Skip to content
Version 1.0.0

Deployment profiles

The two build profiles, what they change, and which one you get by default.

The deployment profile is a build parameter, not a runtime setting. An artifact does not know which profile produced it, and cannot switch.

ProfileEffect
on-premiseRestricted artifact. The network output layer is the inert implementation, the one the code imports by default: no error reporting, no version check. This is the profile you get by default, without specifying anything, and nothing needs to be run to get it. (The product has not measured usage in any profile since 11 August 2026.)
serverlessFull artifact, intended for a deployment operated by the publisher. The network output layer is active. You have to ask for it explicitly.

Through a command-line argument:

Fenêtre de terminal
node build.mjs --profile=serverless

Or through an environment variable:

Fenêtre de terminal
LEMNISCATE_DEPLOYMENT_PROFILE=serverless node build.mjs

With neither, the build produces on-premise. An unrecognized value fails the build rather than falling back to a default: the only accepted values are on-premise and serverless.

The check inspects the six deliverables, and it only judges what was built: a missing component is not compliant, it is reported as missing and the check fails. So build them first:

Fenêtre de terminal
npm run build --prefix extensions/cli
npm run esbuild-base --prefix extensions/vscode
(cd gui && NODE_OPTIONS=--max-old-space-size=6144 npx vite build)
npm run build --prefix llm-gateway
npm run build --prefix gateway-admin
(cd extensions/intellij && ./gradlew buildPlugin)

The sixth, the JetBrains plugin, is written in Kotlin: module substitution does not reach it. You request its profile from Gradle, with the same rule and the same closed default: ./gradlew buildPlugin produces the air-gapped one, -PprofilDeploiement=serverless the open one. It ships as an archive, which the check opens, along with the .jar it contains.

Fenêtre de terminal
node scripts/verify-onprem-artifact.mjs

To check only one of them, the --composant option narrows the scope and says so in its output: it does not waive any check, it only states what it did not look at.

The check covers the built bundle, not the source code.