / crash loop

Common causes: vm.max_map_count too small, low RAM, disk full.

bash
# Linux/WSL2
cat /proc/sys/vm/max_map_count
sudo sysctl -w vm.max_map_count=262144

docker compose ps
docker compose logs --tail=200 <es-service>
7.2 Database connection failures
bash
docker compose ps
docker compose logs --tail=200 <mysql-service>
7.3 Port conflicts
  • Symptom: containers fail to start or port mapping fails.
  • Fix: find the process using the port, or change port mappings in .env / compose and restart.

8) API Usage (Agent-Safe Patterns)

8.1 Base URL + Auth

RAGFlow often exposes:

  • Web UI (port 80/8080)
  • API (commonly 9380, or a reverse-proxied path)

Recommended convention:

  • RAGFLOW_BASE_URL points to the API root, e.g. http://localhost:9380
  • Auth header: Authorization: Bearer $RAGFLOW_API_KEY
8.2 Minimal curl examples (Prefix Auto-Detect; Prefer v1)

Across versions/deployments, RAGFlow may have two API prefixes:

  • v1/... (often system/user/token)
  • api/v1/... (often application endpoints)

Use this template to auto-detect the prefix (prefer v1, fallback to api/v1).

bash
# 0) Ensure you are hitting the API port/host (not the UI port)
#    Any 200 is OK
curl -sS -o /dev/null -w "%{http_code}\n" "$RAGFLOW_BASE_URL/openapi.json"
curl -sS -o /dev/null -w "%{http_code}\n" "$RAGFLOW_BASE_URL/api/v1/openapi.json"

# 1) Auto-detect prefix (prefer v1)
RAGFLOW_API_PREFIX=""
if curl -sS -o /dev/null -w "%{http_code}" "$RAGFLOW_BASE_URL/v1/system/ping" | grep -q "200"; then
  RAGFLOW_API_PREFIX="v1"
elif curl -sS -o /dev/null -w "%{http_code}" "$RAGFLOW_BASE_URL/api/v1/openapi.json" | grep -q "200"; then
  RAGFLOW_API_PREFIX="api/v1"
else
  echo "Cannot detect API prefix. Check base URL / reverse proxy / firewall."
  exit 1
fi

echo "Detected prefix: $RAGFLOW_API_PREFIX"

Ops-only examples (no application-level endpoints):

Example 1: system ping (no secrets in output)

bash
curl -sS -o /dev/null -w "%{http_code}\n" "$RAGFLOW_BASE_URL/v1/system/ping"

Example 2: system status (auth)

bash
curl -sS -X GET "$RAGFLOW_BASE_URL/v1/system/status" \
  -H "Authorization: Bearer $RAGFLOW_API_KEY" | head

Example 3: fetch openapi schema (liveness)

bash
curl -sS "$RAGFLOW_BASE_URL/openapi.json" | head

Note: If your deployment uses different paths, openapi.json is the source of truth. Avoid calling application-level endpoints from ops runbooks.

8.3 Agent Guidance
  • Always fetch openapi.json first to confirm real paths/fields/version differences.
  • If you get 404: suspect base URL (hitting UI port), reverse proxy misconfig, or a different path prefix.
  • If you get 401/403: suspect missing/expired key or missing Bearer prefix.

9) Backup / Restore (Practical)

Principle: stop services first, then back up volumes, then back up compose configs.

Backup (example; volume names depend on your environment):

bash
mkdir -p backup

docker run --rm \
  -v <mysql_volume>:/source \
  -v "$PWD/backup":/backup \
  alpine tar czf /backup/mysql-data.tar.gz -C /source .

Restore:

bash
docker compose down

docker run --rm \
  -v <mysql_volume>:/target \
  -v "$PWD/backup":/backup \
  alpine tar xzf /backup/mysql-data.tar.gz -C /target

docker compose up -d

Show full SKILL.md (684 more words)Show less

10) Security Baseline (Minimum)

  • Do not use latest in production; pin image versions.
  • API keys must be stored in env vars / secret manager only.
  • Minimize exposure: allow only internal/Tailscale ranges to access API ports.
  • If public access is required: add TLS + auth at reverse proxy, and restrict source IP ranges.

