Admin guide
This guide is for the people who deploy and operate a PULSE instance.
Who deploys PULSE
CORE does. This repository holds application code and the backend image build. Cluster bring-up, the operator, and deploys all live in CORE:
cd ../core/grpc # CORE's Go module
go run ./cmd/core deploy pulseCORE’s pulse-operator reconciles the instance into the pulse-system
namespace. The operator’s custom resource is the authoritative pod spec, so
change the resource or its overlay, not the live Deployment. Deploys are plain
kustomize.
What this repository ships
The backend image, built from grpc/Dockerfile with the repository root as
the build context. The build is self-contained. It:
- Builds the Flutter web bundle, with CanvasKit bundled locally instead of fetched from a CDN, and with no source maps.
- Clones the sibling repositories that
grpc/go.modpoints at, using a short-lived token passed as a build argument. - Compiles a static, cgo-free Go server. The SQLite driver
(
modernc.org/sqlite) needs no C toolchain.
The runtime image is debian:bookworm-slim with:
- ffmpeg, for assembling video creatives.
- chromium, for every feature that reads live web pages: the Site Audit, lead prospecting, and market signals.
- Litestream, pinned by SHA-256, with its schedule in
grpc/litestream.yml.
Voice transcription is not in the image. Like the text model, it runs as a
separate service that PULSE reaches through VOXTRAL_REMOTE_URL.
One instance per deployment
SQLite has one writer, so each deployment runs one backend instance. In a cluster, Litestream replicates the database to the in-cluster object store. CORE’s operator refuses any other object-store endpoint.
Serving the web app
Set PULSE_WEB_DIR to the Flutter web build, and the backend serves the app
itself, on the same origin as the API. Then no CORS configuration is needed.
First things to set
| Setting | Why |
|---|---|
PULSE_JWT_SECRET | Required. The server will not start without it. |
CORE_ENVELOPE_KEK | Required. The database refuses to open without it, rather than write OAuth tokens in plaintext. |
TENANT_ID | Names the tenant for billing, the profile page, and the Admin page. |
PULSE_WEB_DIR or CORS_ALLOWED_ORIGINS | Serve the app same-origin, or pin the origins that may call the API. |
INFERENCE_REMOTE_URL, INFERENCE_MODEL | Point at the shared inference plane, and name the model it serves. |
The full list is in the configuration reference.