Environment variables reference
Every environment variable the Mnemose platform reads, grouped by the component that consumes it. Variables marked required must be present before that component starts; everything else has a default.
Binding-shaped configuration (D1, R2, KV, Queues, Durable Objects, AI,
Vectorize) lives in wrangler.toml and its per-environment sections, not in the
environment. Secrets go in with wrangler secret put.
Platform installer (scripts/install.sh, ADR-0009)
Cloudflare-first four-stage pipeline (provision → deploy → seed →
verify). Invoke with pnpm platform:install / pnpm platform:verify, or call
./scripts/install.sh directly.
| Variable | Required | Default | Description |
|---|---|---|---|
CLOUDFLARE_API_TOKEN | Yes (live runs) | — | Scoped Cloudflare API token (D1, R2, KV, Queues, DNS, Workers, Pages) |
CLOUDFLARE_ACCOUNT_ID | Yes (live runs) | — | Account that owns the platform resources |
PULUMI_CONFIG_PASSPHRASE | Yes (live runs) | — | Pulumi secrets passphrase; may be empty, but must be defined |
PULUMI_BACKEND_URL | No | Pulumi Service / local | Pulumi state backend (e.g. s3://… for an R2-compatible backend) |
MNEMOSE_ENV | No | production | Environment label used in every resource name (dev, staging, production) |
MNEMOSE_PROFILE | No | solo | solo (free tier) or prod (Workers Paid) — see infra/profiles.ts |
MNEMOSE_VERSION | No | current git SHA | Value written to the config KV system:version key by the seed stage |
MNEMOSE_CONFIG_KV_ID | No | resolved via wrangler kv namespace list | Config KV namespace id for seed/verify; set it to skip the lookup |
SYSTEM_TENANT_ID | No | ca67917c-32f5-449a-9445-aaf54a0faade | Stable system tenant id inserted by the seed stage |
SYSTEM_TENANT_NAME | No | Mnemose System | Display name for the system tenant |
MNEMOSE_API_URL | No | deployed gateway origin | Origin used by the verify stage for health and GraphQL probes |
INSTALL_REPORT_PATH | No | install-report.json | Where the installer writes its machine-readable report |
CF_ACCESS_AUD | No | unset | When set, written to the config KV auth:trusted_audiences key |
Extension providers stay off unless explicitly enabled:
| Variable | Default | Description |
|---|---|---|
MNEMOSE_ENABLE_GCP / --enable-gcp | false | Pulumi GCP extension (WIF, service accounts, sandbox runners); requires GCP_PROJECT_ID |
MNEMOSE_ENABLE_AWS / --enable-aws | false | Pulumi AWS extension (OIDC roles, S3 replication); requires AWS_ACCOUNT_ID |
MNEMOSE_ENABLE_TAILSCALE / --enable-tailscale | false | Tailscale mesh overlay; requires TAILSCALE_TAILNET |
Pulumi config keys (infra/)
Set with pulumi config set mnemose:<key> <value>; the installer passes them
from its own flags.
| Key | Required | Default | Description |
|---|---|---|---|
mnemose:env | Yes | — | Environment label; drives every resource name (infra/resource-names.ts) |
mnemose:accountId | Yes | — | Cloudflare account id |
mnemose:profile | No | solo | Deployment profile (solo | prod) |
mnemose:zoneId | No | — | DNS zone id for mnemose.ai; enables the DNS record resources |
mnemose:deployConsumers | No | false | Second-pass flag: bind Queue consumers after Wrangler deploys the Workers |
mnemose:enableGcpExtension | No | false | Activate the GCP extension provider |
mnemose:enableAwsExtension | No | false | Activate the AWS extension provider |
mnemose:enableTailscale | No | false | Activate the Tailscale extension provider |
mnemose:provisionAccess | No | false | Provision Cloudflare Access apps, policies, and the M2M service token |
mnemose:accessTeamName | No | round-dawn-c7d7 | Zero Trust team name (only read when provisionAccess is on) |
mnemose:accessAllowedEmailDomain | No | mnemose.ai | Email domain allowed by the operator policy |
Local development
Read by scripts/bootstrap-local-dev.mjs, scripts/dev-runtime.mjs, and the
service dev scripts (which load .env through tsx --env-file).