11) Troubleshooting Flow (Agent Playbook)

When a user says "RAGFlow is not working", use this order to reduce back-and-forth:

  1. docker compose ps (which containers are unhealthy/exited)
  2. docker compose logs --tail=200 <unhealthy-service> (capture the first actionable errors)
  3. Resources: docker stats, disk, vm.max_map_count (Linux/WSL2)
  4. Network: from the caller machine curl $RAGFLOW_BASE_URL/openapi.json
  5. Auth: ragflow_ping.py or GET /v1/system/status (with Bearer)

12) OpenClaw Ops Integration

This section documents an end-to-end operations workflow for running RAGFlow with OpenClaw. It is intentionally decoupled from any application-layer usage and focuses only on RAGFlow runtime operations.

12.1 Scope

Included:

  • Host/service health verification (liveness/readiness)
  • Basic auth verification (API key works)
  • Smoke checks (API reachable, key endpoints respond)
  • Alerting hooks (what to check, what to report)
  • Scheduling (daily/periodic checks)

Excluded (by design):

  • Any application-layer conventions
  • Content parsing/chunking/index strategy
  • Retrieval quality evaluation
12.2 Standard Environment Contract

On the machine running OpenClaw, set:

  • RAGFLOW_BASE_URL (prefer an internal/Tailscale address)
  • RAGFLOW_API_KEY (Bearer token; never commit; do not paste into chat)

Recommended ops endpoints:

  • Liveness (no auth): GET $RAGFLOW_BASE_URL/openapi.json
  • Readiness (auth): GET $RAGFLOW_BASE_URL/v1/system/status

If paths differ in your deployment, use openapi.json as the source of truth.

12.3 Local Workspace Helpers (Preferred)

This skill includes built-in helpers under scripts/. They are designed to be:

  • non-interactive
  • safe to run repeatedly
  • machine-readable (short output + non-zero exit code on failure)

Helpers:

  • scripts/ragflow_ping.py
    • Purpose: liveness + readiness checks.
  • scripts/ragflow_smoke.py
    • Purpose: auth verification + minimal API smoke calls.
    • Note: it only uses system endpoints. It does not depend on any application-level data.
  • scripts/ragflow_status.py
    • Purpose: fetch /v1/system/status and print a compact key summary.
  • scripts/ragflow_alert.py
    • Purpose: send an ops alert to Telegram via the openclaw message send CLI.

(Prefer the skill-local scripts so the runbook works in any environment.)

12.3.1 Script Contracts (Inputs / Outputs / Exit Codes)

scripts/ragflow_ping.py

  • Required env:
    • RAGFLOW_BASE_URL
  • Optional env:
    • RAGFLOW_API_KEY (if set, readiness check is performed)
  • Network calls:
    • GET {base_url}/openapi.json (no auth)
    • GET {base_url}/v1/system/status (Bearer auth)
  • Output (examples):
    • OK_LIVE (no api key set)
    • OK_READY keys=...
    • LIVENESS_FAIL ...
    • READINESS_FAIL ...
  • Exit codes:
    • 0 OK
    • 2 liveness failed
    • 3 readiness failed

scripts/ragflow_smoke.py

  • Required env:
    • RAGFLOW_BASE_URL
    • RAGFLOW_API_KEY
  • Network calls:
    • GET {base_url}/v1/system/status (auth)
    • GET {base_url}/v1/system/ping (auth or no-auth depending on deployment)
  • Output (examples):
    • OK smoke
    • FAIL system/status ...
    • FAIL system/ping ...
  • Exit codes:
    • 0 OK
    • 2 system/status failed
    • 3 system/ping failed

scripts/ragflow_status.py

  • Required env:
    • RAGFLOW_BASE_URL
    • RAGFLOW_API_KEY
  • Network calls:
    • GET {base_url}/v1/system/status
  • Output (example):
    • OK keys=key1,key2,... (compact, no secrets)
  • Exit codes:
    • 0 OK
    • 2 HTTP failure
    • 3 invalid JSON

scripts/ragflow_alert.py

  • Purpose: notify humans when ping/smoke fails.
  • Inputs:
    • CLI flags: --title (required), --details (optional)
    • Optional env: OPENCLAW_PRIMARY_CHAT_ID (default target)
  • Behavior:
    • Sends a Telegram message via openclaw message send ....
  • Notes:
    • Do not include secrets in --details.
12.4 Ops Workflow (Suggested)
  1. Connectivity

