Offline profile¶
Run the whole lifecycle offline, from create to production,
with no internet access at all. The CLI calls this the disconnected profile, and two
commands check it for you.
Local is not disconnected¶
Two different promises:
- Runs locally: the orchestration runs on your machine.
run,playgroundandevalstart a local server, but the model can still be a hosted API, andsetupstill fetches skills from GitHub. - Runs disconnected: nothing in the lifecycle needs the internet. The model, the judge, the package index, the images, the charts, the traces and CI all live on your network.
The disconnected profile is the second. Nothing in it is on by default; the checklist below
sets it up, and login --profile disconnected and
infra check --profile disconnected verify it.
The profile¶
- An on-network model.
MODEL_PROVIDER=openai-compatiblewithOPENAI_BASE_URLat a server on your network (vLLM, TGI, Ollama) and a model that supports tool calling.MODEL_API_KEYis optional for servers that need no key. In a cluster, setenv.OPENAI_BASE_URLinvalues-<env>.yaml;deployrefuses theCHANGE-MEdefault outsidedev. - An on-network judge.
JUDGE_MODEL_PROVIDER=openai-compatiblewithJUDGE_BASE_URL,JUDGE_MODEL_NAMEand, if needed,JUDGE_API_KEY. Without them the judge uses the agent's provider. - The
fastapiruntime. The LangGraph Server image checks its licence with a hosted service at startup, solanggraph-serveris outside the profile. - A private package index. Point uv at it (
UV_INDEX_URL) and install from the lock withgraph-agents-cli install --locked. The image's builder stage runsuv sync --frozenfromuv.lockas well, so the build needs the same index. - Mirrored base images. The Dockerfile's
PYTHON_IMAGE(python:3.12.14-slim-bookworm) andUV_IMAGE(ghcr.io/astral-sh/uv:0.12.18) build arguments name the images; change their defaults to your mirror. - An on-network registry, such as Harbor or
registry:2, set withcreate --registryorscaffold enhance --registry.ghcr.io,docker.io,quay.io,gcr.ioand the cloud registries (*.amazonaws.com,*.pkg.dev,*.azurecr.io) are hosted. - Vendored subcharts. The dev Postgres and Redis subcharts come from
registry-1.docker.io. Runhelm dependency build deployment/helm/<name>on a connected machine and bringdeployment/helm/<name>/charts/across (the scaffold's.gitignoreexcludes it, so drop that line if you commit it). Withcharts/in place,deployskips the fetch. Pointpostgresql.image.registry(andredis.image.registry) at your mirror. - Tracing off, or OTLP to a collector in the cluster. Leave
TRACING_ENABLEDoff, or set it withOTEL_EXPORTER_OTLP_ENDPOINT(tracing.otlpEndpointin the chart) at an in-cluster collector. NoLANGSMITH_API_KEY: hosted LangSmith is outside the profile. See Observability. - No update check.
export GRAPH_AGENTS_CLI_NO_UPDATE_CHECK=1, or the CLI asks GitHub for a newer release (at most every 12 hours) andinforunsnpx skills list. - The CLI from a mirror. Set
GRAPH_AGENTS_CLI_INSTALL_SPEC, with{version}where the version goes, sosetup,update, thescaffold upgradebaseline and new projects' CI install from your mirror (see Upgrading projects). A mirror of PyPI serves releases from 0.3.1 on asgraph-agents-cli=={version}, withUV_INDEX_URLnaming the mirror; earlier releases exist only as git tags. - The skills from the wheel.
setuptries the repository first, then installs the skills bundled in the CLI's wheel withnpx skills add, and withoutnpxcopies them into~/.agents/skills(./.agents/skillswith--workspace). No git or network is needed for the last two. - No GitHub-hosted CI. Use
cd: skipand deploy directly, unless an on-network GitHub Enterprise Server runs Actions (declare it withGH_HOST). Every project also haspr_checks.yamlwithruns-on: ubuntu-latest: point it at your own runner label, or remove it.
Set it up¶
export GRAPH_AGENTS_CLI_NO_UPDATE_CHECK=1
export GRAPH_AGENTS_CLI_INSTALL_SPEC='git+https://git.example.com/graph-agents-cli@v{version}'
export UV_INDEX_URL=https://pypi.example.com/simple
graph-agents-cli create my-agent --model-provider openai-compatible --model my-model \
--registry registry.internal.example/agents
cd my-agent
cp .env.example .env # set OPENAI_BASE_URL to the on-network server
graph-agents-cli install --locked
graph-agents-cli login --write-env --profile disconnected
create defaults to fastapi and cd: skip, and --registry keeps the image off hosted
registries.
