CtrlK
BlogDocsLog inGet started
Tessl Logo

service-publishing

Expose worker HTTP services via Higress gateway. Use when admin asks to publish a worker's web app or API to make it externally accessible.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Service Publishing

Overview

Expose HTTP services running inside worker containers to the outside world via the Higress gateway. Each exposed port gets an auto-generated domain name.

How It Works

Add expose to a Worker's spec to publish container ports. The controller automatically creates the Higress domain, service source, and route.

Auto-generated domain pattern:

worker-{name}-{port}-local.agentteams.io

Example: worker alice exposing port 8080worker-alice-8080-local.agentteams.io

Usage

Via CLI

# Expose port 8080 for worker alice
agt apply worker --name alice --model qwen3.5-plus --expose 8080

# Expose multiple ports
agt apply worker --name alice --model qwen3.5-plus --expose 8080,3000

# Check exposed ports
agt get worker alice
# Look for status.exposedPorts in the output

# Remove exposed ports (update without --expose)
agt apply worker --name alice --model qwen3.5-plus

Via YAML

apiVersion: agentteams.io/v1beta1
kind: Worker
metadata:
  name: alice
spec:
  model: qwen3.5-plus
  expose:
    - port: 8080
    - port: 3000

Apply with:

agt apply -f worker.yaml

Workers referenced by a Team

Configure expose on the Worker CR, then reference that Worker from the Team:

apiVersion: agentteams.io/v1beta1
kind: Worker
metadata:
  name: lead
spec:
  model: qwen3.5-plus
---
apiVersion: agentteams.io/v1beta1
kind: Worker
metadata:
  name: backend
spec:
  model: qwen3.5-plus
  expose:
    - port: 8080
---
apiVersion: agentteams.io/v1beta1
kind: Team
metadata:
  name: dev-team
spec:
  workerMembers:
    - name: lead
      role: team_leader
    - name: backend
      role: worker

Important Notes

  • The worker container must be running and the service must be listening on the specified port before it can be accessed
  • Domains are auto-generated; custom domains are not yet supported
  • No authentication is configured on exposed routes (public access)
  • Docker DNS resolves the worker container name (agentteams-worker-{name}) automatically within agentteams-net
  • To stop exposing a port, remove it from the expose list and re-apply
Repository
agentscope-ai/AgentTeams
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.