> ## Documentation Index
> Fetch the complete documentation index at: https://docs.langchain.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable Fleet on self-hosted LangSmith

> Install Fleet and optionally configure tools and triggers on self-hosted LangSmith.

[Fleet](/langsmith/fleet/index) lets you create and manage agents without writing code. Enable it when your installation needs no-code agents.

## Prerequisites

Fleet requires an [Enterprise](https://langchain.com/pricing) plan and [LangSmith Self-Hosted v0.13](https://changelog.langchain.com/announcements/langsmith-self-hosted-v0-13) or later. This standalone deployment configuration requires v0.15 or later. Install the [base LangSmith platform](/langsmith/kubernetes) first.

Fleet provisions an API server, task queue, PostgreSQL, Redis, tool server, and trigger server. It does not require LangSmith Deployment.

## Enable Fleet

Generate a Fernet encryption key for Fleet:

```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
```

Store it as `agent_builder_encryption_key` in your [existing LangSmith app Secret](/langsmith/self-host-using-an-existing-secret#parameters). Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts):

```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
config:
  existingSecretName: "<your-secret-name>"

fleet:
  enabled: true

fleetToolServer:
  enabled: true

fleetTriggerServer:
  enabled: true
```

Alternatively, set `fleet.encryptionKey` inline. Do not commit encryption keys to version control. Both `fleetToolServer` and `fleetTriggerServer` are required.

<Warning>
  If you are migrating from the legacy `agentBootstrap` deployment model, contact technical support through the [Support Portal](https://support.langchain.com) before upgrading. Current charts reject `backend.agentBootstrap`, `config.insights`, and `config.polly`; remove these legacy settings rather than setting them to `false`. Disable the legacy `config.agentBuilder.enabled` flag. Preserve existing Fleet data before deleting legacy deployments.
</Warning>

Fleet uses dedicated PostgreSQL and Redis instances by default. To use external databases, configure `fleet.postgres.external` and `fleet.redis.external`:

```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
fleet:
  enabled: true
  postgres:
    external:
      enabled: true
      connectionUrl: "<fleet-postgres-connection-url>"
  redis:
    external:
      enabled: true
      connectionUrl: "<fleet-redis-connection-url>"
```

Apply the changes and verify the pods:

```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
kubectl get pods -n <namespace>
```

### (Optional) Enable OAuth tools and triggers for Fleet

To enable OAuth-based tools such as Gmail, Slack, or Linear in Fleet, configure the `providerOrgId` and add provider IDs for each integration you want to use. You can enable any combination of providers.

#### Available providers

| Provider | Tools enabled | Trigger enabled |
| - | - | - |
| `googleOAuthProvider`<br />[setup guide](#google-oauth-provider) | Gmail, Google Calendar,<br />Google Sheets, BigQuery | Gmail |
| `linearOAuthProvider`<br />[setup guide](#linear-oauth-provider) | Linear | - |
| `linkedinOAuthProvider`<br />[setup guide](#linkedin-oauth-provider) | LinkedIn | - |
| `microsoftOAuthProvider`<br />[setup guide](#microsoft-oauth-provider) | Outlook, Calendar, Teams, SharePoint,<br />Word, Excel, PowerPoint | Outlook |
| `salesforceOAuthProvider`<br />[setup guide](#salesforce-oauth-provider) | Salesforce | - |
| `slackOAuthProvider`<br />[setup guide](#slack-oauth-provider) | Slack | Slack |

#### General configuration

Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts). Include only the providers you need.

```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
fleet:
  oauth:
    # Organization ID where OAuth providers are configured
    providerOrgId: "<your-org-id>"
    # Add provider IDs for integrations you want to enable.
    slackOAuthProvider: "<provider-id>"
    googleOAuthProvider: "<provider-id>"
    linkedinOAuthProvider: "<provider-id>"
    linearOAuthProvider: "<provider-id>"
    microsoftOAuthProvider: "<provider-id>"
    salesforceOAuthProvider: "<provider-id>"
```

<Warning>
  The provider ID must be unique and cannot end with `-agent-builder` or `-oauth-provider`.
</Warning>

#### Provider setup guides

<AccordionGroup>
  <Accordion title="Google OAuth provider" id="google-oauth-provider">
    To enable Google OAuth for Fleet, create an OAuth client in GCP and configure it with the required URLs and credentials.

