Back
Kevin Riedl

14 min read · 1 Oct 2026
Last reviewed

Next
Made on your device, with no Instagram connection. We copy the post link for Instagram’s Link sticker.

SmythOS Studio Self-Hosting: Docker Setup, Costs and Limits

A visual agent builder becomes much more interesting when you can keep the builder and its runtime on infrastructure you control. That is the appeal of SmythOS Studio: connect language models, APIs and logic on a canvas, inspect the workflow as you build it, and run the resulting agent through the SmythOS Runtime Environment, or SRE. The repository describes chatbot and API deployment paths, not just a diagram editor. Read the Studio repository and package overview.

The important distinction is between free software, a local application and a production-ready service. Studio gives you the first and a route to the second. The third still needs an operating plan.

Source review: . Repository details below refer to commit 3e1ea87e6718fdfdb24365b2184fbd1daa9f94f8. This is a documentation and source review, not a hands-on deployment benchmark. The suggested configuration and acceptance tests have not been executed against a running Studio instance.

Is SmythOS Studio really free and open source?

The reviewed Studio repository is MIT-licensed. Its license permits use, modification and distribution, including commercial use, subject to retaining the required copyright and permission notices. It does not provide a warranty. That is a software-license statement, not a promise that every model, dependency, integration or hosted SmythOS service shares the same terms. Inspect the actual MIT license.

For a self-hosted deployment, separate the costs into four buckets: model inference, infrastructure, external tools and the time needed to operate the system. A free editor does not make a paid model call free. Running a local model moves inference costs onto your hardware and operations rather than eliminating them.

Our suggested budgeting formula is simple: monthly operating cost = compute and storage + model usage + paid APIs + operational work. Keep implementation effort separate. For a broader measurement framework, use our existing AI agent cost-per-action guide rather than treating the repository's price as the cost of the whole workflow.

What can you build on the visual canvas?

The component documentation covers API calls, JSON transformations, language-model steps, loops and parallel branches. That makes Studio worth evaluating for bounded workflows such as classifying an incoming request, retrieving information from an internal service and drafting a response. These are documented building blocks, not proof that any particular business workflow is ready without configuration. Explore the documented workflow components.

There is also a path beyond predefined blocks. The Code component supports JavaScript for transformations, validation and lightweight logic. Its documented interface uses _output for results and _error for structured error information. A developer can therefore keep a predictable rule in code instead of asking a model to guess it. Check the Code component's input and output contract.

Our view: the useful part of a canvas is not that it removes engineering. It makes the intended sequence visible to the people who understand the process. You still need to specify what happens when an API times out, a result is missing or an action is not authorized.

How do you install SmythOS Studio with Docker?

Use the Docker path for an evaluation, not the separate local-development instructions. The reviewed repository guide specifies Docker Compose v2, at least 8 GB RAM and 10 GB free disk space. Treat those as the guide's setup requirements, not capacity estimates for your agents or local models. Read the repository's Docker setup guide.

Start by cloning the repository and creating the environment file:

git clone https://github.com/SmythOS/smythos-studio.git
cd smythos-studio
git checkout --detach 3e1ea87e6718fdfdb24365b2184fbd1daa9f94f8
cp .env.compose.example .env
chmod 600 .env

The checkout pins the configuration source, not the application image. The Compose file still points at a floating image tag, discussed below.

Before starting, edit .env. Replace the sample database, Redis and session secrets, and configure the credentials for your chosen provider. Generate a separate strong value for each secret, for example with openssl rand -hex 32, and keep the file out of version control and shared logs. The supplied template includes sample credentials, LOG_LEVEL="debug", an HTTP application URL and ENABLE_TLS=false. Inspect the exact Compose environment template.

For a laptop-only evaluation, the following are suggested edits to the existing .env values, not an additional deployment profile. Add the dashboard variable because it is not present in the template:

EXPOSE_TRAEFIK_PORT=127.0.0.1:6060
EXPOSE_HTTPS_TRAEFIK_PORT=127.0.0.1:6062
EXPOSE_TRAEFIK_DASHBOARD_PORT=127.0.0.1:8089
LOG_LEVEL=info

These values use the host-address slot in the reviewed Compose port mappings. Docker normally publishes ports on all host interfaces when no host address is specified. Opening an application through localhost does not, by itself, make it inaccessible from the network. Use a current Docker release and verify the effective bindings; Docker documents a localhost-publishing caveat for releases older than 28.0.0. Check Docker's port-publishing behavior.

After reviewing the environment, start the stack:

docker compose config --quiet && docker compose up -d
docker compose ps
docker compose logs --tail=100 smythos

Open http://localhost:6060 once the services are healthy. Keep these local-only settings separate from any later public deployment. Do not expose this evaluation instance to the internet to make a demo easier.

What does the Docker stack actually run?

The reviewed Compose file defines five services. This is a small application stack, not a single browser application. Its topology, mounted state and image tags are visible in the source. Inspect the five services and their defaults.

