Skip to content
302 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow1// Everything g1t deploys to Cloudflare, in one place. Read by
2// scripts/deploy.mjs (plan, deploy), deploy/self-host/configs.mjs (what a
3// self-hosted installation runs) and the tests in scripts/deploy/.
4// docs/DEPLOYING.md explains each field and how to add a unit.
5//
6// What is written here is what the Wrangler configs cannot say. The rest is
7// read from each unit's wrangler.jsonc, never copied: its D1 databases and
8// migrations, the services it binds to, its KV, R2, queues and routes. The
9// shared crates and packages a unit is built from are read from Cargo's and
10// npm's workspace metadata. `worker` and `d1` are written here too, so the
11// file reads as an inventory, and a test checks they match the configs.
12{
13 // Deployed in this order. A stage starts only when the one before it
14 // succeeded. A unit binds only to units in its own stage or an earlier
15 // one (a test checks it), so new code never calls a service that has
16 // not shipped yet. Within a stage, units go out in parallel.
17 //
18 // migrations: every pending D1 migration, before any code.
19 // core: the services, reached through service bindings.
20 // edge: public endpoints other than the site: API, MCP, models, g1t.page, status.
21 // front: the site, sudo and the docs.
22 "stages": ["migrations", "core", "edge", "front"],
23
24 // Names for the resources the configs refer to by id, for setup
25 // commands and the docs. A test checks every KV id in a config is here.
26 "resources": {
27 "kv": {
28 "16a4232cb746418db53782aa068be693": "g1t-actions-blobs",
29 "e627b571f07047e187c03e1fc2b3bbdd": "g1t-avatars",
30 "14bc5c233d4c46a5bbf23b5367cce5fd": "g1t-domains",
31 "be765052d0124c2a935b3db4dff99f1f": "g1t-repos-git-cache"
32 }
33 },
34
35 // Each deployable unit, by short name (`--only events,web`).
36 //
37 // kind: rust-worker (worker-build), ts-worker (Wrangler bundles it),
38 // react-router (vite build first), astro (astro build first).
39 // secrets: names only; set with `npx wrangler secret put NAME` in its folder.
40 // setup: one-time steps no config can say, for a first deploy.
41 // self_host: what deploy/self-host does with it: "run" (in the one
42 // workerd), "off" (bound to the off Worker), "separate" (a
43 // process of its own), or "none".
44 // inputs: files outside its folder it is built from that no workspace
45 // metadata names (a test finds such imports).
Fast pages, required checks on the branch, self-hosted runners, honest incidents46 // image: a Containers image (docs/DEPLOYING.md, "The runner's images"):
47 // dockerfile the image a deploy ships: the base plus the binary
48 // crate the crate that binary is built from (and what it uses)
49 // base { context: the base's folder, lock: the file that
50 // records the base that was pushed }; the base is
51 // rebuilt only when its folder changes
52 // repository where both are pushed in Cloudflare's registry
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow53 "units": {
54 "events": {
55 "path": "services/events",
56 "kind": "rust-worker",
57 "worker": "g1t-events",
58 "d1": { "database": "g1t-events", "migrations": "migrations" },
59 "stage": "core",
60 "secrets": [],
Merge branch 'worktree-agent-ad8a36dfcd4176015' into spend-guardrails61 "setup": [
62 "The dead-letter queue every queue consumer sends what it gave up on to, before any unit that names it deploys: npx wrangler queues create g1t-events-dlq"
63 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow64 "self_host": "run"
65 },
66 "identity": {
67 "path": "services/identity",
68 "kind": "rust-worker",
69 "worker": "g1t-identity",
70 "d1": { "database": "g1t", "migrations": "migrations" },
71 "stage": "core",
72 "secrets": ["GITHUB_APP_CLIENT_SECRET", "IDENTITY_KEY"],
73 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
74 "self_host": "run"
75 },
76 "repos": {
77 "path": "services/repos",
78 "kind": "rust-worker",
79 "worker": "g1t-repos",
80 "d1": { "database": "g1t-repos", "migrations": "migrations" },
81 "stage": "core",
82 "secrets": ["REPOS_KEY"],
Merge branch 'worktree-agent-a1b995daa94e4e1b7'83 "setup": [
84 "The Artifacts namespace `g1t` (the ARTIFACTS binding)",
Merge branch 'worktree-agent-ac5b181a013e54348'85 "The R2 bucket `g1t-git-packs` (GIT_PACKS) with its lifecycle rule: `npx wrangler r2 bucket create g1t-git-packs`, then `npx wrangler r2 bucket lifecycle add g1t-git-packs expire-packs packs/ --expire-days 7 --abort-multipart-days 1`",