    <Steps>
      <Step title="Create OAuth client in GCP">
        Create a new OAuth client app (Web application) in [Google Cloud Console](https://console.cloud.google.com/apis/credentials).
      </Step>

      <Step title="Add URLs to GCP">
        Add the following URLs to your OAuth client, replacing `<hostname>` with your LangSmith hostname and `<provider-id>` with the provider ID you'll use (for example, `google`):

        **Authorized JavaScript origins:**

        * `https://<hostname>`

        **Authorized redirect URIs:**

        * `https://<hostname>/api-host/v2/auth/callback/<provider-id>`
        * `https://<hostname>/host-oauth-callback/<provider-id>`
      </Step>

      <Step title="Copy credentials">
        Copy the **Client ID** and **Client Secret** from the GCP OAuth app.
      </Step>

      <Step title="Configure OAuth provider in LangSmith">
        In LangSmith, go to **Settings > OAuth Providers** and add a new provider:

        * **Client ID**: from GCP
        * **Client Secret**: from GCP
        * **Authorization URL**: `https://accounts.google.com/o/oauth2/auth`
        * **Token URL**: `https://oauth2.googleapis.com/token`
        * **Provider ID**: Unique string, for example: `google`
      </Step>

      <Step title="Apply the changes">
        Add the LangSmith OAuth provider ID to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts) and deploy:

        ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        fleet:
          oauth:
            providerOrgId: "<your-org-id>"
            googleOAuthProvider: "<provider-id>"
        ```

        ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
        ```
      </Step>
    </Steps>
  </Accordion>

  <Accordion title="Microsoft OAuth provider" id="microsoft-oauth-provider">
    To enable Microsoft OAuth for Fleet, create an Azure app registration, add the required Microsoft Graph delegated permissions, and configure a Microsoft OAuth provider in LangSmith.

    <Steps>
      <Step title="Create an Azure app registration">
        In the [Microsoft Entra admin center](https://entra.microsoft.com/), go to **Applications > App registrations** and create a new registration.
      </Step>

      <Step title="Choose supported account types">
        Select the account type that matches your deployment. If you need users from multiple Microsoft Entra tenants to authenticate, choose a multi-tenant option. If your deployment is limited to one tenant, you can use a single-tenant app registration.
      </Step>

      <Step title="Add the redirect URI">
        Add the following web redirect URI, replacing `<hostname>` with your LangSmith hostname and `<provider-id>` with your provider ID:

        ```
        https://<hostname>/host-oauth-callback/<provider-id>
        ```
      </Step>

      <Step title="Create a client secret">
        In **Certificates & secrets**, create a new client secret. Copy the **Application (client) ID** and the generated client secret value.
      </Step>

      <Step title="Add Microsoft Graph delegated permissions">
        In **API permissions**, add the following Microsoft Graph delegated permissions:

        * `Mail.ReadWrite`
        * `Mail.Send`
        * `Calendars.ReadWrite`
        * `Team.ReadBasic.All`
        * `Channel.ReadBasic.All`
        * `Channel.Create`
        * `ChannelMessage.Send`
        * `ChannelMessage.Read.All`
        * `Chat.Create`
        * `Chat.ReadWrite`
        * `User.ReadBasic.All`
        * `Files.ReadWrite.All`
        * `Sites.ReadWrite.All`

        <Note>
          LangSmith automatically requests `offline_access` for Microsoft providers so users can receive refresh tokens.
        </Note>
      </Step>

      <Step title="Grant tenant consent">
        Grant admin consent for the tenant if your Microsoft 365 policies require it for these delegated permissions.
      </Step>

      <Step title="Configure OAuth provider in LangSmith">
        In LangSmith, go to **Settings > OAuth Providers** and add a new provider:

        * **Name**: For example, `Microsoft`
        * **Provider ID**: Unique string, for example: `microsoft-oauth-provider`
        * **Client ID**: Application (client) ID from Azure
        * **Client Secret**: Client secret value from Azure
        * **Authorization URL**: `https://login.microsoftonline.com/common/oauth2/v2.0/authorize`
        * **Token URL**: `https://login.microsoftonline.com/common/oauth2/v2.0/token`
        * **Provider Type**: `microsoft`
        * **Token endpoint auth method**: `client_secret_post`

