| 1 | /** |
| 2 | * Every state change in g1t is published as an event. Services react to |
| 3 | * each other through events rather than direct calls, and the same stream |
| 4 | * feeds timelines, webhooks and workflows. |
| 5 | * |
| 6 | * The envelope follows CloudEvents: `type` says what happened, `subject` |
| 7 | * says to what, `data` is the type-specific payload. |
| 8 | */ |
| 9 | |
| 10 | import type { RepoRole } from "./access"; |
| 11 | import type { Confidence, Verdict } from "./work"; |
| 12 | |
| 13 | /** What every `package.*` event names. */ |
| 14 | export type PackageEventData = { |
| 15 | packageId: string; |
| 16 | workspace: string; |
| 17 | ecosystem: string; |
| 18 | name: string; |
| 19 | repoId: string | null; |
| 20 | }; |
| 21 | |
| 22 | /** The payload of the `repo.collaborator_*` events. */ |
| 23 | export type RepoCollaboratorData = { |
| 24 | repoId: string; |
| 25 | namespace: string; |
| 26 | name: string; |
| 27 | username: string; |
| 28 | role: RepoRole | null; |
| 29 | previousRole: RepoRole | null; |
| 30 | }; |
| 31 | export type EventPayloads = { |
| 32 | "repo.created": { repoId: string; namespace: string; name: string; isPrivate: boolean }; |
| 33 | "repo.forked": { repoId: string; sourceRepoId: string; pullId: string }; |
| 34 | /** |
| 35 | * A repository's description, topics or visibility changed. |
| 36 | * `visibilityChanged` says whether it went public or private, which |
| 37 | * `repo.visibility_changed` also announces on its own. |
| 38 | */ |
| 39 | "repo.updated": { repoId: string; namespace: string; name: string; isPrivate: boolean; visibilityChanged: boolean }; |
| 40 | "repo.visibility_changed": { repoId: string; isPrivate: boolean }; |
| 41 | /** |
| 42 | * A repository's name changed within its workspace `namespace`, from |
| 43 | * `from` to `to`, keeping its id. A path change like `repo.transferred`: |
| 44 | * services move rows kept under its path to its *current* path (see |
| 45 | * `repoMove`, `currentMovedPath`). |
| 46 | */ |
| 47 | "repo.renamed": { repoId: string; namespace: string; from: string; to: string }; |
| 48 | /** |
| 49 | * A repository was deleted. It is hidden and git refuses it, but it can |
| 50 | * be restored until `purgeAfter`: services stop what runs for it and hide |
| 51 | * it, and keep their rows until `repo.purged`. |
| 52 | */ |
| 53 | "repo.deleted": { |
| 54 | repoId: string; |
| 55 | namespace: string; |
| 56 | name: string; |
| 57 | isPrivate: boolean; |
| 58 | purgeAfter: string; |
| 59 | /** It went with its workspace (`workspace.deleting`); deployments leaves it to that. */ |
| 60 | withWorkspace?: boolean; |
| 61 | }; |
| 62 | /** A deleted repository is back, as it was. Services start again what they stopped. */ |
| 63 | "repo.restored": { |
| 64 | repoId: string; |
| 65 | namespace: string; |
| 66 | name: string; |
| 67 | isPrivate: boolean; |
| 68 | /** It came back with its workspace (`workspace.restored`). */ |
| 69 | withWorkspace?: boolean; |
| 70 | }; |
| 71 | /** |
| 72 | * A deleted repository is gone for good, its git data with it. Services |
| 73 | * drop every row they keep for it, except a workspace's history (ledgers, |
| 74 | * invoices, the audit log). |
| 75 | */ |
| 76 | "repo.purged": { repoId: string; namespace: string; name: string }; |
| 77 | /** |
| 78 | * A repository was archived (read-only: pushes, merges, agents and |
| 79 | * workflows refused; issues and pull requests locked; deployments keep |
| 80 | * serving), or unarchived. |
| 81 | */ |
| 82 | "repo.archived": { repoId: string; namespace: string; name: string; archived: true }; |
| 83 | "repo.unarchived": { repoId: string; namespace: string; name: string; archived: false }; |
| 84 | /** The default branch is now `to`; `renamed` when `from` was renamed to it. */ |
