Skip to content

Deploying Titlesearch ​

A deployed Titlesearch serves the web UI, the REST API, and the MCP server at /mcp, behind your organization's sign-in. Add https://<your server>/mcp to Claude as a custom connector.

TargetGuideCachePreviewsOAuth
Google Cloud Rungoogle-cloud-run.mdFirestoreRenderer serviceYour identity provider issues the tokens
AWS Lambda (or ECS)aws-lambda.mdDynamoDBRenderer functionYour identity provider issues the tokens
Cloudflare Workerscloudflare-workers.mdD1Browser RenderingThe Worker issues the tokens; your provider signs people in

Pick an identity provider first: identity-providers.md. Whatever the target, Titlesearch is read-only, and it isn't a trademark search.

Status. These targets are built and tested locally: emulators for Firestore and DynamoDB, and workerd for the Worker, including the full OAuth flow. CI builds and smoke-tests the container images and validates the Terraform. They haven't yet been run on a live Google Cloud, AWS, or Cloudflare account. On a first deployment, check sign-in, health checks, and WHOIS egress, and please report what you find.

Settings ​

Every target reads the same settings. They're environment variables on Cloud Run and AWS, and vars and secrets on Workers. Secrets must come from the platform's secret store, never plain environment variables or files. A problem with the configuration stops startup with a message naming the setting, never its value.

SettingRequiredMeaning
PUBLIC_URLYesWhere users reach the server, as an https:// origin. Only this host is answered.
EXTRA_HOSTSOther Host values to accept, comma-separated (a Lambda function URL behind CloudFront, for example).
OIDC_ISSUERYesYour identity provider's issuer URL.
OIDC_AUDIENCEThe aud access tokens carry. Defaults to PUBLIC_URL + /mcp. Cloud Run and AWS only.
OIDC_CLIENT_IDFor sign-inThe OAuth client for browser sign-in, and, on Workers, for the MCP sign-in step.
OIDC_CLIENT_SECRETSecretThat client's secret. Omit for a public client: PKCE protects the exchange.
SESSION_SECRETSecret, requiredAt least 32 random characters. Signs session cookies. Terraform generates it.
ALLOWED_EMAILSOne rule is requiredVerified email addresses allowed in, comma-separated.
ALLOWED_EMAIL_DOMAINSVerified email domains allowed in.
ALLOWED_SUBJECTSOAuth subjects (sub) allowed in.
REQUIRED_SCOPEA scope your provider grants only to permitted users. Access tokens only.
REQUIRED_ROLEAn app role your provider assigns only to permitted users (the roles claim).
GODADDY_ENABLEDtrue (default) or false.
WHOIS_ENABLEExtra WHOIS extensions, such as de (ADR 8).
PORKBUN_API_KEY, PORKBUN_SECRET_API_KEYSecretsPrices from Porkbun. A sandbox key (pk1_sb_…) is recommended: see ADR 17.
NAMECOM_USERNAME, NAMECOM_TOKENToken is a secretPrices from Name.com. NAMECOM_ENVIRONMENT=test uses its sandbox.
ANTHROPIC_API_KEYSecretServer-side market-overlap judgment. Without it, Claude judges in chat.
ASSESSMENT_MODEserver (a model here judges), client, or off. anthropic is the old name for server.
ASSESSMENT_PROVIDERanthropic (default) or openai-compatible, for OpenRouter, Groq, Together, or your own vLLM or llama.cpp server.
ASSESSMENT_MODEL, ASSESSMENT_EFFORTDefaults: claude-opus-5-5, medium.
ASSESSMENT_BASE_URLFor openai-compatibleThe server's base URL, such as https://vllm.internal.example/v1.
OPENAI_COMPATIBLE_API_KEYSecretThat server's key, if it needs one. Sent only over HTTPS.
RENDERER_URL, RENDERER_TOKENToken is a secretThe renderer service, for screenshots.
RATE_LIMIT_PER_MINUTE, CONCURRENCYPer-user request limit (default 120 a minute) and outbound ceiling (default 8).
LOG_LEVELerror, warn, info (default), or debug. Logs are JSON, with secrets redacted.

The container also reads CACHE_BACKEND (firestore, dynamodb, or memory), GOOGLE_CLOUD_PROJECT, FIRESTORE_DATABASE, DYNAMODB_TABLE, AWS_REGION, and PORT. On AWS, any secret, and PUBLIC_URL, may be given as NAME_ARN, a Secrets Manager ARN read at startup.

Building the images ​

From the repository root:

sh
docker build -f deploy/container/Dockerfile --target api      -t titlesearch-api .
docker build -f deploy/container/Dockerfile --target renderer -t titlesearch-renderer .

Push both to your registry and deploy them by digest. The renderer image is about 1 GB, mostly Chromium and fonts.

Apache-2.0. Titlesearch is read-only, and it isn't a trademark search.