        <Note>
          If you created a single-tenant app registration, replace `common` in the authorization and token URLs with your tenant ID.
        </Note>
      </Step>

      <Step title="Apply the changes">
        Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts) and deploy:

        ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        fleet:
          oauth:
            providerOrgId: "<your-org-id>"
            microsoftOAuthProvider: "<provider-id>"
        ```

        ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
        ```
      </Step>
    </Steps>
  </Accordion>

  <Accordion title="Linear OAuth provider" id="linear-oauth-provider">
    To enable Linear OAuth for Fleet, create a Linear OAuth app and configure it with the required credentials.

    <Steps>
      <Step title="Create a Linear OAuth app">
        Go to [Linear Settings > API > Applications](https://linear.app/settings/api/applications/new) and create a new OAuth application.
      </Step>

      <Step title="Add callback URL">
        Set the callback URL, replacing `<hostname>` with your LangSmith hostname and `<provider-id>` with your provider ID:

        ```
        https://<hostname>/host-oauth-callback/<provider-id>
        ```
      </Step>

      <Step title="Copy credentials">
        After creating the app, copy the **Client ID** and **Client Secret**.
      </Step>

      <Step title="Configure OAuth provider in LangSmith">
        In LangSmith, go to **Settings > OAuth Providers** and add a new provider:

        * **Client ID**: from Linear app
        * **Client Secret**: from Linear app
        * **Authorization URL**: `https://linear.app/oauth/authorize`
        * **Token URL**: `https://api.linear.app/oauth/token`
        * **Provider ID**: Unique string, for example: `linear`
      </Step>

      <Step title="Apply the changes">
        Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts) and deploy:

        ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        fleet:
          oauth:
            providerOrgId: "<your-org-id>"
            linearOAuthProvider: "<provider-id>"
        ```

        ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
        ```
      </Step>
    </Steps>
  </Accordion>

  <Accordion title="LinkedIn OAuth provider" id="linkedin-oauth-provider">
    To enable LinkedIn OAuth for Fleet, create a LinkedIn OAuth app and configure it with the required credentials.

    <Steps>
      <Step title="Create a LinkedIn OAuth app">
        Go to [linkedin.com/developers/apps](https://www.linkedin.com/developers/apps/) and create a new app.
      </Step>

      <Step title="Add redirect URI">
        In your app settings, go to the **Auth** tab. Add the following redirect URI, replacing `<hostname>` with your LangSmith hostname and `<provider-id>` with your provider ID:

        ```
        https://<hostname>/host-oauth-callback/<provider-id>
        ```
      </Step>

      <Step title="Copy credentials">
        Copy the **Client ID** and **Client Secret** from the Auth tab.
      </Step>

      <Step title="Configure OAuth provider in LangSmith">
        In LangSmith, go to **Settings > OAuth Providers** and add a new provider:

        * **Client ID**: from LinkedIn app
        * **Client Secret**: from LinkedIn app
        * **Authorization URL**: `https://www.linkedin.com/oauth/v2/authorization`
        * **Token URL**: `https://www.linkedin.com/oauth/v2/accessToken`
        * **Provider ID**: Unique string, for example: `linkedin`
      </Step>

      <Step title="Apply the changes">
        Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts) and deploy:

        ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        fleet:
          oauth:
            providerOrgId: "<your-org-id>"
            linkedinOAuthProvider: "<provider-id>"
        ```

        ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
        ```
      </Step>
    </Steps>
  </Accordion>

  <Accordion title="Salesforce OAuth provider" id="salesforce-oauth-provider">
    To enable Salesforce OAuth for Fleet, create a Salesforce External Client App, configure its OAuth settings and policies, retrieve its credentials, then configure a Salesforce OAuth provider in LangSmith.

    <Steps>
      <Step title="Create an External Client App">
        In Salesforce **Setup**, use **Quick Find** to open **External Client App Manager**, then click **New External Client App**.