| 85 | "repo.default_branch_changed": { repoId: string; from: string; to: string; renamed: boolean }; |
| 86 | /** A branch was renamed. Pull requests from it follow. */ |
| 87 | "branch.renamed": { repoId: string; from: string; to: string; defaultBranch: boolean }; |
| 88 | /** An account was made, or changed what its profile shows. Ask identity for the profile. */ |
| 89 | "user.updated": { username: string }; |
| 90 | /** A workspace was made, or its name, description or icon changed. */ |
| 91 | "workspace.updated": { workspaceId: string; slug: string }; |
| 92 | /** Someone, or g1t staff, made an invite. Never the code or the address. */ |
| 93 | "invite.created": { inviteId: string; inviterId: string | null; workspaceId: string | null; bound: boolean }; |
| 94 | /** An invite was used: by a new account, or by an account joining a workspace. */ |
| 95 | "invite.redeemed": { |
| 96 | inviteId: string; |
| 97 | userId: string; |
| 98 | inviterId: string | null; |
| 99 | workspaceId: string | null; |
| 100 | createdAccount: boolean; |
| 101 | }; |
| 102 | /** Someone asked for access while registration is invite-only. The address is not in the event. */ |
| 103 | "waitlist.requested": { entryId: string }; |
| 104 | /** |
| 105 | * One branch moved by a push. `ref` is the full ref, `after` the commit it |
| 106 | * points to now, and `defaultBranch` whether it is the default branch. |
| 107 | */ |
| 108 | "git.push": { repoId: string; ref: string; after: string; defaultBranch: boolean }; |
| 109 | /** |
| 110 | * `author` is who opened it: g1t, for one its agent filed while at work, |
| 111 | * with `requestedBy` the person it was working for. Every issue and pull |
| 112 | * request event carries both. |
| 113 | */ |
| 114 | "issue.opened": { |
| 115 | issueId: string; |
| 116 | repoId: string; |
| 117 | number: number; |
| 118 | title: string; |
| 119 | author?: { id: string; username: string }; |
| 120 | requestedBy?: { id: string; username: string }; |
| 121 | }; |
| 122 | "issue.updated": { issueId: string; repoId: string; number: number }; |
| 123 | /** The people an issue is assigned to changed; `assignees` is the new set. */ |
| 124 | "issue.assigned": { issueId: string; repoId: string; number: number; assignees: string[] }; |
| 125 | /** `resolvedBy` is the number of the pull request whose merge closed it. */ |
| 126 | "issue.closed": { |
| 127 | issueId: string; |
| 128 | repoId: string; |
| 129 | number: number; |
| 130 | reason: "completed" | "not_planned"; |
| 131 | resolvedBy?: number; |
| 132 | }; |
| 133 | "issue.reopened": { issueId: string; repoId: string; number: number }; |
| 134 | /** |
| 135 | * `issue` is the number of the issue the pull request is for. `author` is |
| 136 | * who opened it: g1t, for a change g1t made, with `requestedBy` the person |
| 137 | * who asked for it. |
| 138 | */ |
| 139 | "pull.opened": { |
| 140 | pullId: string; |
| 141 | repoId: string; |
| 142 | number: number; |
| 143 | issue?: number; |
| 144 | agent: string; |
| 145 | author?: { id: string; username: string }; |
| 146 | requestedBy?: { id: string; username: string }; |
| 147 | }; |
| 148 | /** `confidence`, on a g1t agent's change once g1t has worked it out, is on every pull request event. */ |
| 149 | "pull.ready": { pullId: string; repoId: string; number: number; issue?: number; confidence?: Confidence }; |
| 150 | /** A push moved the head of a pull request that is ready for review. */ |
| 151 | "pull.updated": { pullId: string; repoId: string; number: number; issue?: number; commit: string; confidence?: Confidence }; |
| 152 | /** A merge was asked for while the pull request was behind; it has to catch up first. */ |
| 153 | "pull.merge_requested": { pullId: string; repoId: string; number: number; issue?: number; confidence?: Confidence }; |
| 154 | "pull.closed": { pullId: string; repoId: string; number: number; issue?: number; confidence?: Confidence }; |
