initializdocs
DeveloperForge runtimeGetting started

Ship to Production

The full pipeline: init, skills, secrets, validate, build, package, deploy.

Once forge try has shown you a working agent, this is the path to a deployable one you own: scaffold it, give it skills and secrets, validate, build, and package it into an egress-enforced container for your own cluster. Each step is independently runnable.

1. Scaffold

forge init my-agent
cd my-agent

The interactive wizard configures the model provider, validates the API key, optionally connects a channel (Slack / Telegram), picks skills, and sets the egress allowlist. For scripted setups, use flags with --non-interactive:

forge init my-agent --model-provider anthropic --non-interactive

forge try --keep writes the same layout to ./forge-quickstart, so you can graduate the demo agent instead of starting from scratch.

2. Add skills

Skills are the agent's capabilities. Install from the registry or write your own:

forge skills add tavily-research        # registry skill
# or author skills/<name>/SKILL.md by hand

See Your First Skill for the SKILL.md format.

3. Configure secrets

Secrets are encrypted at rest (AES-256-GCM), per-agent:

forge secret set ANTHROPIC_API_KEY sk-...
forge secret set SLACK_BOT_TOKEN xoxb-...

4. Validate

Catch config, egress, and policy problems before building:

forge validate

5. Run locally

forge run                 # A2A server on :8080
forge serve               # long-running service
forge run --with slack    # attach a channel

Tail the audit log while it runs to see tool calls, egress decisions, and guardrail blocks, the same stream forge try renders inline.

6. Build

Compile the agent and its dependencies into a runnable artifact. Build-time egress allowlisting and Ed25519 artifact signing happen here:

forge build

7. Package and deploy

Produce an egress-enforced container image and the deployment manifests for your cluster:

forge package

The generated image enforces the outbound domain allowlist at runtime (including subprocess HTTP via the local egress proxy), so the deployed agent has the same network posture you validated locally. Deploy it with your own pipeline.

On this page