        Under **Basic Information**, set:

        * **External Client App Name**: for example, `LangSmith Fleet`
        * **Contact Email**: an admin email address
        * **Distribution State**: **Local**

        <Note>
          External Client Apps are the current framework Salesforce uses for OAuth integrations. If **New External Client App** is unavailable, confirm that app creation is enabled for your org under **Setup > External Client App Settings**.
        </Note>
      </Step>

      <Step title="Enable OAuth and configure the OAuth settings">
        Expand **API (Enable OAuth Settings)** and select **Enable OAuth**. Then configure:

        * **Callback URL**, replacing `<hostname>` with your LangSmith hostname and `<provider-id>` with your provider ID:

        ```
        https://<hostname>/host-oauth-callback/<provider-id>
        ```

        * **Selected OAuth Scopes**: add **Manage user data via APIs (api)** and **Perform requests at any time (refresh\_token, offline\_access)**.
        * Keep **Require Secret for the Web Server Flow** selected.
        * Leave **Enable Authorization Code and Credentials Flow** and **Enable Client Credentials Flow** unselected. Fleet uses the standard web server (authorization code) flow.

        Click **Create**.
      </Step>

      <Step title="Set the OAuth policies">
        Open the app, select the **Policies** tab, and click **Edit**:

        * **Refresh Token Policy**: select **Refresh token is valid until revoked**.
        * **Permitted Users**: leave **All users may self-authorize**. If you choose **Admin approved users are pre-authorized** instead, you must first assign the app to a permission set or profile, or authorization fails.

        Click **Save**.

        <Note>
          An External Client App is configured in two places: **Settings** (the OAuth definition from the previous step) and **Policies** (this step). Both must be saved.
        </Note>
      </Step>

      <Step title="Copy the credentials">
        On the **Settings** tab, under **OAuth Settings**, select **Consumer Key and Secret**. The **Consumer Key** is your Client ID and the **Consumer Secret** is your Client Secret.

        <Note>
          After you create the app, allow up to 30 minutes for it to propagate before the first connection attempt.
        </Note>
      </Step>

      <Step title="Configure OAuth provider in LangSmith">
        In LangSmith, go to **Settings > OAuth Providers**, click **OAuth Provider**, and fill in:

        * **Provider ID**: Unique string, for example: `salesforce-oauth-provider`. Use this same value for `salesforceOAuthProvider` in the next step.
        * **Display Name**: For example, `Salesforce`
        * **Client ID**: Consumer Key from Salesforce
        * **Client Secret**: Consumer Secret from Salesforce
        * **Authorization URL**: `https://<MyDomain>.my.salesforce.com/services/oauth2/authorize`
        * **Token URL**: `https://<MyDomain>.my.salesforce.com/services/oauth2/token`

        LangSmith recognizes Salesforce automatically from the Token URL, so there is no provider-type or token-auth-method field to set. Leave **Enable PKCE** off to match the web server flow configured above.

        <Note>
          Replace `<MyDomain>` with your org's My Domain, found under **Setup > My Domain**. For a sandbox, use `https://<MyDomain>--<SandboxName>.sandbox.my.salesforce.com/services/oauth2/authorize` and the matching token URL.
        </Note>
      </Step>

      <Step title="Apply the changes">
        Add the following to your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts) and deploy:

        ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        fleet:
          oauth:
            providerOrgId: "<your-langsmith-org-id>"
            salesforceOAuthProvider: "<provider-id>"
        ```

        ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
        helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
        ```
      </Step>
    </Steps>

    <Warning>
      If sign-in fails: confirm the **Callback URL** in Salesforce exactly matches `https://<hostname>/host-oauth-callback/<provider-id>` (HTTPS, no trailing slash); if you selected **Admin approved users are pre-authorized**, assign the app via a permission set; and if your org enforces login IP ranges, allowlist your Fleet server's egress IPs on the user's profile or set **IP Relaxation** to **Relax IP restrictions** in the app's policies.
    </Warning>
  </Accordion>

  <Accordion title="Slack OAuth provider" id="slack-oauth-provider">
    One Slack OAuth provider powers both Slack tools and the Slack apps you add to individual agents, so Slack setup lives with the rest of the Slack integration.