| 155 | /** |
| 156 | * The pull request's head or its target moved and the files both changed |
| 157 | * overlap: a sandbox should find out whether it still merges cleanly. |
| 158 | * `commit` is its head. |
| 159 | */ |
| 160 | "pull.mergecheck": { pullId: string; repoId: string; number: number; issue?: number; commit: string }; |
| 161 | /** Whether the pull request merges cleanly was settled. */ |
| 162 | "pull.mergeability": { pullId: string; repoId: string; number: number; issue?: number }; |
| 163 | /** Another agent asked the agent on a pull request, which was not at work, a question or handed it work. */ |
| 164 | "agent.asked": { pullId: string; repoId: string; number: number; issue?: number }; |
| 165 | "pull.merged": { pullId: string; repoId: string; number: number; issue?: number; commit: string; confidence?: Confidence }; |
| 166 | /** A run of the acceptance checks finished. `commit` is what was checked. */ |
| 167 | "checks.completed": { |
| 168 | pullId: string; |
| 169 | repoId: string; |
| 170 | number: number; |
| 171 | status: "passed" | "failed" | "errored"; |
| 172 | commit: string; |
| 173 | }; |
| 174 | /** A g1t agent finished reviewing a pull request; no verdict if it could not. */ |
| 175 | "review.completed": { |
| 176 | pullId: string; |
| 177 | repoId: string; |
| 178 | number: number; |
| 179 | verdict?: "approve" | "request_changes"; |
| 180 | }; |
| 181 | /** A person was given a role on one repository directly, had it changed, or lost it. `role` is null once removed. */ |
| 182 | "repo.collaborator_added": RepoCollaboratorData; |
| 183 | "repo.collaborator_removed": RepoCollaboratorData; |
| 184 | "repo.collaborator_role_changed": RepoCollaboratorData; |
| 185 | /** A repository's merge queue gained, lost or settled an entry. */ |
| 186 | "queue.changed": { repoId: string }; |
| 187 | /** `number` is the issue or pull request commented on. */ |
| 188 | "comment.created": { |
| 189 | commentId: string; |
| 190 | repoId: string; |
| 191 | number: number; |
| 192 | /** Set when the comment is on a pull request. */ |
| 193 | pullId?: string; |
| 194 | /** Set when the comment is a review. */ |
| 195 | verdict?: Verdict; |
| 196 | }; |
| 197 | "session.appended": { pullId: string; repoId: string; number: number; count: number }; |
| 198 | /** |
| 199 | * A package version was published, such as an image pushed by |
| 200 | * `docker push`. `tags` are the tags that now point to it; `repoId` (and |
| 201 | * the event's) is the repository the package is linked to, if any. |
| 202 | */ |
| 203 | "package.published": PackageEventData & { version: string; digest: string; size: number; tags: string[] }; |
| 204 | /** One version of a package was deleted, with the tags that pointed to it. */ |
| 205 | "package.version_deleted": PackageEventData & { version: string; digest: string }; |
| 206 | /** A package was deleted with every version it had. */ |
| 207 | "package.deleted": PackageEventData; |
| 208 | /** A package became public or private. */ |
| 209 | "package.visibility_changed": PackageEventData & { visibility: "public" | "private" }; |
| 210 | /** |
| 211 | * A workspace's slug changed from `from` to `to`. Services that store a |
| 212 | * slug move their rows to the workspace's *current* slug (see |
| 213 | * `currentWorkspaceSlug`), so a repeated or late delivery after a second |
| 214 | * rename still lands in the right place. |
| 215 | */ |
| 216 | "workspace.renamed": { workspaceId: string; from: string; to: string }; |
| 217 | /** |
| 218 | * A repository moved from workspace `from` to `to`, keeping its id and |
| 219 | * name. Services that store its path or its workspace's slug move those |
| 220 | * rows to its *current* path (ask repos `path_by_id`), so a repeated or |
