Deploying
Bishop is one long-running process that logs JSON to stdout and errors to stderr, so any process supervisor works. It runs in the foreground and never restarts itself.
Two ways to run it:
- Linux and systemd: the npm package on a host, with a hardened unit. The host is the agent's shell, so you install what the agent needs.
- Container:
ghcr.io/agent-deployment-co/bishop, which already carries the agent's usual tools.
Network
Slack and Gmail need outbound access only, since one holds a socket open and the other polls. Teams POSTs activities to an endpoint, so Bishop serves one when Teams credentials are present. That endpoint binds loopback like every other port Bishop opens, and a tunnel gives it a public hostname and a certificate without an inbound firewall rule. See The endpoint.
Logs
BISHOP_LOG_LEVEL=info bishopBISHOP_LOG_LEVEL=debug adds tool activity and every routing decision. Pipe through npx pino-pretty to read it by eye. It works in .env as well as exported, and an exported one wins. A value that isn't a level (trace, debug, info, warn, error, fatal, silent) logs a warning and leaves the level at info.
Startup checks
At startup Bishop checks that the agent can launch, resolves the allow lists, and connects to each interface, failing with a specific message if any of those doesn't work. A clean start proves the harness is installed and authenticated, and costs nothing. A first turn that fails after that is usually a bad --model or --effort, which nothing validates at startup.
What has to persist
- Bishop's own directory, the one it runs from:
.env,bishop.dbwith its-waland-shmfiles, and.bishop/. - The home directory of the user Bishop runs as, which holds both harnesses' logins and session transcripts. Wiping it breaks every existing thread, because Bishop resumes a thread by handing the harness a session it no longer has.
Back up bishop.db with the process stopped, or through SQLite's backup API. Copying the file while Bishop is running misses whatever is still in bishop.db-wal. Bishop takes its own copy before a schema migration, which covers an upgrade but not a disk.
Restarts
A restart kills whichever turn asked for it. An agent that edits its own unit file and restarts the service takes down the process running that same turn. It comes back clean, since thread state lives in Bishop's own directory, so the conversation resumes on the next message. But the response that triggered the restart cuts off mid-stream, which reads as a crash to whoever is waiting on it unless they're told to expect it.
Bishop notices neither a revoked Slack app nor a dead socket, so a supervised process can look healthy while receiving nothing. Restart it if the agent goes quiet.