OpenInspect
Administration

Deployment overview

What an OpenInspect deployment consists of, what the operator configures once, and where the self-hosting, setup, and debugging guides live.

Last reviewed View as MarkdownEdit on GitHubGive feedback

This page orients an operator: the parts of a deployment, the decisions made once at setup, and where the full runbooks are. It is not a step-by-step guide; those live in the repository.

What a deployment consists of

ComponentRuns onRole
Web clientVercel, or Cloudflare Workers via OpenNextThe browser app: sign-in, sessions, settings, analytics.
Control planeCloudflare Workers with Durable Objects and a D1 databaseSession state, live streaming over WebSockets, sandbox lifecycle, source-control integration, authentication and access control, encrypted secrets.
Sandbox data planeOne configured sandbox providerIsolated per-session development environments where the agent runs.
Slack bot (optional)Cloudflare WorkerStarts sessions from Slack messages and posts results back.
GitHub bot (optional)Cloudflare WorkerAutomatic PR reviews and @mention handling from GitHub webhooks.
Linear bot (optional)Cloudflare WorkerStarts sessions from Linear issue activity.

Every client sees the same session state because state lives in the control plane, not in the client. A prompt sent from Slack or GitHub shows up on the web in real time.

Terraform creates the infrastructure. The operator's job is to create the accounts, gather credentials, and fill in one configuration file; Terraform's job is to create and wire the services.

Sandbox providers

A deployment runs on exactly one sandbox provider, chosen at setup:

ProviderSession resume model
Modal (default)Filesystem snapshot restore
DaytonaPersistent sandbox stopped and started again
Vercel SandboxesFilesystem snapshot restore
OpenComputerCheckpoint-backed restore
E2BPersistent sandbox paused and resumed

Provider differences that users notice (which resource and timeout settings apply, how prebuilt images are stored, and the Daytona prebuild admission switch) are covered in Sandbox providers.

What the operator configures once

AreaWhat is set
GitHub AppOne App installation, required in every deployment. Its installation scope is the set of repositories the workspace can reach. Install it on selected repositories, not all.
Sign-in providersGitHub OAuth, Google OAuth, or both. At least one is required; partial credential pairs are rejected.
Admission allowlistsGitHub usernames, email domains, exact email addresses, or GitHub organizations. A user is admitted if they match any allowlist. Set at least one for production; open access is a separate explicit opt-in.
Sandbox provider credentialsThe API credentials, and where applicable the base snapshot or template, for the chosen provider.
Security secretsGenerated once: the token encryption key, the repo-secrets encryption key, the sandbox API secret, the browser authentication secret, and the GitHub webhook secret when the GitHub bot is enabled. A provider-accounts encryption key is generated by Terraform unless overridden.
Model credentialsOptional at deploy time. An Anthropic key can be injected fleet-wide, or model credentials can be added later as global secrets in the web app. The Slack and Linear classifier needs a key for whichever provider it runs on.
Optional botsSlack app, GitHub bot webhook, Linear OAuth app, each enabled with its own flag.
Branding: app_nameShown in the web tab title, sign-in page, landing hero, Slack and Linear messages, the pull request footer, and outbound User-Agent headers.
Branding: app_icon_urlOptional. Replaces the built-in icon and favicon.
Execution timeoutOptional control-plane variable EXECUTION_TIMEOUT_MS: the longest one prompt may run when the session's sandbox settings set no timeout. When unset, the limit is 2 hours.

Web branding values are inlined at build time, so a rebrand needs a fresh web build; the bot and control-plane workers read the name at request time.

Changing most of these means editing the configuration file and applying Terraform again. EXECUTION_TIMEOUT_MS is set in the control-plane worker's environment.

Initial Owner bootstrap

Owner assignment is an explicit operator action, not something sign-in grants:

  1. After deployment, the intended Owner signs in once. This creates their user with the default Member role.
  2. The operator runs the Owner bootstrap command against the D1 database with that person's canonical user ID, as a dry run first. The dry run reports whether it is ready. The command refuses a suspended or missing user or an existing unsuspended Owner, and there is no force option.
  3. The operator runs the command for real. It writes a workspace.owner_bootstrapped audit event and replaces the assignment in one transaction.
  4. The control-plane health endpoint now reports the owner assignment as present.

The exact commands are in the self-hosting guide linked below.

Keeping a deployment current

Updating means pulling the latest code, rebuilding the shared package if it changed, and applying Terraform again; it only changes what differs. If the web app is on Vercel it is redeployed separately; on Cloudflare, Terraform rebuilds it. The self-hosting guide also documents an optional GitHub Actions workflow for applying deployments from CI.

Where the runbooks are

GuideUse it for
Self-hosting guideThe full deployment walkthrough: accounts, credentials, GitHub App, Terraform phases, bots, Owner bootstrap, verification, CI/CD.
Setup guideRunning the web app locally against an existing backend, contributing code, or the fastest path to a full stack.
Debugging playbookQuerying the structured JSON logs every service emits, and the correlation fields (trace, session, message IDs) that join them.
How it worksArchitecture, sandbox lifecycle, snapshots, and the security model in depth.

Keep configuration out of source control

The Terraform variable files hold every credential for the deployment. Never commit them; use your CI's secret store for automated applies, and rotate secrets by updating the file and applying again.

Next steps

On this page