| 221 | * late delivery after a second transfer still lands in the right place. |
| 222 | */ |
| 223 | "repo.transferred": { repoId: string; name: string; from: string; to: string }; |
| 224 | /** |
| 225 | * A workspace is gone. Services drop what they keep for it alone; ledgers, |
| 226 | * invoices and the audit log stay under its slug, which is never reused. |
| 227 | */ |
| 228 | "workspace.deleted": { workspaceId: string; slug: string }; |
| 229 | /** |
| 230 | * An owner deleted a workspace; staff can restore it until `purgeAfter`, |
| 231 | * and nobody can reach it meanwhile. Services hide what they keep for it |
| 232 | * and stop what runs for it, keeping their rows: repos deletes its |
| 233 | * repositories softly (`repo.deleted` with `withWorkspace`), deployments |
| 234 | * pauses its apps, search drops it. `workspace.restored` undoes exactly |
| 235 | * that; `workspace.deleted` follows once `purgeAfter` passes. `by` is the |
| 236 | * owner's username. |
| 237 | */ |
| 238 | "workspace.deleting": { workspaceId: string; slug: string; by: string; purgeAfter: string }; |
| 239 | /** |
| 240 | * Staff brought a deleted workspace back with its members and tokens. |
| 241 | * Services undo what they did on `workspace.deleting`, and only that. |
| 242 | */ |
| 243 | "workspace.restored": { workspaceId: string; slug: string }; |
| 244 | /** |
| 245 | * A memory was added, changed, reviewed or forgotten. No text: ask the |
| 246 | * work service for it by id. `repoId` is the project's, or null for the |
| 247 | * workspace's memory. `status` is `deleted` once forgotten. |
| 248 | */ |
| 249 | "memory.changed": { memoryId: string; workspace: string; status: "candidate" | "kept" | "dismissed" | "deleted" }; |
| 250 | /** |
| 251 | * A sandbox was stopped because it looked like it was mining: CPU pinned |
| 252 | * with little I/O and no progress, or a miner seen by name. For g1t's |
| 253 | * staff, in sudo; published with no `repoId` so it never reaches a |
| 254 | * repository's timeline or webhooks. `metrics` is what the sandbox |
| 255 | * measured (`Verdict` in crates/runner abuse.rs), or null if it could |
| 256 | * not say. |
| 257 | */ |
| 258 | "abuse.flagged": { |
| 259 | workspace: string; |
| 260 | repo: string | null; |
| 261 | /** The agent run, when the sandbox had one. */ |
| 262 | run: string | null; |
| 263 | /** What the sandbox was for: agent, checks, queue, actions, deploy... */ |
| 264 | kind: string; |
| 265 | sandbox: string; |
| 266 | metrics: Record<string, unknown> | null; |
| 267 | }; |
| 268 | }; |
| 269 | |
| 270 | export type EventType = keyof EventPayloads; |
| 271 | |
| 272 | export type G1tEvent<T extends EventType = EventType> = { |
| 273 | [K in T]: { |
| 274 | id: string; |
| 275 | type: K; |
| 276 | /** The service that published it. */ |
| 277 | source: string; |
| 278 | /** RFC 3339. */ |
| 279 | time: string; |
| 280 | /** The repo the event concerns, used to scope timelines and deliveries. */ |
| 281 | repoId: string | null; |
| 282 | /** The user or agent that caused it, if any. */ |
| 283 | actor: string | null; |
| 284 | data: EventPayloads[K]; |
| 285 | }; |
| 286 | }[T]; |
| 287 | |
| 288 | /** What a publisher supplies; the bus fills in `id` and `time`. */ |
| 289 | export type NewEvent<T extends EventType = EventType> = { |
| 290 | [K in T]: Omit<G1tEvent<K>, "id" | "time">; |
| 291 | }[T]; |
| 292 | |
| 293 | export type EventQuery = { |
| 294 | repoId?: string; |
| 295 | types?: EventType[]; |
| 296 | /** Return events older than this event id. */ |
| 297 | before?: string; |
| 298 | limit?: number; |
| 299 | }; |
| 300 | |
| 301 | /** The event bus and its durable log. */ |
| 302 | export interface EventsApi { |
| 303 | publish(events: NewEvent[]): Promise<void>; |
| 304 | /** Newest first. */ |
| 305 | list(query: EventQuery): Promise<G1tEvent[]>; |
| 306 | } |