    • Confirm OpenClaw host can reach RAGFLOW_BASE_URL over the network.
  2. Liveness

    • Check openapi.json responds with HTTP 200.
  3. Readiness

    • Check v1/system/status responds with HTTP 200 when authenticated.
  4. Smoke

    • Run the skill-local smoke helper: scripts/ragflow_smoke.py (system endpoints only).
  5. Escalation artifacts

    • Collect:
      • docker compose ps
      • docker compose logs --tail=200 <ragflow-service>
      • the exact endpoint + HTTP code observed from the OpenClaw side
12.5 Scheduling (Copy/Paste Examples)

Goal: provide copy/paste recipes. An agent can create these tasks when needed.

12.5.1 cron (Linux)

Ping every 10 minutes and alert on failure:

cron
*/10 * * * * RAGFLOW_BASE_URL="http://127.0.0.1:9380" RAGFLOW_API_KEY="${RAGFLOW_API_KEY}" /usr/bin/python3 /path/to/skills/ragflow-runbook/scripts/ragflow_ping.py || /usr/bin/python3 /path/to/skills/ragflow-runbook/scripts/ragflow_alert.py --title "ping failed" --details "ragflow_ping.py exit=$?"

Smoke once per day at 06:05 and alert on failure:

cron
5 6 * * * RAGFLOW_BASE_URL="http://127.0.0.1:9380" RAGFLOW_API_KEY="${RAGFLOW_API_KEY}" /usr/bin/python3 /path/to/skills/ragflow-runbook/scripts/ragflow_smoke.py || /usr/bin/python3 /path/to/skills/ragflow-runbook/scripts/ragflow_alert.py --title "smoke failed" --details "ragflow_smoke.py exit=$?"

Notes:

  • Replace /path/to/skills/... with the real absolute path.
  • Prefer sourcing secrets from a root-owned env file, or use your secret manager. Avoid putting API keys directly into crontab.
12.5.2 launchd (macOS)

Create two plist files (one for ping, one for smoke) and load them with launchctl.

Ping (every 10 minutes):

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
  <dict>
    <key>Label</key>
    <string>ai.openclaw.ragflow.ping</string>

    <key>ProgramArguments</key>
    <array>
      <string>/usr/bin/python3</string>
      <string>/ABS/PATH/skills/ragflow-runbook/scripts/ragflow_ping.py</string>
    </array>

    <key>StartInterval</key>
    <integer>600</integer>

    <key>EnvironmentVariables</key>
    <dict>
      <key>RAGFLOW_BASE_URL</key>
      <string>http://127.0.0.1:9380</string>
      <key>RAGFLOW_API_KEY</key>
      <string>${RAGFLOW_API_KEY}</string>
    </dict>

    <key>StandardOutPath</key>
    <string>/tmp/ragflow-ping.out</string>
    <key>StandardErrorPath</key>
    <string>/tmp/ragflow-ping.err</string>

    <key>RunAtLoad</key>
    <true/>
  </dict>
</plist>

Smoke (daily at 06:05):

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
  <dict>
    <key>Label</key>
    <string>ai.openclaw.ragflow.smoke</string>

    <key>ProgramArguments</key>
    <array>
      <string>/usr/bin/python3</string>
      <string>/ABS/PATH/skills/ragflow-runbook/scripts/ragflow_smoke.py</string>
    </array>

    <key>StartCalendarInterval</key>
    <dict>
      <key>Hour</key>
      <integer>6</integer>
      <key>Minute</key>
      <integer>5</integer>
    </dict>

    <key>EnvironmentVariables</key>
    <dict>
      <key>RAGFLOW_BASE_URL</key>
      <string>http://127.0.0.1:9380</string>
      <key>RAGFLOW_API_KEY</key>
      <string>${RAGFLOW_API_KEY}</string>
    </dict>

    <key>StandardOutPath</key>
    <string>/tmp/ragflow-smoke.out</string>
    <key>StandardErrorPath</key>
    <string>/tmp/ragflow-smoke.err</string>

    <key>RunAtLoad</key>
    <true/>
  </dict>
</plist>

Notes:

  • Replace /ABS/PATH/... with the real absolute path.
  • Prefer storing secrets outside the plist and injecting them safely; do not commit plists with secrets.
12.6 Security Notes
  • Do not expose SVR_HTTP_PORT to the public internet.
  • Prefer allowlisting internal/Tailscale ranges.
  • Store RAGFLOW_API_KEY in env/secret manager only.

