---
url: https://bishop.agentdeployment.co/deploying/container.md
description: Running the Bishop container image, with its volumes, setup commands and tags.
---

# Container

`ghcr.io/agent-deployment-co/bishop` runs Bishop on Debian with Node 24, for `linux/amd64` and `linux/arm64`. The image is the agent's shell as well as Bishop's, so it carries git, `gh`, ripgrep, jq, curl, ssh, and python3 alongside both harness SDKs. `uv` and `uvx` are there too, with CPython 3.14 already installed and on `PATH` as `python3.14`, since Debian's `python3` is externally managed and won't let anything install into it.

## Volumes

Two directories to persist. `/data` is the working directory, holding everything Bishop writes:

```
/data/.bishop/config.json    configuration
/data/.bishop/agents/        cloned agents, when --agent is a git URL
/data/bishop.db              the thread-to-session mapping
```

`/home/node` holds what the harnesses write: their logins, and the session transcripts they resume from. A home directory that dies with the container leaves every existing thread asking for a transcript the harness no longer has. Mount it or lose every conversation on the next deploy.

Bishop runs as uid 1000 and needs to write both volumes. On Kubernetes that means a `fsGroup` in the pod's security context, or volumes already owned by 1000.

## Running it

Credentials go in the environment rather than a `.env` file:

```sh
docker run -d --name bishop \
    -v bishop-data:/data -v bishop-home:/home/node \
    -e BISHOP_SLACK_BOT_TOKEN -e BISHOP_SLACK_APP_TOKEN \
    -e ANTHROPIC_API_KEY \
    -e GIT_CONFIG_COUNT=2 \
    -e GIT_CONFIG_KEY_0=user.name -e GIT_CONFIG_VALUE_0="Agent" \
    -e GIT_CONFIG_KEY_1=user.email -e GIT_CONFIG_VALUE_1="agent@example.com" \
    ghcr.io/agent-deployment-co/bishop \
    --agent https://github.com/you/your-agent.git --auto-update
```

The entrypoint is `bishop`, so arguments after the image are its flags, and any other command works the same way:

```sh
docker run --rm -v bishop-data:/data ghcr.io/agent-deployment-co/bishop gc
```

Set a git identity, as above, or the agent can't commit what it does in a worktree. `GIT_CONFIG_COUNT` reaches every snapshot and worktree Bishop creates, which a `git config` run in one directory doesn't.

## Setup commands

Setup commands that need a browser or a terminal, like `bishop slack setup` and `bishop gmail setup`, are meant to be run on a laptop. Carry the tokens they produce to the container as environment variables, and the `.bishop/config.json` they write into the `/data` volume.

## Tags

`latest` and `sha-<commit>` from `main`, plus `<version>` and `<major>.<minor>` for each release.

## Limits

The image doesn't include nono, so the [sandbox](/running/sandbox) isn't supported in it yet.
