Skip to content

2. Deploy the platform

Provision a complete Mnemose environment on Cloudflare. The installer is a four-stage pipeline:

provision → deploy → seed → verify
(Pulumi) (Wrangler) (D1+KV) (probes)

Prerequisite: 1. Prerequisites complete — CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, and PULUMI_CONFIG_PASSPHRASE exported.

One-shot install

Terminal window
git clone --recurse-submodules https://github.com/Mnemose-ai/mnemose.git
cd mnemose
pnpm install
# Preview every action without executing anything
./scripts/install.sh --env dev --dry-run
# Live install (all four stages)
./scripts/install.sh --env dev

The installer writes a machine-readable summary to install-report.json.

Deployment profiles

Two profiles select infrastructure cost/limits. Both run on the same Cloudflare topology; prod assumes a Workers Paid plan.

Knobsolo (default)prod
Cloudflare planFreePaid
Worker requests100k/day10M/mo
Worker CPU10ms30s
D1 size limit500MB5GB
R2 storage10GB10GB included, then metered
Queue messages100k/day100k ops/mo included, metered
Queue consumer batch10 / 5 concurrent50 / 10 concurrent
DLQsYesYes
Terminal window
./scripts/install.sh --env production --profile prod

What each stage does

Stage 1 — provision (Pulumi)

pulumi up against the mnemose-<env> stack. Creates the stateful baseline in infra/index.ts:

ResourceName pattern
D1 databasemnemose-<env>
R2 bucketsmnemose-assets-<env>, mnemose-reports-<env>, mnemose-llm-calls-<env>
KV namespacesmnemose-config-<env>, mnemose-sessions-<env>
Queues + DLQsmnemose-commands-<env>, mnemose-events-<env> (+ -dlq)
DNS recordsmnemose.ai, api., console.
Workers routesapi.<domain>/*, <domain>/*

Optional extension providers (GCP WIF, AWS OIDC, Tailscale) activate only with their flags. Queue consumers are bound in a second Pulumi pass after the Workers are deployed (stage 2).

Stage 2 — deploy (Wrangler)

Builds the workspace packages and deploys the gateway Worker (wrangler.toml) plus the console (Cloudflare Pages project mnemose-console-<env>), then re-runs pulumi up with mnemose:deployConsumers=true to bind the queue consumers.

Stage 3 — seed

Applies D1 migrations and inserts the system tenant:

Terminal window
wrangler d1 migrations apply mnemose-<env> --remote

The system tenant id is stable (SYSTEM_TENANT_ID, default ca67917c-32f5-449a-9445-aaf54a0faade). The stage also hydrates the config KV namespace (system:initialized_at, system:version, auth:trusted_audiences).

Stage 4 — verify

Runs scripts/verify-install.sh --env <env> — synthetic health, GraphQL, and binding probes against the deployed gateway.

Non-interactive install

All variables are env-driven; nothing prompts:

Terminal window
CLOUDFLARE_API_TOKEN=*** \
CLOUDFLARE_ACCOUNT_ID=*** \
PULUMI_CONFIG_PASSPHRASE=*** \
MNEMOSE_ENV=production \
MNEMOSE_PROFILE=prod \
./scripts/install.sh

Running a single stage

Terminal window
./scripts/install.sh --env dev --stage provision
./scripts/install.sh --env dev --stage deploy
./scripts/install.sh --env dev --stage seed
./scripts/install.sh --env dev --stage verify

Post-install secrets

Set Worker secrets (per environment) before the platform is fully functional:

Terminal window
# LLM API key — required for the agent runtime (Anthropic, OpenCode, etc.)
echo -n "$LLM_API_KEY" | npx wrangler secret put LLM_API_KEY
# Cloudflare Access — stamped by infra/access.ts when provisionAccess is on
npx wrangler secret put CF_ACCESS_TEAM_DOMAIN # or set as [vars]
npx wrangler secret put CF_ACCESS_AUD
# Dev shared-secret bypass (dev ONLY — ignored when NODE_ENV=production)
npx wrangler secret put DEV_AUTH_TOKEN

Topic and queue names are pulled from CoreManifest — keeping the deployed topology in lockstep with the runtime manifest.

Next

→ 3. Onboard your first tenant