References

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts) in skills/ragflow-runbook of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • CHANGELOG.md
  • README.md
  • _meta.json
  • examples/api-examples.sh
  • examples/troubleshooting.md
  • package.json
  • scripts/deploy.sh
  • scripts/healthcheck.sh
  • scripts/ragflow_alert.py
  • scripts/ragflow_ping.py
  • scripts/ragflow_smoke.py
  • scripts/ragflow_status.py

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Ragflow Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ragflow Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ragflow Runbook this skillLeoYeAI/openclaw-master-skills2.2k—~5.3kAutomated safety check: NotesMIT
Swig CI Reproswig/swig6.3k—~1.2kAutomated safety check: PassCustom licence
Youtubeeat-pray-ai/yutu699—~1.1kAutomated safety check: PassMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Docker Jfr Benchmark Loopeclipse-rdf4j/rdf4j420—~945Automated safety check: PassBSD-3-Clause
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only

Similar skills

  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Youtube

    eat-pray-ai/yutu

    A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.

    699 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Docker Jfr Benchmark Loop

    eclipse-rdf4j/rdf4j

    Run a repeatable RDF4J performance loop against one JMH benchmark in Docker with Linux Java 26 and JFR CPU-time profiling.

    420 GitHub stars~945 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Oneclickvirt

    oneclickvirt/oneclickvirt

    OneClickVirt operations skill for managing containers, virtual machines, provider nodes, health checks, and metrics through MCP.

    372 GitHub stars~1.1k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Ragflow Runbook

What does Ragflow Runbook do?

End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only). Ragflow Runbook is an agent skill from LeoYeAI/openclaw-master-skills. End-to-end runbook for deploying, operating, troubleshooting, and monitoring RAGFlow (runtime ops only).

When should I use Ragflow Runbook?

Ragflow Runbook fits situations like: tasks that involve Runbooks and postmortems.

How do I install Ragflow Runbook in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill ragflow-runbook -a claude-code`. Or copy the skill folder (skills/ragflow-runbook in LeoYeAI/openclaw-master-skills) into .claude/skills/ragflow-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Ragflow Runbook in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill ragflow-runbook -a codex`. Or copy the skill folder (skills/ragflow-runbook in LeoYeAI/openclaw-master-skills) into .agents/skills/ragflow-runbook in your project. Codex loads it when a task matches its description.

Can I use Ragflow Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill ragflow-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ragflow-runbook, .gemini/skills/ragflow-runbook, .github/skills/ragflow-runbook and .opencode/skills/ragflow-runbook in your project.

What does Ragflow Runbook need to run?

Going by SKILL.md and its folder, Ragflow Runbook needs Python and a shell for the scripts in its folder, the command-line tools its instructions call (docker, curl and git) and credentials named RAGFLOW_API_KEY, ELASTIC_PASSWORD, MYSQL_PASSWORD and MINIO_PASSWORD. Our summary lists: Python 3; A Bash shell; Docker; A credential in RAGFLOW_API_KEY.

Does Ragflow Runbook access the network?

SKILL.md names 3 domains. In commands or code: github.com and apple.com; the agent is likely to contact these when it follows the instructions. As links in the text: ragflow.io. This is read from the text; nothing was executed.

Is Ragflow Runbook safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo; mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ragflow Runbook use?

Ragflow Runbook is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ragflow Runbook use?

About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ragflow Runbook?

Skills that share tags, products or a category with Ragflow Runbook: Swig CI Repro (swig/swig, 6.3k stars), Youtube (eat-pray-ai/yutu, 699 stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Docker Jfr Benchmark Loop (eclipse-rdf4j/rdf4j, 420 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ragflow Runbook?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.