2. Deploy the platform
Provision a complete Mnemose environment on Cloudflare. The installer is a four-stage pipeline:
provision → deploy → seed → verify(Pulumi) (Wrangler) (D1+KV) (probes)Prerequisite: 1. Prerequisites complete —
CLOUDFLARE_API_TOKEN,CLOUDFLARE_ACCOUNT_ID, andPULUMI_CONFIG_PASSPHRASEexported.
One-shot install
git clone --recurse-submodules https://github.com/Mnemose-ai/mnemose.gitcd mnemosepnpm install
# Preview every action without executing anything./scripts/install.sh --env dev --dry-run
# Live install (all four stages)./scripts/install.sh --env devThe installer writes a machine-readable summary to install-report.json.
Deployment profiles
Two profiles select infrastructure cost/limits. Both run on the same Cloudflare
topology; prod assumes a Workers Paid plan.
| Knob | solo (default) | prod |
|---|---|---|
| Cloudflare plan | Free | Paid |
| Worker requests | 100k/day | 10M/mo |
| Worker CPU | 10ms | 30s |
| D1 size limit | 500MB | 5GB |
| R2 storage | 10GB | 10GB included, then metered |
| Queue messages | 100k/day | 100k ops/mo included, metered |
| Queue consumer batch | 10 / 5 concurrent | 50 / 10 concurrent |
| DLQs | Yes | Yes |
./scripts/install.sh --env production --profile prodWhat each stage does
Stage 1 — provision (Pulumi)
pulumi up against the mnemose-<env> stack. Creates the stateful baseline in
infra/index.ts:
| Resource | Name pattern |
|---|---|
| D1 database | mnemose-<env> |
| R2 buckets | mnemose-assets-<env>, mnemose-reports-<env>, mnemose-llm-calls-<env> |
| KV namespaces | mnemose-config-<env>, mnemose-sessions-<env> |
| Queues + DLQs | mnemose-commands-<env>, mnemose-events-<env> (+ -dlq) |
| DNS records | mnemose.ai, api., console. |
| Workers routes | api.<domain>/*, <domain>/* |
Optional extension providers (GCP WIF, AWS OIDC, Tailscale) activate only with their flags. Queue consumers are bound in a second Pulumi pass after the Workers are deployed (stage 2).
Stage 2 — deploy (Wrangler)
Builds the workspace packages and deploys the gateway Worker
(wrangler.toml) plus the console (Cloudflare Pages project
mnemose-console-<env>), then re-runs pulumi up with
mnemose:deployConsumers=true to bind the queue consumers.
Stage 3 — seed
Applies D1 migrations and inserts the system tenant:
wrangler d1 migrations apply mnemose-<env> --remoteThe system tenant id is stable (SYSTEM_TENANT_ID, default
ca67917c-32f5-449a-9445-aaf54a0faade). The stage also hydrates the config KV
namespace (system:initialized_at, system:version,
auth:trusted_audiences).
Stage 4 — verify
Runs scripts/verify-install.sh --env <env> — synthetic health, GraphQL, and
binding probes against the deployed gateway.
Non-interactive install
All variables are env-driven; nothing prompts:
CLOUDFLARE_API_TOKEN=*** \CLOUDFLARE_ACCOUNT_ID=*** \PULUMI_CONFIG_PASSPHRASE=*** \MNEMOSE_ENV=production \MNEMOSE_PROFILE=prod \ ./scripts/install.shRunning a single stage
./scripts/install.sh --env dev --stage provision./scripts/install.sh --env dev --stage deploy./scripts/install.sh --env dev --stage seed./scripts/install.sh --env dev --stage verifyPost-install secrets
Set Worker secrets (per environment) before the platform is fully functional:
# LLM API key — required for the agent runtime (Anthropic, OpenCode, etc.)echo -n "$LLM_API_KEY" | npx wrangler secret put LLM_API_KEY
# Cloudflare Access — stamped by infra/access.ts when provisionAccess is onnpx wrangler secret put CF_ACCESS_TEAM_DOMAIN # or set as [vars]npx wrangler secret put CF_ACCESS_AUD
# Dev shared-secret bypass (dev ONLY — ignored when NODE_ENV=production)npx wrangler secret put DEV_AUTH_TOKENTopic and queue names are pulled from
CoreManifest — keeping the
deployed topology in lockstep with the runtime manifest.