Architecture
Ramose separates authority, persistence, and local interaction while keeping one public model. The architecture is optimized for many independent graph databases rather than one globally writable cluster.
Request edge
Section titled “Request edge”One Cloudflare Worker terminates HTTPS, synchronization, and MCP. It verifies identity, selects the deployed database and catalog server-side, applies request limits, and routes work to the database’s stateful components.
The Worker is stateless for correctness. MCP requests do not depend on sticky sessions or in-memory client state.
One writer per database
Section titled “One writer per database”Each graph has one authoritative writer that orders operations, checks grants and visible targets, runs operation bodies, validates facts, assigns the next version, and commits all or nothing.
This is the source of simple uniqueness, exact operation receipts, dense ordering, and deterministic history. It is also the database write ceiling.
Immutable read values
Section titled “Immutable read values”Read copies serve immutable database values built from persisted indexes plus committed changes. A request selects current, as-of, or history semantics, filters that value for the principal, and only then evaluates the query.
Content-addressed index nodes and retained roots live in R2. Stateful coordination and recent change data live with the graph’s Durable Objects. A failed storage write cannot expose a partial commit.
Complete browser replicas
Section titled “Complete browser replicas”The browser receives logical authorized facts and opaque revisions, not physical indexes or raw transaction metadata. It persists one complete local value per active principal and database, builds local indexes, and derives query results.
Snapshots install atomically. Resume streams authorized additions and removals. Incompatible catalog or read-view changes reset the committed replica while preserving compatible queued invocation identity.
Database routing
Section titled “Database routing”Configured deployments establish the database and catalog binding. Callers cannot select internal database or catalog identities.
Failure model
Section titled “Failure model”Clients retry transient transport and platform failures. Durable receipts make repeated operation delivery safe. Read copies and browser replicas can reset from a complete snapshot.
Workflows that include external systems are sequences of independently committed operations with application-level compensation or reconciliation.