Deploying Qwen Code¶
Qwen Code is an open-source AI coding agent for the terminal. The qwen-code runtime runs its TUI inside tmux behind a browser terminal, and is installed by the language-operator-runtimes chart. No Qwen account or login is needed: every model call goes through the cluster's model gateway over the OpenAI chat-completions API, so any LanguageModel works, not only Qwen models.
The runtime image is built in qwen-code-adapter on the shared coding-runtime base, like the Claude Code, OpenCode and Kilo runtimes.
Prerequisites¶
- Language Operator installed, including the
language-operator-runtimeschart (provides theqwen-coderuntime) - A
LanguageClusterto deploy into, with yourkubectlcontext set to its namespace (examples below assume a cluster nameddemo-cluster) - An LLM provider API key, or a local model endpoint (e.g. Ollama)
Instructions¶
Configure a Model¶
kubectl create secret generic anthropic-credentials \
--from-literal=api-key=sk-ant-your-key-here
kubectl apply -f - <<EOF
apiVersion: langop.io/v1alpha1
kind: LanguageModel
metadata:
name: claude-sonnet
spec:
provider: anthropic
modelName: claude-sonnet-4-5
apiKeySecretRef:
name: anthropic-credentials
key: api-key
EOF
Deploy Qwen Code¶
kubectl apply -f - <<EOF
apiVersion: langop.io/v1alpha1
kind: LanguageAgent
metadata:
name: qwen-code
spec:
runtime: qwen-code
models:
- name: claude-sonnet # or gpt-4o, llama3
EOF
On start, the runtime writes Qwen Code's settings.json from the operator's /etc/agent/config.yaml: the gateway as an OpenAI-compatible provider, the first referenced model, and every LanguageTool the agent references as an MCP server. Header tokens for those tools are written as ${NAME} references to the container's environment, so they never land on disk. The persona and spec.instructions, when set, are loaded as standing context (QWEN.md) for every session.
Verify¶
Wait for PHASE to reach Running. The MODE column shows service: the TUI is long-lived and addressable. See
Execution Modes.
Connect¶
Access is gated by the cluster's OIDC proxy — there is no separate Qwen Code password.
If your LanguageCluster has a domain and auth enabled,
open https://qwen-code.demo-cluster.\<your-domain> and sign in through the cluster's OIDC provider.
For local access, port-forward the service (this bypasses the proxy, so no login is required):
Then open http://localhost:8080 in your browser. The session lives in tmux, so it survives page reloads, and after a pod restart Qwen Code resumes the previous conversation from the workspace volume.
In the terminal, Qwen Code asks before it edits a file or runs a shell command; Shift+Tab cycles the approval mode. Qwen's own default, where a model decides each approval, is not used, because every decision would be an extra model call through the gateway.
Warning
The terminal has no built-in authentication. When the cluster does not enable auth, it is exposed unauthenticated on its ingress. Enable cluster auth to protect it.
Task Mode¶
Qwen Code also runs headless as a task: each run does the work in spec.instructions and exits.
apiVersion: langop.io/v1alpha1
kind: LanguageAgent
metadata:
name: changelog
spec:
runtime: qwen-code
models:
- name: claude-sonnet
repository:
url: https://github.com/acme/api.git
instructions: |
Summarise the commits merged since the last tag into CHANGELOG.md.
execution:
mode: task
schedule: "0 6 * * 1" # or omit it and run on demand with argo submit
Each run executes qwen "<instructions>" --approval-mode yolo --output-format text. yolo approves every tool call, since nobody is there to answer; the pod's own restrictions (read-only root filesystem, non-root user, writes confined to the workspace) are the boundary. The exit code is the run's result: 0 is Succeeded, anything else Failed. An agent with no instructions fails before Qwen Code starts.
Gateway Credentials¶
The operator gives every agent its own gateway key as MODEL_API_KEY, and Qwen Code sends it on every model call, so there is nothing to configure. The gateway rejects calls without a valid key and attributes each one to the agent. See Gateway authentication.
What the Operator Created¶
| Resource | Name | Purpose |
|---|---|---|
| WorkflowTemplate | qwen-code |
The agent's pod spec; also what argo submit --from targets |
| Workflow | qwen-code |
The long-lived run. Runs the Qwen Code WebSocket terminal container |
| Service | qwen-code |
ClusterIP on port 8080 |
| NetworkPolicy | qwen-code |
Allows inbound from other agents in this namespace |
| PVC | qwen-code-workspace |
10Gi persistent workspace |
| ConfigMap | qwen-code-agent |
Injected at /etc/agent/config.yaml |
A task-mode agent gets a CronWorkflow (when it has a schedule) instead of the long-lived Workflow, and no Service.