flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/runner/wrangler.jsonc

75 lines3,680 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Hosted agents: sandboxes on Cloudflare Containers started from an intent1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-runner",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 "main": "./src/index.ts",
7 "workers_dev": false,
8 "containers": [
9 {
10 "class_name": "AttemptSandbox",
11 // Built from the repository root so the image can compile the
12 // runner crate.
13 "image": "./Dockerfile",
14 "image_build_context": "../..",
15 "instance_type": "standard-1",
Agents as a team: lifecycle, merge queue, billing and a new shell16 "max_instances": 20,
17 // A deploy replaces sandboxes. Ones that are busy are given this
18 // long, in seconds, to finish first, so shipping g1t does not
19 // kill agents in the middle of their work.
20 "rollout_active_grace_period": 7200
Hosted agents: sandboxes on Cloudflare Containers started from an intent21 }
22 ],
23 "durable_objects": {
24 "bindings": [{ "name": "SANDBOX", "class_name": "AttemptSandbox" }]
25 },
26 "migrations": [{ "tag": "v1", "new_sqlite_classes": ["AttemptSandbox"] }],
27 "services": [
28 { "binding": "IDENTITY", "service": "g1t-identity" },
Agents as a team: lifecycle, merge queue, billing and a new shell29 { "binding": "REPOS", "service": "g1t-repos" },
30 { "binding": "WORK", "service": "g1t-work" },
Integrations: your own model provider, alerts that open issues, tickets agents read31 { "binding": "BILLING", "service": "g1t-billing" },
GitHub Actions on g1t, part two: running workflows32 { "binding": "INTEGRATIONS", "service": "g1t-integrations" },
Deployments: a preview for every pull request, production on g1t.page33 { "binding": "ACTIONS", "service": "g1t-actions" },
Project dependencies: addresses, preview stacks, Affects, and agents who know34 { "binding": "DEPLOYMENTS", "service": "g1t-deployments" },
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API35 { "binding": "PROJECTS", "service": "g1t-projects" },
36 // The context hub: the Context section every agent run starts with.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look37 { "binding": "CONTEXT", "service": "g1t-context" },
38 // The event bus: abuse.flagged, when a sandbox looks like it is mining.
39 { "binding": "EVENTS", "service": "g1t-events" }
Hosted agents: sandboxes on Cloudflare Containers started from an intent40 ],
Agents as a team: lifecycle, merge queue, billing and a new shell41 // A sweep for lifecycle steps whose trigger was missed or whose sandbox
42 // died before reporting.
43 "triggers": { "crons": ["*/5 * * * *"] },
Acceptance checks in sandboxes, line comments and review verdicts44 // Events it reacts to: a pull request ready for review, or its head moving.
45 "queues": {
46 "consumers": [{ "queue": "g1t-events-runner", "max_batch_size": 20, "max_batch_timeout": 1 }]
47 },
Hosted agents: sandboxes on Cloudflare Containers started from an intent48 "vars": {
Models per workspace: several providers, routed by kind of work49 // Each workspace chooses where its agents' model spend goes: its own
50 // provider (under Integrations) or g1t's hosted models, paid from its
51 // credit. While billing takes no real money, hosted models are open
52 // only to these workspaces; once it does, to every workspace.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look53 "HOSTED_AGENT_WORKSPACES": "flagon-io",
Agents as a team: lifecycle, merge queue, billing and a new shell54 // Which model each kind of work runs on. Nobody assigning an agent
55 // chooses; this is g1t's policy. "modelName" is shown to people in the
56 // session; "model" is sent to the provider.
57 "AGENT_ROUTES": "{\"implement\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\"},\"review\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\"},\"update\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\"},\"plan\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\"}}",
Integrations: your own model provider, alerts that open issues, tickets agents read58 // Where sandboxes send model requests, with a token for their run.
59 // The proxy holds the keys: g1t's gateway's, or the workspace's own.
60 "MODELS_URL": "https://models.g1t.sh",
g1t agents: model menu and optional AI Gateway routing61 // Set to a Cloudflare AI Gateway id to route model traffic through it.
Integrations: your own model provider, alerts that open issues, tickets agents read62 // Used only when MODELS_URL is unset.
Agents as a team: lifecycle, merge queue, billing and a new shell63 "AI_GATEWAY_ID": "g1t",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API64 "CLOUDFLARE_ACCOUNT_ID": "1e6f2cffa3f445920836e8ebe446bb58",
65 // Guardrails' network list is enforced by starting sandboxes without
66 // internet and passing their HTTP(S) through this Worker. "off" opens
67 // every sandbox's network again, whatever its guardrails say.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look68 "EGRESS": "enforce",
69 // Sandboxes stop themselves when they look like they are mining
70 // (crates/runner abuse.rs). "off" turns the CPU watch off; miners
71 // named in commands are refused either way.
72 "ABUSE_WATCH": "on"
Hosted agents: sandboxes on Cloudflare Containers started from an intent73 },
74 "observability": { "enabled": true }
75}