Skip to content

Environment variables reference

Every environment variable the Mnemose platform reads, grouped by the component that consumes it. Variables marked required must be present before that component starts; everything else has a default.

Binding-shaped configuration (D1, R2, KV, Queues, Durable Objects, AI, Vectorize) lives in wrangler.toml and its per-environment sections, not in the environment. Secrets go in with wrangler secret put.


Platform installer (scripts/install.sh, ADR-0009)

Cloudflare-first four-stage pipeline (provision → deploy → seed → verify). Invoke with pnpm platform:install / pnpm platform:verify, or call ./scripts/install.sh directly.

VariableRequiredDefaultDescription
CLOUDFLARE_API_TOKENYes (live runs)—Scoped Cloudflare API token (D1, R2, KV, Queues, DNS, Workers, Pages)
CLOUDFLARE_ACCOUNT_IDYes (live runs)—Account that owns the platform resources
PULUMI_CONFIG_PASSPHRASEYes (live runs)—Pulumi secrets passphrase; may be empty, but must be defined
PULUMI_BACKEND_URLNoPulumi Service / localPulumi state backend (e.g. s3://… for an R2-compatible backend)
MNEMOSE_ENVNoproductionEnvironment label used in every resource name (dev, staging, production)
MNEMOSE_PROFILENosolosolo (free tier) or prod (Workers Paid) — see infra/profiles.ts
MNEMOSE_VERSIONNocurrent git SHAValue written to the config KV system:version key by the seed stage
MNEMOSE_CONFIG_KV_IDNoresolved via wrangler kv namespace listConfig KV namespace id for seed/verify; set it to skip the lookup
SYSTEM_TENANT_IDNoca67917c-32f5-449a-9445-aaf54a0faadeStable system tenant id inserted by the seed stage
SYSTEM_TENANT_NAMENoMnemose SystemDisplay name for the system tenant
MNEMOSE_API_URLNodeployed gateway originOrigin used by the verify stage for health and GraphQL probes
INSTALL_REPORT_PATHNoinstall-report.jsonWhere the installer writes its machine-readable report
CF_ACCESS_AUDNounsetWhen set, written to the config KV auth:trusted_audiences key

Extension providers stay off unless explicitly enabled:

VariableDefaultDescription
MNEMOSE_ENABLE_GCP / --enable-gcpfalsePulumi GCP extension (WIF, service accounts, sandbox runners); requires GCP_PROJECT_ID
MNEMOSE_ENABLE_AWS / --enable-awsfalsePulumi AWS extension (OIDC roles, S3 replication); requires AWS_ACCOUNT_ID
MNEMOSE_ENABLE_TAILSCALE / --enable-tailscalefalseTailscale mesh overlay; requires TAILSCALE_TAILNET

Pulumi config keys (infra/)

Set with pulumi config set mnemose:<key> <value>; the installer passes them from its own flags.

KeyRequiredDefaultDescription
mnemose:envYes—Environment label; drives every resource name (infra/resource-names.ts)
mnemose:accountIdYes—Cloudflare account id
mnemose:profileNosoloDeployment profile (solo | prod)
mnemose:zoneIdNo—DNS zone id for mnemose.ai; enables the DNS record resources
mnemose:deployConsumersNofalseSecond-pass flag: bind Queue consumers after Wrangler deploys the Workers
mnemose:enableGcpExtensionNofalseActivate the GCP extension provider
mnemose:enableAwsExtensionNofalseActivate the AWS extension provider
mnemose:enableTailscaleNofalseActivate the Tailscale extension provider
mnemose:provisionAccessNofalseProvision Cloudflare Access apps, policies, and the M2M service token
mnemose:accessTeamNameNoround-dawn-c7d7Zero Trust team name (only read when provisionAccess is on)
mnemose:accessAllowedEmailDomainNomnemose.aiEmail domain allowed by the operator policy

Local development

Read by scripts/bootstrap-local-dev.mjs, scripts/dev-runtime.mjs, and the service dev scripts (which load .env through tsx --env-file).

VariableRequiredDefaultDescription
DEV_AUTH_BYPASSYes for seedingunsettrue enables the dev shared-secret auth path and the D1 seed step
DEV_AUTH_TENANT_IDNo11111111-1111-4111-8111-111111111111Dev tenant id used by the seed script
DEV_AUTH_TOKENYes for API calls—Shared secret accepted as Authorization: Bearer in dev
NODE_ENVNodevelopmentAnything other than production keeps the dev bypass eligible
NODE_AUTH_TOKENNolocal-dev-tokenInjected by dev-runtime.mjs for local package installs
OTEL_EXPORTER_OTLP_ENDPOINTNounset (no-op)OTLP collector endpoint; telemetry is a graceful no-op when unset
VITE_DEV_AUTH_BYPASS / VITE_DEV_AUTH_TOKEN / VITE_DEFAULT_TENANT_IDNounsetConsole-side mirror of the dev auth bypass (apps/console)

Cloudflare Access (gateway Worker)

Consumed by services/gateway/src/auth/cf-access.ts. See Cloudflare Access for provisioning.

VariableRequiredDefaultDescription
CF_ACCESS_TEAM_DOMAINProduction—Issuer URL https://<team>.cloudflareaccess.com; JWKS is fetched from ${CF_ACCESS_TEAM_DOMAIN}/cdn-cgi/access/certs
CF_ACCESS_AUDProduction—Access application AUD (infra/access.ts output accessApiAud)
NODE_ENVYesdevelopment (wrangler)production hard-disables the shared-secret bypass
DEV_AUTH_TOKENDev only—Worker secret (wrangler secret put DEV_AUTH_TOKEN) accepted as Bearer/assertion token
DEV_AUTH_BYPASSDev onlyunsetEnables the bypass path; production ignores it, and the token must still match

Remote MicroVM runner (sandbox execution)

Consumed by the MicroVM adapter in @mnemose/sandbox-execution when a sandbox compute facet selects a remote backend. Unset URL with a mock transport uses the in-process simulator.

VariableRequiredDefaultDescription
MICROVM_RUNNER_URLNounsetRemote runner origin (https://… or wss://…)
SANDBOX_MICROVM_URLNounsetAlternate runner URL accepted by the adapter factory
MICROVM_TRANSPORTNomock when no URLhttp | websocket | grpc | mock
MICROVM_AUTH_TOKENNounsetBearer token for the runner
MICROVM_TIMEOUT_MSNo30000Default exec timeout in milliseconds

Resource naming

Deterministic from infra/resource-names.ts — <name>-${mnemose:env}:

ResourcePatternExample (env = dev)
D1 databasemnemose-{env}mnemose-dev
R2 bucketsmnemose-assets-{env}, mnemose-reports-{env}mnemose-assets-dev
KV namespacesmnemose-config-{env}, mnemose-sessions-{env}mnemose-config-dev
Queues + DLQsmnemose-commands-{env}, mnemose-events-{env} (+ -dlq)mnemose-commands-dev
Workersmnemose-{service}-{env}mnemose-gateway-dev
Pages projectmnemose-console-{env}mnemose-console-dev
Pulumi stackmnemose-{env}mnemose-dev