- Skill ID
- google/agents-cli/google-agents-cli-deploy
- Publisher
- Repository
- agents-cli
- Installs
- 11,136
- Files
- 8
- Synced
- Sep 16, 2026
Open any RiverX project, open the Skills panel in the chat, and search for this identifier. The files are fetched from the source repository at install time.
google/agents-cli/google-agents-cli-deployInstalls these files- references/agent-runtime.md
- references/batch-inference.md
- references/cicd-pipeline.md
- references/cloud-run.md
- references/gke.md
- references/terraform-patterns.md
- references/testing-deployed-agents.md
- SKILL.md
What this skill tells the agent
Deployment Guide
Requires:agents-cli(uv tool install google-agents-cli) — install uv first if needed.
Prefer using theagents-clicommands throughout this guide — they wrap Terraform, Docker, and deployment into a tested pipeline. If your project isn't scaffolded yet, see/google-agents-cli-scaffoldto add deployment support first.
Reference Files
For deeper details, consult these reference files in references/:
- `cloud-run.md` — Scaling defaults, Dockerfile, session types, networking
- `agent-runtime.md` — container-based deploy, unified FastAPI app, the
/apipassthrough, Terraform resource, deployment metadata, CI/CD differences - `gke.md` — GKE Autopilot cluster, Kubernetes manifests, Workload Identity, session types, networking
- `terraform-patterns.md` — Custom infrastructure, IAM, state management, importing resources
- `batch-inference.md` — BigQuery Remote Function trigger; for Pub/Sub / Eventarc on ADK see
/google-agents-cli-adk-code - `cicd-pipeline.md` — Full CI/CD pipeline setup,
infra cicdflags, runner comparison, WIF auth, pipeline stages - `testing-deployed-agents.md` — Testing instructions per deployment target, curl examples, load tests
Observability: See the /google-agents-cli-observability skill for Cloud Trace, prompt-response logging, BigQuery Analytics, and third-party integrations.Deployment Target Decision Matrix
Choose the right deployment target based on your requirements:
| Criteria | Agent Runtime | Cloud Run | GKE |
|---|---|---|---|
| Scaling | Managed auto-scaling (configurable min/max, concurrency) | Fully configurable (min/max instances, concurrency, CPU allocation) | Full Kubernetes scaling (HPA, VPA, node auto-provisioning) |
| Networking | VPC-SC and PSC-I supported (private VPC connectivity via network attachments) | Full VPC support, direct VPC egress, IAP, ingress rules | Full Kubernetes networking |
| Session state | Managed Agent Engine sessions (ADK wires VertexAiSessionService automatically) | In-memory (dev), Cloud SQL, or Agent Platform Sessions backend | In-memory (dev), Cloud SQL, or Agent Platform Sessions backend |
| Batch/event processing | Trigger endpoints reachable via the Agent Engine /api passthrough | Native trigger endpoints (Pub/Sub, Eventarc); ADK: see /google-agents-cli-adk-code | Custom (Kubernetes Jobs, Pub/Sub) |
| Cost model | vCPU-hours + memory-hours (not billed when idle) | Per-instance-second + min instance costs | Node pool costs (always-on or auto-provisioned) |
| Setup complexity | Lower (managed, purpose-built for agents) | Medium (Dockerfile, Terraform, networking) | Higher (Kubernetes expertise required) |
| Best for | Managed infrastructure, minimal ops | Custom infra, full networking control | Full Kubernetes control |
Ask the user which deployment target fits their needs. Each is a valid production choice with different trade-offs.
All three targets are container-based, so any language works.
Product name mapping: "Agent Engine" / "Vertex AI Agent Engine" is now Agent Runtime. Use --deployment-target agent_runtime.Ambient / scheduled / event-driven agents (ADK projects): ADK'strigger_sourcesregisters/apps/{app}/trigger/*endpoints on the same FastAPI app for all targets. On Cloud Run / GKE these are public HTTP routes you point a Pub/Sub push subscription or Eventarc trigger at; on Agent Runtime the same routes are reachable through the Agent Engine/apipassthrough (e.g..../reasoningEngines/v1/{resource}/api/apps/{app}/trigger/pubsub). Cloud Run remains the simplest target for unauthenticated trigger sources. See/google-agents-cli-adk-code(references/adk-python.md, section "12. Event-Driven / Ambient Agents") for thetrigger_sourcespattern.
OAuth / user consent agents: Use Agent Runtime with Gemini Enterprise for agents that need OAuth 2.0 user consent (e.g., accessing Google Drive, Calendar, or other user-scoped APIs). Cloud Run does not currently support managed OAuth flows. For a worked ADK example, look up OAuth user consent in the topic index in/google-agents-cli-adk-code→references/samples.md.
Deploying to Dev
Deploy Workflow
Task tracking: Deployment involves multiple sequential steps (infra setup, CI/CD configuration, deploy, verification). Use a task list to track progress through these steps — skipping one often causes failures in later steps that are hard to trace back.
- If prototype (no deployment target), first enhance:
agents-cli scaffold enhance . --deployment-target <target> - Notify the human: paste the eval scores and test results, then ask "Ready to deploy to dev?"
- Wait for explicit approval
- Once approved:
agents-cli deploy
Agent Runtime timeout recovery: Agent Runtime deploys can take 5-10 minutes and may exceed command timeouts. If the deploy command is cancelled or times out, the deployment continues server-side. Run agents-cli deploy --status to check progress — poll every 60 seconds until it reports completion or failure.IMPORTANT: Never run agents-cli deploy without explicit human approval.
Do NOT run `agents-cli infra single-project` before deploying. It is not a prerequisite —agents-cli deployworks on its own. Run it separately if the user needs observability features (prompt-response logging, BigQuery analytics) — see/google-agents-cli-observability.
Single-Project Infrastructure Setup (Optional — Advanced)
agents-cli infra single-project runs terraform apply in deployment/terraform/single-project/. Use this to provision single-project GCP infrastructure without CI/CD (service accounts, IAM bindings, telemetry resources, Artifact Registry). Also useful to test things in a single project before going to production. It is NOT required for deploying.
# Optional — provision infrastructure in a single GCP project
agents-cli infra single-projectNote:agents-cli deploydoesn't automatically use the Terraform-createdapp_sa. Pass the service account explicitly:agents-cli deploy --service-account SA_EMAIL.
Deploy Flag Reference
| Flag | Description | Targets |
|---|---|---|
--project | GCP project ID | All |
--region | GCP region | All |
--service-account | Service account email for the deployed agent | All |
--service-name | Override the deployed service name (Cloud Run service or Agent Runtime display name); defaults to the project name. If you override it, consider updating your Terraform and CI (if present) — they name resources from the project name. Not supported for GKE, whose names are fully owned by Terraform. | Agent Runtime, Cloud Run |
--secrets | Comma-separated ENV=SECRET or ENV=SECRET:VERSION pairs | Agent Runtime, Cloud Run |
--update-env-vars | Comma-separated KEY=VALUE environment variables | Agent Runtime, Cloud Run |
--agent-identity | Enable agent identity (Preview) | Agent Runtime |
--network-attachment | Network attachment resource name for PSC interface (enables private VPC connectivity) | Agent Runtime |
--dns-peering-domain | DNS peering domain suffix, e.g. my-internal.corp. (requires --network-attachment) | Agent Runtime |
--dns-peering-project | Project ID hosting the Cloud DNS managed zone for DNS peering (requires --network-attachment) | Agent Runtime |
--dns-peering-network | VPC network name in the target project for DNS peering (requires --network-attachment) | Agent Runtime |
