---
title: Deployment and services
description: Configure the services your fork needs and preserve the boundaries that make it recoverable.
---

The repository includes a working application backend and clients. A production installation also needs service accounts, storage, identity and platform distribution. There is no single command that provisions all of these for a new operator.

These instructions support personal and internal business deployments under ELv2. A hosted or managed service that gives third parties access to a substantial set of Impo's features or functionality requires a separate license from the rights holders. See [source and dependencies](/docs/#source-and-dependencies) for the license scope.

## Start with the required core

Run the API and worker as separate processes against the same PostgreSQL database. Use Drizzle entities as the schema source and `npm run db:push` during development. The production agent path needs Rebyte configuration; the deterministic runtime is for local protocol work.

The default local identity mode is restricted to development. Configure Clerk for a hosted installation. Bind public origins and client environments to your own deployment; do not ship a fork pointing at someone else's account services by accident.

## Add services by capability

| Capability | Service and configuration |
| --- | --- |
| Real agent execution | Rebyte; `REBYTE_API_KEY` and `INSTANT_RUNTIME=rebyte`. |
| Connected apps | Composio; server-owned credentials and verified OAuth bindings. |
| Durable schedules and background steps | Temporal address, namespace and worker queue. |
| Voice transcription and speech | Server-side provider configuration, including `GEMINI_API_KEY` for the current speech adapter. |
| Audio and transcript archive | Private S3 storage, limited signed uploads and cleanup rules. |
| Long-term memory | Per-user Turso stores and configured embedding/model services. |
| Phone notifications | FCM and, for iOS, APNs configuration; a durable notification outbox. |
| Gadgets | The Cloudflare gadget gateway and server-to-gateway credentials. |

Use [`.env.example`](https://github.com/impoai/impo/blob/main/.env.example) and the [server guide](https://github.com/impoai/impo/blob/main/server/README.md) for exact variables. Keep local configuration and signing material untracked. Provision secrets through your deployment's secret store.

## Publish clients and the website

iOS needs an Apple signing identity and application configuration. Android needs its own package/signing setup. Web needs the correct identity configuration, same-origin API proxy and direct-upload CORS policy.

The website and generated documentation live under `site/`. `npm run build:site` renders the handbook. `npm run build:web` builds the Web app and stages it under `site/app/` alongside the website. The Pages worker preserves `/app/`, API, download and release routes.

A fork must create its own hosting project and service bindings before using deployment commands. Existing commands in this repository target Impo's configured project; they are not generic infrastructure provisioning.

## Validate a release

Check API health and database readiness, then verify an authenticated command through the worker and back to the client. Exercise an uncertain response and recovery, not only the initial request.

Run checks appropriate to the changed capability. A connector protocol double cannot establish a real OAuth grant. Simulator audio and Bluetooth mocks cannot establish microphone or physical gadget behavior. Record what was actually exercised.

## Operate the data lifecycle

Retain owned execution receipts long enough for recovery. Apply the documented upload expiration and account-deletion flows. Back up durable state according to your operator policy, and ensure deletion also reaches derived context and provider resources.

Follow the [architecture storage guide](/docs/architecture/context/) and repository [security policy](https://github.com/impoai/impo/blob/main/SECURITY.md) when adding a new hosted service.
