Compared with google-agents-cli¶
graph-agents-cli is a fork of google-agents-cli. It keeps the lifecycle and the scaffold engine, and targets LangGraph on any Kubernetes cluster instead of ADK on Google Cloud.
graph-agents-cli started from google-agents-cli 1.6.1, with the Google Cloud specific parts removed and the agent framework, deployment target, evaluation backend and observability replaced. NOTICE lists the modifications; files kept from the original project keep their Google LLC copyright headers. This comparison is as of google-agents-cli 1.7.0 (September 2026).
What it keeps¶
- The lifecycle:
setup,createandscaffold,run,eval,deploy, extensions and a suite of coding-agent skills, in the same order and with the same shape. - The scaffold engine: template layering, remote templates, and the 3-way merge behind
scaffold enhanceandscaffold upgrade. - The extension system: command overrides and additions from git repositories or local paths.
Side by side¶
| Area | graph-agents-cli | google-agents-cli |
|---|---|---|
| Agent framework | LangGraph (one Python template) | ADK (Python and other languages), plus a LangChain template |
| Where agents run | Any Kubernetes cluster, with Helm | Agent Runtime, Cloud Run, GKE |
| Continuous delivery | Direct deploy, a self-hosted runner (helm-push), or Argo CD through pull requests (argocd) |
Cloud Build or GitHub Actions pipelines set up by infra cicd |
| Infrastructure | infra check reports prerequisites; creates nothing |
infra single-project and infra cicd provision with Terraform |
| Authentication | In the app, on every surface: shared-bearer, jwt (OIDC) or a custom policy |
Google Cloud's identity layer |
| Outbound calls | api-policy.yaml in the project, enforced at runtime and checked by lint, with human approval of chosen calls |
An Agent Gateway bound at deploy time (Agent Runtime) |
| Evaluation | Local deterministic checks and model judges, an enforceable gate, a keyless fake model | Agent Platform evaluation, dataset synthesis, user simulation, prompt optimisation |
| Secrets | secrets apply and secrets status for an allow-listed Kubernetes Secret |
Secret Manager |
| Observability | LangSmith or OpenTelemetry, opt-in, metadata-only by default | Cloud Trace, logging, BigQuery Agent Analytics |
| Publishing | Out of scope | Gemini Enterprise, Agent Registry |
| Distribution | PyPI, and a pinned git tag per release | PyPI |
Where it goes further¶
- An enforceable eval gate: every planned case accounted for, deterministic checks and
mandatory judges with no threshold, quality metrics with an explicit
min_pass_rate, exit codes CI can use,eval compare --fail-on-regression, and a deterministic fake model for keyless CI. See Evaluation. - An outbound API policy enforced at runtime and checked by
lint, with human approval of the calls a prompt injection could abuse. See Outbound API policy. - Kubernetes Secrets management (
secrets applyandstatus, allow-listed keys, pre-deploy checks) and Argo CD GitOps through pull requests. - A disconnected profile, verified by
loginandinfra check. See Offline profile. - Self-hosted auth policies (shared bearer, OIDC/JWT, custom) enforced in the app on every surface, instead of a cloud provider's identity layer.
Where it is behind¶
- Evaluation: no prompt optimisation, dataset synthesis, user simulation or results fetch
(
eval optimize,eval dataset synthesize,eval resultsupstream); eval cases are written by hand. - Infrastructure: no provisioning.
infra checkonly reports; upstream'sinfra cicdcreates the CI/CD setup with Terraform. - Templates and languages: one Python LangGraph template and no sample catalogue, against upstream's ADK templates in several languages, samples and a LangChain template.
- Lint: no type checker or spell checker in the generated project's
lint. - Maturity: upstream has a long release history. This project has four tagged releases
(
v0.1.0,v0.2.0,v0.3.0,v0.3.1), this documentation site (published once the maintainers enable it) and the skills; it is on PyPI from 0.3.1. - Upstream fixes are ported by hand after 1.6.1, following the upstream-sync process in CONTRIBUTING.md. For example, remote templates still skip symlinks, which upstream 1.7.0 copies when they stay inside the repository.
Each gap is tracked in Known issues, for example KI-093.
Out of scope¶
Google Cloud targets (Agent Runtime, Cloud Run, GKE-specific integrations), publishing to Gemini Enterprise and BigQuery analytics are out of scope, not gaps.
-
What graph-agents-cli does, in one page.
-
Parked issues, each with its impact and workaround.
-
Every release and its migration steps.