Services defined in the reviewed Docker Compose revision
ServiceRole in the reviewed stack
traefikRoutes application and runtime traffic; includes TLS configuration and a dashboard.
smythosRuns the application and runtime servers on internal ports 5050 and 5053.
mysqlPersists database state in the mysql_data volume.
redisProvides the configured Redis service with persistent storage.
git-syncPeriodically synchronizes a public model-configuration repository into the mounted models directory.

The git-sync service is an important qualification to the phrase “no platform in the middle.” Its default repository is SmythOS/sre-models-pub, and the configured interval defaults to 600s. It synchronizes repository content, not a local model-inference service. The stack does not acquire offline model execution simply because that service is present. See the synchronization and mount configuration.

The application image is smythos/smythos-studio:alpha in this revision. Pinning Git does not pin that image. For a repeatable pilot, record the image digest you actually run and your agent export. Before an upgrade, test the replacement with the same inputs and a restorable copy of the relevant state.

Why might localhost:6060 or an agent URL not work?

First check the setup path. The web self-hosting guide shows http://localhost and uses APP_BASE_URL, while the pinned Compose template uses APP_URL with port 6060. Do not mix variables from different guides without checking the source for your selected revision. Compare the web guide with the repository instructions.

Then check all three port-related values. EXPOSE_TRAEFIK_PORT controls the host mapping. APP_URL describes the browser-facing application URL. AGENT_DOMAIN_PORT is separately set to 6060 in the template. Changing only the published port can leave generated URLs pointing somewhere else.

A working editor does not prove a working runtime route. The template uses dev.agent.oss.smyth.ai for the runtime and development-agent domain, and prod.agent.oss.smyth.ai for production agents. Verify resolution on the machines that need those names, the resulting destination and Traefik's host routing. Do not assume that a vendor-supplied hostname means a vendor-hosted runtime. Check the exact domain and URL variables.

For a 502 or unhealthy service, inspect the stack before changing the workflow. Start with docker compose ps and bounded logs. The application health check covers both internal HTTP servers. Database credentials, mounted-directory permissions and runtime startup are separate failure points; a canvas edit cannot fix them.

What needs changing before a public deployment?

The following is our deployment review checklist. It is not a claim that the default distribution has already passed it.

Suggested release checks for a self-hosted Studio deployment
CheckEvidence to require before release
Public exposureOnly intended entrypoints are reachable. The evaluation dashboard and internal services are not publicly exposed.
Credentials and accessSample secrets are replaced; login, agent-endpoint authorization and denied requests are tested separately.
ReproducibilityStudio source revision, actual image digest, agent export and relevant model configuration are recorded.
State recoveryDatabase, application storage and required vault material restore successfully into a clean environment.
External callsModel, API, synchronization and code-execution destinations are known and constrained where required.
Failure handlingProvider errors, invalid outputs and retries fail safely without duplicating an external action.

Remove the insecure dashboard path

The pinned Compose file enables --api.insecure=true and publishes the dashboard on host port 8089 by default. It also defines an api@internal router. Disabling the insecure flag alone is not a complete review of dashboard exposure: remove the unwanted port and router, or protect an intentional administrative route with authentication and network restrictions. Traefik explicitly warns against insecure dashboard mode in production. Read Traefik's dashboard warning.

Separate hostnames from URLs and verify TLS

The repository's production guide places https:// inside example APP_DOMAIN and RUNTIME_DOMAIN values, but Compose interpolates those values into Traefik Host(...) rules. Our source-based recommendation is to use bare hostnames in domain fields and complete URLs in URL fields:

APP_DOMAIN=studio.example.com
APP_URL=https://studio.example.com
RUNTIME_DOMAIN=runtime.example.com
RUNTIME_URL=https://runtime.example.com

This is a naming example, not a complete production configuration. Set the remaining agent domains, DNS, ingress ports, redirects and TLS settings for your environment. Test the editor, runtime and published agent routes independently. Compare the Host rules with the configuration above.

The supplied resolver uses an HTTP challenge. That does not automatically provide a wildcard certificate for arbitrary agent subdomains. Traefik documents DNS-01 for wildcard certificates; either configure that path or use individually covered hostnames and verify the certificate actually served. Check Traefik's ACME and wildcard requirements.

Inventory what leaves the machine

Local hosting is a statement about where part of the system runs. It is not a statement about every data flow. A cloud LLM, an API connector or a remote execution component can still receive workflow data.

For example, SmythOS's NodeJS (Serverless) documentation describes execution on AWS Lambda. Do not confuse that component with the lightweight Code block or assume that every feature documented for the wider product executes locally in Community. Check the selected component, edition and configured backend. Read the documented Lambda execution path.

The .smyth bind mount also contains more than the synchronized models directory: the Compose comments identify vault configuration and runtime storage. Back up the actual state locations, control access to backups and test recovery. A database-only backup is not evidence that a complete agent deployment can be restored. Review the application mounts.

