Skip to content
Mimir

Worker architecture

Mimir runs as one Cloudflare Worker. The deployment combines the model gateway, harness ingestion, session APIs, dashboard, and storage bindings.

These features share authentication, session identity, storage, and deployment. Keeping them together avoids internal network calls and separate failure modes.

worker/wrangler.jsonc points Cloudflare to worker/src/index.ts.

index.ts exports the Hono application and SessionObject Durable Object. worker/src/app.ts registers middleware and route groups:

const app = new Hono<AppEnv>();
installErrorHandling(app);
installAuthentication(app);
registerMachineRoutes(app);
registerProxyRoutes(app);
registerSessionRoutes(app);
registerSearchRoutes(app);
registerConfigRoutes(app);
registerIntegrationRoutes(app);
registerDashboardAuthRoutes(app);
registerDashboardSessionRoutes(app);
registerDashboardExchangeRoutes(app);
registerDashboardDeviceRoutes(app);
registerDashboardFacetRoutes(app);
export default app;

/v1/* forwards supported OpenRouter requests, preserves streaming, and schedules capture without delaying the response.

Harness adapters report lifecycle events and reconstructed exchanges when model traffic does not pass through the proxy. The Worker validates and redacts these records, stores exchanges in R2, and writes searchable metadata to D1.

/sessions/* handles lifecycle, titles, hierarchy, outcomes, capture status, live state, and reconciliation. A Session Durable Object coordinates each live session. D1 and R2 hold durable state.

Machine-token endpoints provide identity, association, configuration, search, integration health, and CLI access.

The Worker serves the Vue dashboard and its Cloudflare Access-protected APIs. The dashboard reads the same session data as the machine API.

worker/src/
├── index.ts deployment exports
├── app.ts middleware and route registration
├── env.ts bindings and Hono environment
├── auth/ machine and Access authentication
├── config/ configuration routes and storage
├── gateway/ OpenRouter proxy
├── exchanges/ capture, redaction, evidence, dashboard routes
├── sessions/ lifecycle, queries, outcomes, titles, status
├── machines/ machine and device routes
├── integrations/ harness registration and health
├── search/ search routes
├── dashboard/ dashboard shell and cursors
└── shared/ small cross-feature utilities

HTTP handlers live with the feature they expose. Shared product rules belong in domain functions used by both machine and dashboard routes.

Route handlers parse and validate input, enforce authorization, call domain operations, and return HTTP responses. They do not reimplement session identity, outcome precedence, redaction, or capture eligibility.

Direct D1 and R2 calls are fine when local and clear. Repeated queries that encode a product rule should move behind a named domain operation. Mimir does not use a generic repository or dependency-injection layer.

Dependencies point inward:

index.ts -> app.ts -> routes -> domain operations -> storage bindings
\-> response projection

Domain modules do not import route or dashboard code.

Each tool-bearing harness supplies a fixture with session identity, repository, model, tool calls, errors, and lifecycle events. Worker integration tests verify that ingestion produces the expected session, searchable files and errors, and Git evidence.

Architecture changes should pass:

Terminal window
npm --prefix worker test
npm --prefix worker run typecheck
bun test plugins/pi/ plugins/opencode/
python -m unittest discover -s plugins/hermes -p "test_*.py"
go test ./internal/harness/hooks ./internal/install ./internal/doctor
cd worker && npx wrangler deploy --dry-run

The deployment remains one Worker with feature-owned modules and one composition root.