86 "The R2 bucket for nightly backups: npx wrangler r2 bucket create g1t-backups"
Merge branch 'worktree-agent-a1b995daa94e4e1b7'87 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow88 "self_host": "run"
89 },
90 "work": {
91 "path": "services/work",
92 "kind": "rust-worker",
93 "worker": "g1t-work",
94 "d1": { "database": "g1t-work", "migrations": "migrations" },
95 "stage": "core",
96 "secrets": [],
97 "self_host": "run"
98 },
99 "search": {
100 "path": "services/search",
101 "kind": "rust-worker",
102 "worker": "g1t-search",
103 "d1": { "database": "g1t-search", "migrations": "migrations" },
104 "stage": "core",
105 "secrets": [],
106 "self_host": "run"
107 },
108 "projects": {
109 "path": "services/projects",
110 "kind": "ts-worker",
111 "worker": "g1t-projects",
112 "d1": { "database": "g1t-projects", "migrations": "migrations" },
113 "stage": "core",
114 "secrets": [],
115 "self_host": "run"
116 },
117 "billing": {
118 "path": "services/billing",
119 "kind": "rust-worker",
120 "worker": "g1t-billing",
121 "d1": { "database": "g1t-billing", "migrations": "migrations" },
122 "stage": "core",
Stripe's webhook secret is a Worker secret, STRIPE_WEBHOOK_SECRET, from a destination made in Stripe's dashboard123 "secrets": ["STRIPE_SECRET_KEY", "STRIPE_WEBHOOK_SECRET", "CLOUDFLARE_USAGE_TOKEN"],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow124 "self_host": "run"
125 },
126 "integrations": {
127 "path": "services/integrations",
128 "kind": "rust-worker",
129 "worker": "g1t-integrations",
130 "d1": { "database": "g1t-integrations", "migrations": "migrations" },
131 "stage": "core",
132 "secrets": ["INTEGRATIONS_KEY", "GITHUB_APP_PRIVATE_KEY", "GITHUB_APP_WEBHOOK_SECRET"],
133 "self_host": "run"
134 },
135 "webhooks": {
136 "path": "services/webhooks",
137 "kind": "rust-worker",
138 "worker": "g1t-webhooks",
139 "d1": { "database": "g1t-webhooks", "migrations": "migrations" },
140 "stage": "core",
141 "secrets": ["WEBHOOKS_KEY"],
142 "self_host": "run"
143 },
144 "actions": {
145 "path": "services/actions",
146 "kind": "rust-worker",
147 "worker": "g1t-actions",
148 "d1": { "database": "g1t-actions", "migrations": "migrations" },
149 "stage": "core",
150 "secrets": ["ACTIONS_KEY"],
151 "self_host": "run"
152 },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member153 "packages": {
154 "path": "services/packages",
155 "kind": "rust-worker",
156 "worker": "g1t-packages",
157 "d1": { "database": "g1t-packages", "migrations": "migrations" },
158 "stage": "core",
159 "secrets": ["PACKAGES_TOKEN_SECRET", "R2_ACCESS_KEY_ID", "R2_SECRET_ACCESS_KEY"],
160 "setup": [
161 "The D1 database: npx wrangler d1 create g1t-packages, its id in services/packages/wrangler.jsonc",
162 "The R2 bucket for packages' files: npx wrangler r2 bucket create g1t-packages",
163 "The events queue: npx wrangler queues create g1t-events-packages",
164 "For signed downloads: an R2 API token with read access to g1t-packages, as R2_ACCESS_KEY_ID and R2_SECRET_ACCESS_KEY"
165 ],
166 "self_host": "run"
167 },
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow168 "security": {
169 "path": "services/security",
170 "kind": "rust-worker",
171 "worker": "g1t-security",
172 "d1": { "database": "g1t-security", "migrations": "migrations" },
173 "stage": "core",
174 "secrets": [],
175 "self_host": "run"
176 },
177 "deployments": {
178 "path": "services/deployments",
179 "kind": "ts-worker",
180 "worker": "g1t-deployments",
181 "d1": { "database": "g1t-deployments", "migrations": "migrations" },
182 "stage": "core",
183 "secrets": ["CLOUDFLARE_API_TOKEN"],
184 "setup": [
185 "Workers for Platforms, and the dispatch namespace: scripts/setup-deployments.sh",
186 "Custom domains (Cloudflare for SaaS on g1t.page): scripts/setup-custom-domains.sh"
187 ],
188 "self_host": "run"
189 },
190 "runner": {
191 "path": "services/runner",
192 "kind": "ts-worker",
193 "worker": "g1t-runner",
194 "stage": "core",
195 "secrets": ["AI_GATEWAY_TOKEN"],
Fast pages, required checks on the branch, self-hosted runners, honest incidents196 "setup": [
197 "Containers on the account; Docker on the machine that builds a new image",
198 "The base image, once: node scripts/deploy.mjs build-base"
199 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow200 "image": {
201 "dockerfile": "services/runner/Dockerfile",
Fast pages, required checks on the branch, self-hosted runners, honest incidents202 // The binary the image adds to its base (scripts/build-runner.mjs).
