Skip to main content
PostgreSQL holds the authoritative memory text, revisions, evidence, and permissions. Optional search providers add semantic candidates; their indexes are disposable projections and never authorize disclosure.

Choose a backend

Embedding providers are configured independently: ollama uses /api/embed; http uses an /embeddings API. Set the endpoint, model, and expected dimensions. Dimension mismatches, non-finite vectors, and incomplete responses are rejected.

Configure and test

Use the installation’s Settings page, or these operator API endpoints: Saving validates locally; it does not establish connectivity. Provider keys are write-only encrypted installation secrets. Omitting a key preserves it; an empty key clears it. Example shape for pgvector with an Ollama embedding service:
This example assumes Ollama runs on a trusted, isolated network. Use HTTPS when connecting across an untrusted network. Replace the model and dimension placeholders with values matching your service. The allowed memory token budget is 256–32,768; the default is 4,096.

Confidential processing

Embedding a query exports that query as well as any indexed memory text. Enable allow_confidential_processing only for endpoints approved to process that material. This setting permits data sharing; it does not secure the transport. Use HTTPS for remote endpoints. Limit plain HTTP to services on a trusted, isolated network: it sends memory text, queries, and any API key without transport encryption. Mesh accepts both schemes and does not enforce HTTPS. A local-looking hostname is not proof of trust. With permission disabled, confidential conversations keep authorized local lexical retrieval. The optional sensitivity advisor can add a conversation restriction or suggest asking about sharing. It cannot grant permission. See memory privacy.

Rebuilds and failure behavior

Canonical revision writes enqueue index jobs. Workers use expiring fenced leases, bounded retries, and idempotent revision upserts. Changing the backend, endpoint, embedding model, dimensions, or processing policy changes the projection generation and rebuilds from canonical state. Every semantic query is scoped to one agent and an explicit eligible revision set. Returned IDs are distrusted: Mesh reloads current text and permissions from PostgreSQL. Forgotten or superseded memories cannot reappear through a stale index. Missing, unavailable, or rebuilding indexes degrade to authorized lexical results. Reindexing can reuse cached embeddings for an unchanged model configuration. Use a versioned model name or change configuration when a service changes its model behind an existing name. Retiring an endpoint does not delete that service’s old collections or backups; clean those up separately.

Operations and legacy data

Retrieval audits record selection and degradation categories. Inspect projection backlog without exposing memory text:
confidential_processing_disabled identifies deliberate withholding from an external provider. Unknown legacy audience evidence is a different issue: text remains available to administrators but is withheld from runtime retrieval until supported by authenticated evidence or explicit review. Do not label old private records public merely to make search return them. Optional adapter integration tests use MESH_TEST_PGVECTOR_URL and MESH_TEST_QDRANT_URL; the ordinary database suite uses MESH_TEST_DATABASE_URL. Use isolated test services and the migration runner. Implementation: internal/memory/providers (repository), internal/memory/indexer.go (repository), and internal/memory/config.go (repository).