Deployment & CI¶
Container image¶
FROM python:3.12-slim
WORKDIR /app
COPY pyproject.toml ./
RUN pip install --no-cache-dir ".[server,graph,llm,http]"
COPY . .
RUN langstitch compile # precompile application.json for fast startup
EXPOSE 8000
CMD ["langstitch", "run", "--host", "0.0.0.0", "--port", "8000"]
Provide secrets at runtime (-e OPENAI_API_KEY=... / orchestrator secrets), not in
the image. The server exposes /health (liveness), /info (registered components),
and /invoke.
CI & release¶
- Test matrix across Python 3.10โ3.13;
python -m build+twine checkvalidate the distribution. - Publish via PyPI Trusted Publishing (OIDC) on a version tag โ no token secret.
Consumers then add
langstitch-sdk>=0.3.2topyproject.toml.
# .github/workflows/release.yml (sketch)
name: release
on:
push:
tags: ["v*"]
jobs:
build:
runs-on: ubuntu-latest
strategy:
matrix:
python: ["3.10", "3.11", "3.12", "3.13"]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python }}
- run: pip install -e ".[all]" && pytest -q
publish:
needs: build
runs-on: ubuntu-latest
permissions:
id-token: write # PyPI Trusted Publishing (OIDC)
steps:
- uses: actions/checkout@v4
- run: pip install build && python -m build
- uses: pypa/gh-action-pypi-publish@release/v1
Health checks¶
Wire /health to your orchestrator's liveness/readiness probes.
Related¶
- Production hardening
- CLI โ
compile,run