203 "crate": "g1t-runner",
204 "base": { "context": "services/runner/base", "lock": "services/runner/base.json" },
205 "repository": "g1t-runner"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow206 },
207 "self_host": "off"
208 },
209 "context": {
210 "path": "services/context",
211 "kind": "ts-worker",
212 "worker": "g1t-context",
213 "d1": { "database": "g1t-context", "migrations": "migrations" },
214 "stage": "core",
215 "secrets": [],
216 "setup": [
217 "The Vectorize index: npx wrangler vectorize create g1t-context --dimensions=768 --metric=cosine, with metadata indexes on workspace, kind, project and private"
218 ],
219 "self_host": "off"
220 },
221 "og": {
222 "path": "services/og",
223 "kind": "ts-worker",
224 "worker": "g1t-og",
225 "stage": "core",
226 "secrets": [],
227 "setup": ["Browser Rendering on the account (the BROWSER binding)"],
228 // The roadmap cards read the site's roadmap.
229 "inputs": ["apps/web/app/lib/roadmap.ts"],
230 "self_host": "none"
231 },
232 "api": {
233 "path": "apps/api",
234 "kind": "rust-worker",
235 "worker": "g1t-api",
236 "stage": "edge",
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2237 // ACTIONS_OIDC_KEY signs workflow jobs' OIDC tokens; without it the
238 // issuer answers 404 and jobs are not offered tokens.
239 // ACTIONS_OIDC_KEY_PREVIOUS only while rotating. docs/DEPLOYING.md.
240 "secrets": ["ACTIONS_OIDC_KEY"],
241 "setup": [
242 "The OIDC signing key for workflow jobs: an RSA key made with `openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048`, stored with `npx wrangler secret put ACTIONS_OIDC_KEY` (docs/DEPLOYING.md, \"OIDC tokens for workflow jobs\")",
243 "The actions cache bucket's lifecycle rule limited to `c/`, so artifacts under `a/` are kept their retention-days (docs/DEPLOYING.md)"
244 ],
Merge branch 'worktree-agent-aaf03bdceac799c89'245 "self_host": "separate"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow246 },
247 "models": {
248 "path": "services/models",
249 "kind": "ts-worker",
250 "worker": "g1t-models",
251 "stage": "edge",
252 "secrets": ["AI_GATEWAY_TOKEN"],
253 "setup": ["The AI Gateway `g1t`"],
254 "self_host": "none"
255 },
256 "pages": {
257 "path": "services/pages",
258 "kind": "ts-worker",
259 "worker": "g1t-pages",
260 "stage": "edge",
261 "secrets": [],
262 "setup": ["A proxied wildcard DNS record on g1t.page (`*`, AAAA 100::): scripts/setup-deployments.sh"],
263 "self_host": "none"
264 },
265 "status": {
266 "path": "apps/status",
267 "kind": "ts-worker",
268 "worker": "g1t-status",
269 "d1": { "database": "g1t-status", "migrations": "migrations" },
270 "stage": "edge",
271 "secrets": ["STATUS_SECRET"],
272 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
273 "self_host": "separate"
274 },
275 "web": {
276 "path": "apps/web",
277 "kind": "react-router",
278 "worker": "g1t",
279 "stage": "front",
280 "secrets": [],
Fast pages, required checks on the branch, self-hosted runners, honest incidents281 "setup": ["The R2 bucket g1t-downloads, for the self-hosted runner's releases: npx wrangler r2 bucket create g1t-downloads"],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow282 "self_host": "run"
283 },
284 "sudo": {
285 "path": "apps/sudo",
286 "kind": "react-router",
287 "worker": "g1t-sudo",
288 "stage": "front",
289 "secrets": [],
290 "setup": ["A Cloudflare Access application on sudo.g1t.sh; its AUD tag is ACCESS_AUD"],
291 "self_host": "none"
292 },
293 "docs": {
294 "path": "apps/docs",
295 "kind": "astro",
296 "worker": "g1t-docs",
297 "stage": "front",
298 "secrets": [],
299 "self_host": "none"
300 }
301 }
302}

This file's history is long; its oldest lines are credited to the oldest commit read.