| Variable | Required | Default | Description |
|---|---|---|---|
DEV_AUTH_BYPASS | Yes for seeding | unset | true enables the dev shared-secret auth path and the D1 seed step |
DEV_AUTH_TENANT_ID | No | 11111111-1111-4111-8111-111111111111 | Dev tenant id used by the seed script |
DEV_AUTH_TOKEN | Yes for API calls | — | Shared secret accepted as Authorization: Bearer in dev |
NODE_ENV | No | development | Anything other than production keeps the dev bypass eligible |
NODE_AUTH_TOKEN | No | local-dev-token | Injected by dev-runtime.mjs for local package installs |
OTEL_EXPORTER_OTLP_ENDPOINT | No | unset (no-op) | OTLP collector endpoint; telemetry is a graceful no-op when unset |
VITE_DEV_AUTH_BYPASS / VITE_DEV_AUTH_TOKEN / VITE_DEFAULT_TENANT_ID | No | unset | Console-side mirror of the dev auth bypass (apps/console) |
Cloudflare Access (gateway Worker)
Consumed by services/gateway/src/auth/cf-access.ts. See
Cloudflare Access for provisioning.
| Variable | Required | Default | Description |
|---|---|---|---|
CF_ACCESS_TEAM_DOMAIN | Production | — | Issuer URL https://<team>.cloudflareaccess.com; JWKS is fetched from ${CF_ACCESS_TEAM_DOMAIN}/cdn-cgi/access/certs |
CF_ACCESS_AUD | Production | — | Access application AUD (infra/access.ts output accessApiAud) |
NODE_ENV | Yes | development (wrangler) | production hard-disables the shared-secret bypass |
DEV_AUTH_TOKEN | Dev only | — | Worker secret (wrangler secret put DEV_AUTH_TOKEN) accepted as Bearer/assertion token |
DEV_AUTH_BYPASS | Dev only | unset | Enables the bypass path; production ignores it, and the token must still match |
Remote MicroVM runner (sandbox execution)
Consumed by the MicroVM adapter in @mnemose/sandbox-execution when a sandbox
compute facet selects a remote backend. Unset URL with a mock transport uses the
in-process simulator.
| Variable | Required | Default | Description |
|---|---|---|---|
MICROVM_RUNNER_URL | No | unset | Remote runner origin (https://… or wss://…) |
SANDBOX_MICROVM_URL | No | unset | Alternate runner URL accepted by the adapter factory |
MICROVM_TRANSPORT | No | mock when no URL | http | websocket | grpc | mock |
MICROVM_AUTH_TOKEN | No | unset | Bearer token for the runner |
MICROVM_TIMEOUT_MS | No | 30000 | Default exec timeout in milliseconds |
Resource naming
Deterministic from infra/resource-names.ts — <name>-${mnemose:env}:
| Resource | Pattern | Example (env = dev) |
|---|---|---|
| D1 database | mnemose-{env} | mnemose-dev |
| R2 buckets | mnemose-assets-{env}, mnemose-reports-{env} | mnemose-assets-dev |
| KV namespaces | mnemose-config-{env}, mnemose-sessions-{env} | mnemose-config-dev |
| Queues + DLQs | mnemose-commands-{env}, mnemose-events-{env} (+ -dlq) | mnemose-commands-dev |
| Workers | mnemose-{service}-{env} | mnemose-gateway-dev |
| Pages project | mnemose-console-{env} | mnemose-console-dev |
| Pulumi stack | mnemose-{env} | mnemose-dev |