Check it¶
Both checks fail on any hosted dependency. login reads your environment and .env;
infra check reads the project and the chart values.
| Check | login --profile disconnected |
infra check --profile disconnected |
|---|---|---|
| A hosted model provider | fails | fails |
A hosted judge (JUDGE_) |
fails | |
LANGSMITH_ set |
fails | |
| Tracing on without an OTLP endpoint | fails | fails (tracing.enabled without tracing.) |
OPENAI_BASE_URL |
required; <url>/ is probed (advisory) |
must be set in the chart env |
| GitHub-hosted CI | fails on a GitHub-hosted runner label (ubuntu-*, windows-*, macos-*) in .github/; warns when cd is not skip |
fails when cd is not skip; warns instead when GH_HOST names a GitHub Enterprise Server |
The langgraph-server runtime |
fails | fails |
| A hosted registry | fails | |
GRAPH_ not 1 |
warns | warns |
login exits 1 when a check fails (0 with --status); infra check exits 1 when a required
item is missing.
A new openai-compatible project fails one check, because of the pr_checks runner:
$ graph-agents-cli login --profile disconnected
...
✓ provider: model provider openai-compatible (.env)
! provider_key: MODEL_API_KEY not set (optional for servers that do not require a key)
Set MODEL_API_KEY in .env or run 'graph-agents-cli login --write-env'.
! openai_base_url: OPENAI_BASE_URL set but http://127.0.0.1:21248/v1/models is unreachable (ConnectError)
Start the on-network model server or fix OPENAI_BASE_URL; the check is advisory.
✓ api_key: API_KEY set (.env)
- judge: judge defaults to the agent's provider and key
- tracing: TRACING_ENABLED is not true; tracing off
✓ kubeconfig: current context: docs-unreachable
✓ profile.runtime: runtime fastapi
✗ profile.ci: GitHub-hosted CI detected: .github/workflows/pr_checks.yaml uses a GitHub-hosted runner
CI/CD is outside the disconnected profile unless an on-network GitHub Enterprise Server hosts Actions; use 'cd: skip' with direct-mode deploy.
✓ profile.update_check: GRAPH_AGENTS_CLI_NO_UPDATE_CHECK=1
5 ok, 2 warning(s), 1 failed, 2 skipped.
Nothing is stored by the CLI.
With runs-on: [self-hosted, linux] in pr_checks.yaml it passes:
A default project (the openai provider, a LangSmith key and argocd on GitHub-hosted
runners) fails three checks:
✗ provider: model provider openai (manifest) is hosted; the disconnected profile requires openai-compatible
Set MODEL_PROVIDER=openai-compatible and OPENAI_BASE_URL to an on-network server.
✗ tracing: LANGSMITH_API_KEY set (.env); LangSmith is a hosted dependency
Unset LANGSMITH_API_KEY and export traces over OTLP to an in-cluster collector, or disable tracing.
✗ profile.ci: GitHub-hosted CI detected: .github/workflows/pr_checks.yaml uses a GitHub-hosted runner; .github/workflows/promote-to-prod.yaml uses a GitHub-hosted runner; .github/workflows/staging.yaml uses a GitHub-hosted runner
infra check --profile disconnected adds its rows to the usual report:
│ disconnected: model │ ok │ yes │ openai-compatible │
│ provider │ │ │ │
│ disconnected: │ ok │ yes │ http://vllm.models.svc.cl… │
│ OPENAI_BASE_URL │ │ │ │
│ disconnected: runtime │ ok │ yes │ fastapi │
│ disconnected: registry │ ok │ yes │ registry.internal.example… │
│ disconnected: tracing │ ok │ yes │ off │
│ disconnected: ci/cd │ ok │ yes │ cd is skip: lifecycle │
│ │ │ │ covered by direct-mode │
│ │ │ │ deploy │
│ disconnected: update check │ ok │ no │ GRAPH_AGENTS_CLI_NO_UPDAT… │
└─────────────────────────────┴────────┴──────────┴────────────────────────────┘
All required prerequisites are present.
Add --env <env> to check the cluster as well; see Deploy to Kubernetes.
What stays outside the profile¶
eval submit, which uploads results to LangSmith.- The
langgraph-serverruntime, until your licence works without a hosted check. helm-pushandargocdon GitHub-hosted Actions. On an on-network GitHub Enterprise Server,infra checkwarns instead of failing; setGH_HOST(andGH_ENTERPRISE_TOKENorGITHUB_TOKEN) sodeployopens its pull requests there.
Next steps¶
-
Install the CLI and the skills, and what
setupfalls back to. -
Direct deploys, local clusters and vendored chart dependencies.
-
OTLP tracing to a collector in your cluster.
-
GRAPH_AGENTS_CLI_*,OPENAI_BASE_URL,JUDGE_*and the rest.