Self-Hosting
Self-host the Altered Digital Worker for enterprise deployments with full control over data residency.
Enterprise self-host
For enterprise customers who need full control over data residency, the Altered Digital Worker can be self-hosted on Cloudflare Workers with your own D1 database, KV namespace, and R2 bucket. Set the SELF_HOST=1 environment flag to short-circuit tenant lookup — the Worker uses env-var Sanity credentials directly.
Environment variables
| Variable | Required | Description |
|---|---|---|
SELF_HOST | Yes | Set to 1 to enable self-host mode |
SANITY_PROJECT_ID | Yes | Your Sanity project ID |
SANITY_DATASET | No | Default: production |
SANITY_API_TOKEN | Yes | Read+write API token |
WP_WEBHOOK_SECRET | Yes | Shared secret for WP webhook signature |
NEXTJS_REVALIDATE_URL | No | Your Next.js /api/revalidate endpoint |
NEXTJS_REVALIDATE_SECRET | No | Secret for the revalidate endpoint |
MIGRATION_DB | Yes | D1 database binding |
CACHE_KV | No | KV namespace for caching |
ASSETS_R2 | No | R2 bucket for asset staging |
What self-host mode skips
When SELF_HOST=1:
- No tenant resolution — the Worker uses
selfHostSanityConfig()(env vars) for all Sanity calls - No D1 tenant lookup — the webhook signature is verified against
WP_WEBHOOK_SECRETdirectly - No AI service calls — AI transform fallback is disabled (the Worker has no
AI_SERVICE_URL/AI_SERVICE_INTERNAL_TOKEN) - No
/v2/connect— tenants aren't created (single-tenant by definition) - No
/v2/cleanup— returns 409 (cleanup is a multi-tenant AI feature) - No
/v2/mcp/*— returns 409 (MCP hand-off requires a tenant record)
Deploying
Use the deployment script:
This runs scripts/deploy.mjs — an interactive, idempotent setup that creates your D1 database, KV namespace, and R2 bucket (if missing), writes wrangler.toml, and deploys the Worker.
When to choose self-host
- Data residency requirements — your content must stay within your Cloudflare account
- Custom Sanity cluster — you run a dedicated Sanity cluster
- No AI features needed — you only want deterministic Gutenberg migration
- SLA monitoring — you need direct control over the Worker's uptime
For most customers, the cloud multi-tenant deployment is recommended — it includes AI transform fallback, content cleanup, schema generation, and the Claude Connect hand-off.