    For the full walkthrough, see [Set up Slack on Self-hosted](/langsmith/fleet/slack-app#set-up-slack-on-self-hosted). It covers creating the Slack app, adding bot scopes, registering the provider, setting the redirect URI, and configuring Helm values.
  </Accordion>
</AccordionGroup>

### (Optional) Enable GitHub App for Fleet

Fleet integrates with GitHub through a dedicated **GitHub App** (not an OAuth app). The GitHub App provides repository access for Fleet's GitHub tools and supports the user authorization flow required for private repository access.

Setup involves creating a GitHub App, gathering its credentials, storing them as Kubernetes secrets, and referencing them from your [`langsmith_config.yaml`](/langsmith/kubernetes#configure-your-helm-charts).

<Steps>
  <Step title="Create a GitHub App">
    Go to [GitHub Settings > Developer settings > GitHub Apps](https://github.com/settings/apps) and click **New GitHub App**.

    <Note>
      You can create the app under a personal account or an organization. If multiple people will manage the integration, an organization-owned app is recommended.
    </Note>
  </Step>

  <Step title="Fill in basic details">
    * **GitHub App name**: Any unique name, for example `acme-langsmith-fleet`. Make a note of the slug GitHub generates (the lowercased, hyphenated form of the name), as this is the value you'll use for `FLEET_GITHUB_APP_SLUG`.
    * **Homepage URL**: Your LangSmith hostname, for example `https://langsmith.acme.com`.
    * Deselect **Active** under **Webhook** for now. You'll enable it in a later step after generating a webhook secret.
  </Step>

  <Step title="Set callback URLs">
    Under **Identifying and authorizing users**, add the following **Callback URL**, replacing `<hostname>` with your LangSmith hostname:

    ```
    https://<hostname>/api/v1/platform/fleet/providers/github-app/auth/callback
    ```

    Select **Redirect on update**.

    Under **Post installation**, add the following **Setup URL**:

    ```
    https://<hostname>/api/v1/platform/fleet/providers/github-app/callback
    ```

    Select **Redirect on update**.
  </Step>

  <Step title="Set webhook URL and generate a webhook secret">
    Generate a random webhook secret:

    ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
    python3 -c "import secrets; print(secrets.token_urlsafe(48))"
    ```

    Under **Webhook**:

    * Select **Active**.

    * Set the **Webhook URL** to:

      ```
      https://<hostname>/api/v1/platform/fleet/providers/github-app/webhooks
      ```

    * Paste the generated value into **Webhook secret**. Save it, as you'll need the same value when creating the Kubernetes secret in a later step.
  </Step>

  <Step title="Set repository permissions">
    Under **Permissions > Repository permissions**, grant the following:

    * **Contents**: Read and write
    * **Issues**: Read and write
    * **Pull requests**: Read and write
    * **Metadata**: Read-only (automatically selected)

    Under **Permissions > Account permissions**, grant **Email addresses: Read-only**.

    <Note>
      These are the minimum permissions required for Fleet's built-in GitHub tools (issue management, pull request creation, repository content access). Adjust if you need additional tool capabilities.
    </Note>
  </Step>

  <Step title="Choose install visibility">
    Under **Where can this GitHub App be installed?**, select the option that matches your distribution needs. For most self-hosted deployments, **Only on this account** is correct.
  </Step>

  <Step title="Create the app">
    Click **Create GitHub App**. On the app settings page, note the following values:

    | Value | Where to find it | Environment variable |
    | - | - | - |
    | **App ID** | Numeric, at the top of the page | `FLEET_GITHUB_APP_ID` |
    | **Public link** | For example, `https://github.com/apps/acme-langsmith-fleet` | `FLEET_GITHUB_APP_PUBLIC_LINK` |
    | App slug | Last path segment of the public link | `FLEET_GITHUB_APP_SLUG` |
    | **Client ID** | Under **About** | `FLEET_GITHUB_APP_CLIENT_ID` |
  </Step>

  <Step title="Generate a client secret">
    Under **Client secrets**, click **Generate a new client secret** and copy the value. This is `FLEET_GITHUB_APP_CLIENT_SECRET`. GitHub only shows it once.
  </Step>

  <Step title="Generate a private key">
    Scroll to **Private keys** and click **Generate a private key**. GitHub downloads a `.pem` file. Keep this file secure, as it grants full access to the GitHub App. The PEM contents are `FLEET_GITHUB_APP_PRIVATE_KEY`.
  </Step>

