Graphs in, agents out.
Build, evaluate and deploy LangGraph agents on your own Kubernetes¶
One CLI, and six skills for your coding agent, take an agent from
create to a hardened Helm release: a streaming chat API, shared-key or per-user
auth, an outbound API policy, human approval of risky calls and an eval gate CI can enforce.
Now on PyPI: uv tool install graph-agents-cli,
with skills tuned by SkillOpt.
# install the CLI from PyPI, then the skills
uv tool install graph-agents-cli
graph-agents-cli setup
# create an agent and ask it a question: the fake model needs no key
graph-agents-cli create my-agent && cd my-agent
cp .env.example .env
export MODEL_PROVIDER=fake
graph-agents-cli login --write-env
graph-agents-cli install
graph-agents-cli run "What's the weather in San Francisco?"
Get started in three steps¶
Everything runs on your machine first; a model key and a cluster come later.
-
Install the CLI and the skills
One
uv tool install graph-agents-clifrom PyPI, thensetupadds the skills to the coding agents it finds. -
Create and run an agent
createa project, letlogin --write-envfill in.env,install, thenruna prompt. Five minutes on the fake model, no key. -
Evaluate and deploy it
Add an API tool under a policy, pass the
eval rungate, thendeploy --env devto a local kind cluster.
What you get¶
A generic toolkit: nothing in the CLI or the generated project is specific to one domain or one company.
-
Scaffold a real service
createrenders a LangGraph project with a streaming chat API, an A2A endpoint, an eval harness, a hardened Helm chart and GitHub Actions workflows. -
Run it locally
runsends a prompt through a temporary local server;playgroundserves a dev chat page with reload. A deterministic fake model needs no key. -
Evaluate with a gate
eval runsends every dataset case to the agent, grades deterministic checks and LLM judges, and its exit code is the gate your CI enforces. -
Deploy to any Kubernetes
deploy --env dev|staging|prodwith Helm, directly or through Argo CD pull requests. Local clusters (kind, k3d, minikube, Docker Desktop) need no registry push: any valid name, such as--registry localhost/dev, works. -
Secure by default
One auth policy on every surface (shared bearer, OIDC/JWT or your own), an outbound API allow-list and human approval of the calls you choose.
-
Built for coding agents
Six bundled skills teach your coding agent the same lifecycle, so you can ask it to "use graph-agents-cli to build ..." and review each step. They are tuned with SkillOpt on a 104-task benchmark: 0.84 to 0.97 on Claude Code against the 0.2 skills.
One lifecycle, from prototype to production¶
Each stage is a command, and each command's exit code tells a script or a coding agent what happened.
-
A project with its API, auth, policy, chart and CI.
createscaffold enhance -
Write tools, declare the APIs they call, try it.
runplaygroundapilint -
Grade every case; the exit code is the gate.
eval runeval compare -
Build, apply the Secret, roll out with Helm or Argo CD.
buildsecrets applydeploy -
Watch rollouts, decide approvals, upgrade the project.
deploy --statusapprovalsscaffold upgrade
Every change goes round again: develop, evaluate, deploy. The lifecycle explains each stage.
Where to next¶
-
Get started
Install, run your first agent in five minutes, then follow a tutorial.
-
Guides
Authentication, the API policy, approvals, evaluation, deployment, secrets and more.
-
Reference
Every command and flag, environment variables, the HTTP API, exit codes and skills.