A useful first workflow: draft a support response, without sending it

Our suggested pilot is deliberately narrow: receive a synthetic support request, validate its fields, fetch permitted reference data, draft an answer and return it to a reviewer. Do not grant send, refund or account-modification permissions in the first iteration.

Map each step to a visible part of the workflow. Use a deterministic validation step for required fields, an API step for approved data access, a model step for the draft and explicit handling for missing evidence. This is a proposed workflow, not a bundled Studio template we tested.

The acceptance question is not “did every block turn green?” It is whether the response is supported by the retrieved information and whether the system refuses to proceed safely when the information is absent. Include an unauthorized record, a provider timeout, malformed data and an instruction embedded in retrieved content that asks the agent to bypass its rules. Keep any later write authorization outside the model's discretion.

Use our agent design-pattern guide for the architecture decision. This article's job is to help you evaluate Studio as the visual authoring and self-hosting environment, not replace your whole agent design process.

Can you run a Studio agent without the visual editor?

There is a documented export path. SmythOS describes exporting a .smyth file from Studio and running it with the SRE CLI. After installing and configuring a compatible CLI, the documented command is:

sre run ./my-agent.smyth

That is a practical way to test whether the workflow can leave its authoring environment. Read the Studio-to-CLI workflow.

Do not treat the export as a complete backup or an automatically portable deployment. Inventory the credentials, model configuration, storage, custom code and connectors required by that agent. Run the export in a clean environment and compare its output and failure behavior with the editor version. Access to source reduces one kind of dependency; it does not remove migration work.

For the distinction between an editor, a runtime and the surrounding reliability controls, see our agent harness engineering guide.

When is SmythOS Studio worth evaluating?

Our assessment: shortlist Studio when you need a visual workflow that non-specialists can inspect, developers can extend and your team can operate on its chosen infrastructure. Start with one useful process and an explicit acceptance test, not a promise to automate an entire department.

A managed service may be the more practical choice when nobody owns updates, recovery and incident handling. A code-first implementation may fit better when most of the workflow is already custom code or your team primarily needs library-level integration. Those are operating-model decisions, not a claim that one interface is universally superior.

Wavect's AI engineering services cover workflow implementation and production hardening. Our Twinsoft AI case study is relevant implementation experience, not a SmythOS Studio reference deployment. Use the pre-launch QA checklist to define the evidence you need, or discuss a self-hosted agent pilot with Wavect.

SmythOS Studio self-hosting FAQ

Is SmythOS Studio free for commercial use?

The reviewed Studio repository uses the MIT license, which permits commercial use subject to its notice requirements. Model APIs, infrastructure, dependencies and hosted services can have separate costs and terms. Free source code is not a zero-cost operating model.

Does self-hosted SmythOS Studio keep every request local?

Not automatically. The builder and runtime can run on your infrastructure, while configured model providers, APIs and execution components may receive data elsewhere. The reviewed Compose stack also synchronizes an external model-configuration repository. Inspect the actual workflow and network destinations.

Which environment file should I use for Docker Compose?

For the reviewed repository revision, copy .env.compose.example to .env. The separate .env.example belongs to a different setup path. Replace the sample credentials before starting, and check variables against the selected source revision rather than combining instructions from different guides.

Why does the local application use port 6060?

The Compose environment template sets EXPOSE_TRAEFIK_PORT to 6060 and APP_URL to an HTTP URL on that port. The runtime and generated agent URLs have related settings. Changing the published port alone does not necessarily update every generated URL.

What is the difference between SmythOS Studio and SRE?

Studio is the visual authoring and management environment. Its runtime package uses the SmythOS Runtime Environment, or SRE, to execute agents. The documented CLI path can run an exported .smyth agent without the full visual editor, but the required credentials and integrations still need configuration.

Can I add code to a visual SmythOS agent?

Yes. The documented Code component supports JavaScript for lightweight logic and transformations. Other execution components have different deployment requirements. In particular, the NodeJS (Serverless) documentation describes AWS Lambda; do not assume all custom execution is local.

Is the default Docker Compose file ready for public production?

Do not treat successful startup as release approval. The reviewed configuration includes sample secrets, an insecure dashboard path and a floating alpha image. Review exposure, access control, TLS, image pinning, external calls, backups and failure handling, then test the deployment before making it public.

Final thoughts

SmythOS Studio is worth a focused evaluation when visual authoring and control over deployment matter. Start with one bounded, draft-only workflow. Record the source and image versions, keep the initial instance local, and require evidence that access controls, error paths and recovery work before turning the prototype into a service.

Build the product, not just the backlog

If this article maps to a real product decision, Wavect can help you scope, build, harden, or lead the software work with senior founder-level judgment.

Useful service paths:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Kevin Riedl

14 min read · 1 Oct 2026
Last reviewed

Next

Get the next AI and agents field note

One concise email when we publish. No tracking pixels, and no inbox filler.

Free, double opt-in, no tracking pixels.