# Requirements

URL: https://helmr.dev/docs/self-hosting/requirements
Description: Prepare the accounts, tools, release inputs, data services, and network policy required for self-hosting.

# Requirements

Prepare these inputs before applying either AWS composition.

## Accounts and tools

- An AWS account and one primary AWS region.
- AWS credentials allowed to create the VPC, load balancer, ECS, RDS, ElastiCache, S3, KMS, Secrets Manager, IAM, EC2, Auto Scaling, and optional CloudFront resources in the composition you select.
- OpenTofu or Terraform, plus the AWS CLI, `jq`, OpenSSL, and curl. The repository's Nix development shell provides the pinned project toolchain.
- A GitHub OAuth app for browser login.
- A customer-owned ClickHouse service reachable from Control Plane, dispatcher, and migration tasks over HTTPS.

## Required deployment inputs

Both `infra/aws/quickstart` and `infra/aws/standard` require:

| Input | Purpose |
| --- | --- |
| `aws_region` | Selects regional infrastructure and the release's worker AMI. |
| `helmr_version` | Resolves the official AWS release manifest. |
| `region_id` | Identifies this Helmr region. |
| `worker_group_name` | Names the initial logical worker group. |
| `platform_store_uri` | Points to immutable Platform Artifact objects. |
| `platform_store_bucket_arn` | Authorizes access to the Platform Artifact bucket. |
| `platform_store_kms_key_arn` | Authorizes decryption of Platform Artifacts. |
| `clickhouse_url` | HTTPS endpoint for historical telemetry. |
| `github_oauth_client_id` | Non-secret OAuth application client ID. |
| `worker_network_blocked_ipv4_cidrs` | Deployment-owned deny set that must wholly cover the execution VPC prefix. |

The Platform Artifact values come from `infra/aws/modules/release-storage` as a child module under an operator-owned root and backend, or from an equivalent deployment. The example compositions do not create that foundation for you. Compose `infra/aws/modules/release-publisher` separately when you need a publisher role, passing the exact storage outputs and your trusted IAM principals.

## Release artifacts

Stable and preview common releases publish a signed `release-index.json` with
CLI, SDK, Control Plane/builder images, and Worker host/runtime bundles. Neither
publishes managed AMIs or `aws-artifacts.json`.

For these releases, supply the AWS compositions' explicit `controlplane_image`
(digest-pinned from the verified index's Control Plane descriptor) and
`worker_ami_id` when workers are enabled. Prepare that AMI in your deployment
from the selected host/runtime bundles. Selecting `helmr_version` alone cannot
supply those AWS-specific inputs: the generic resolver's manifest default is
not an output of the common release graph. An operator-owned AWS manifest is
also an explicit preparation input; it is not a Product publication fallback.

## Worker prerequisites

Workers additionally need:

- Private-subnet outbound access to the Control Plane, S3, ECR, AWS APIs, registries, and any external services tasks call.
- KVM-capable EC2 capacity. The evaluation profile supports explicitly enabled nested virtualization on supported families; the production profile defaults to a metal instance.
- A worker AMI containing `worker`, Firecracker, jailer, `ip`, `nft`, AWS CLI v2, curl, the systemd unit, and certified guest boot artifacts.
- Explicit host, VM, cache, disk, and execution-slot capacity sized for the workload.
- SSM access for maintenance unless you supply an alternative. The module does not open SSH by default.

Review [workers](/docs/self-hosting/workers) before creating capacity.
