Skip to content
Admin guide

Admin guide

This guide is for the people who deploy and operate a PULSE instance.

Who deploys PULSE

CORE does. This repository holds application code and the backend image build. Cluster bring-up, the operator, and deploys all live in CORE:

cd ../core/grpc                 # CORE's Go module
go run ./cmd/core deploy pulse

CORE’s pulse-operator reconciles the instance into the pulse-system namespace. The operator’s custom resource is the authoritative pod spec, so change the resource or its overlay, not the live Deployment. Deploys are plain kustomize.

What this repository ships

The backend image, built from grpc/Dockerfile with the repository root as the build context. The build is self-contained. It:

  1. Builds the Flutter web bundle, with CanvasKit bundled locally instead of fetched from a CDN, and with no source maps.
  2. Clones the sibling repositories that grpc/go.mod points at, using a short-lived token passed as a build argument.
  3. Compiles a static, cgo-free Go server. The SQLite driver (modernc.org/sqlite) needs no C toolchain.

The runtime image is debian:bookworm-slim with:

  • ffmpeg, for assembling video creatives.
  • chromium, for every feature that reads live web pages: the Site Audit, lead prospecting, and market signals.
  • Litestream, pinned by SHA-256, with its schedule in grpc/litestream.yml.

Voice transcription is not in the image. Like the text model, it runs as a separate service that PULSE reaches through VOXTRAL_REMOTE_URL.

One instance per deployment

SQLite has one writer, so each deployment runs one backend instance. In a cluster, Litestream replicates the database to the in-cluster object store. CORE’s operator refuses any other object-store endpoint.

Serving the web app

Set PULSE_WEB_DIR to the Flutter web build, and the backend serves the app itself, on the same origin as the API. Then no CORS configuration is needed.

First things to set

SettingWhy
PULSE_JWT_SECRETRequired. The server will not start without it.
CORE_ENVELOPE_KEKRequired. The database refuses to open without it, rather than write OAuth tokens in plaintext.
TENANT_IDNames the tenant for billing, the profile page, and the Admin page.
PULSE_WEB_DIR or CORS_ALLOWED_ORIGINSServe the app same-origin, or pin the origins that may call the API.
INFERENCE_REMOTE_URL, INFERENCE_MODELPoint at the shared inference plane, and name the model it serves.

The full list is in the configuration reference.