  <Step title="Generate a state JWT secret">
    LangSmith signs short-lived OAuth state tokens with an HMAC key. Generate one:

    ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
    python3 -c "import secrets; print(secrets.token_urlsafe(48))"
    ```

    This is `FLEET_GITHUB_APP_STATE_JWT_SECRET`.
  </Step>

  <Step title="Create a Kubernetes secret">
    Store the sensitive values in a Kubernetes secret:

    ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
    kubectl create secret generic fleet-github-app \
      --namespace <your-langsmith-namespace> \
      --from-literal=client_secret="<client-secret>" \
      --from-literal=webhook_secret="<webhook-secret>" \
      --from-literal=state_jwt_secret="<state-jwt-secret>" \
      --from-file=private_key=/path/to/fleet-app.private-key.pem
    ```

    For production deployments, manage this secret through your existing secrets workflow (for example, [Sealed Secrets](https://github.com/bitnami-labs/sealed-secrets) or [External Secrets Operator](https://external-secrets.io/)). See [Use an existing secret](/langsmith/self-host-using-an-existing-secret) for more.
  </Step>

  <Step title="Add the configuration to your langsmith_config.yaml">
    Add the following, replacing the placeholder values with the non-sensitive values gathered above:

    ```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
    commonEnv:
      - name: FLEET_GITHUB_APP_ID
        value: "<app-id>"
      - name: FLEET_GITHUB_APP_SLUG
        value: "<app-slug>"
      - name: FLEET_GITHUB_APP_PUBLIC_LINK
        value: "https://github.com/apps/<app-slug>"
      - name: FLEET_GITHUB_APP_CLIENT_ID
        value: "<client-id>"
      - name: FLEET_GITHUB_APP_CLIENT_SECRET
        valueFrom:
          secretKeyRef:
            name: fleet-github-app
            key: client_secret
      - name: FLEET_GITHUB_APP_PRIVATE_KEY
        valueFrom:
          secretKeyRef:
            name: fleet-github-app
            key: private_key
      - name: FLEET_GITHUB_APP_WEBHOOK_SECRET
        valueFrom:
          secretKeyRef:
            name: fleet-github-app
            key: webhook_secret
      - name: FLEET_GITHUB_APP_STATE_JWT_SECRET
        valueFrom:
          secretKeyRef:
            name: fleet-github-app
            key: state_jwt_secret

    fleetToolServer:
      deployment:
        extraEnv:
          - name: FLEET_GITHUB_APP_ENABLED
            value: "true"
    ```

    <Note>
      `FLEET_GITHUB_APP_ENABLED` must be set on the tool server so the GitHub tools are registered. The remaining `FLEET_GITHUB_APP_*` variables are consumed by the platform backend and live under `commonEnv`.
    </Note>
  </Step>

  <Step title="Deploy and install the app on repositories">
    Run the following command to apply the changes:

    ```bash theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
    helm upgrade -i langsmith langchain/langsmith --values langsmith_config.yaml --version <version> -n <namespace> --wait --debug
    ```

    Once pods are healthy:

    1. In LangSmith, open a Fleet agent and go to the GitHub integration in the agent editor.
    2. Click **Connect GitHub** to install the app on the repositories Fleet should access.
    3. For private repositories, you must explicitly select each repository during installation.

    <Note>
      Each user must also authorize the GitHub App against their own GitHub account using the re-auth flow in LangSmith. This allows Fleet to resolve per-user tokens for tools that act on behalf of a user.
    </Note>
  </Step>
</Steps>

## Disable Fleet

To disable Fleet, set these values and apply the Helm upgrade:

```yaml theme={"theme":{"light":"catppuccin-latte","dark":"catppuccin-mocha"}}
fleet:
  enabled: false
fleetToolServer:
  enabled: false
fleetTriggerServer:
  enabled: false
```

***

<div className="source-links">
  <Callout icon="terminal-2">
    [Connect these docs](/use-these-docs) to your agent of choice via MCP for real-time answers.
  </Callout>

  <Callout icon="edit">
    [Edit this page on GitHub](https://github.com/langchain-ai/docs/edit/main/src/langsmith/enable-self-hosted-fleet.mdx) or [file an issue](https://github.com/langchain-ai/docs/issues/new/choose).
  </Callout>
</div>
