Skip to content
57 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API reference examples use projects1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-api",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
Fast pages, required checks on the branch, self-hosted runners, honest incidents6 "placement": { "mode": "off" },
API reference examples use projects7 "main": "build/index.js",
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow8 "build": { "command": "node ../../scripts/build-rust-worker.mjs" },
API reference examples use projects9 "workers_dev": false,
10 // One Worker, two hostnames: REST on api, MCP on mcp. Both are thin
11 // adapters over the same operations.
12 "routes": [
13 { "pattern": "api.g1t.sh", "custom_domain": true },
14 { "pattern": "mcp.g1t.sh", "custom_domain": true }
15 ],
16 "services": [
17 { "binding": "IDENTITY", "service": "g1t-identity" },
18 { "binding": "REPOS", "service": "g1t-repos" },
19 { "binding": "WORK", "service": "g1t-work" },
20 { "binding": "EVENTS", "service": "g1t-events" },
21 { "binding": "RUNNER", "service": "g1t-runner" },
22 { "binding": "BILLING", "service": "g1t-billing" },
23 { "binding": "INTEGRATIONS", "service": "g1t-integrations" },
24 { "binding": "WEBHOOKS", "service": "g1t-webhooks" },
25 { "binding": "ACTIONS", "service": "g1t-actions" },
26 // Builds of deployments report through here.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API27 { "binding": "DEPLOYMENTS", "service": "g1t-deployments" },
28 // The context hub: search_context and get_entity.
Search across all of g1t, Explore, and a command palette29 { "binding": "CONTEXT", "service": "g1t-context" },
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily30 { "binding": "SEARCH", "service": "g1t-search" },
31 // Secret and dependency alerts: list_security_alerts and dismissing them.
API: pinned projects over REST and MCP32 { "binding": "SECURITY", "service": "g1t-security" },
33 // A person's pinned projects: list_pinned_projects and changing them.
Merge packages: roles, Actions access, source label, soft delete, API34 { "binding": "PROJECTS", "service": "g1t-projects" },
35 // Packages: list_packages, their settings, deleting and restoring them.
Merge main into Artifacts Phase 236 { "binding": "PACKAGES", "service": "g1t-packages" },
37 // Artifacts (folios): the artifact tool and /workspaces/{ws}/artifacts.
Every agent can have its own computer. A session that needs one wakes it: a home of its own on g1t cloud, one per agent and never shared, where it runs commands, reads and writes files and keeps what it made, with each session working in its own folder under a shared home; after ten idle minutes it sleeps, its home kept as a snapshot and restored when it wakes, and Reset wipes the home while memory and artifacts stay. Its shell and files are abilities with the usual choices, Alone, Alone when asked, Ask first or Never, offered only inside sessions and never to a chat reply; every command shows on the session with its output, and the agent's new Computer tab shows the state, the disk used of the five gigabytes included, the recent commands, and Wake, Put to sleep and Reset. Machine time counts only while it is awake, on the sandbox lines of the ledger that name the agent and who asked, held to the same spend caps as the session; the disk itself costs nothing in this version. The runner gained a long-lived supervisor that answers the computer's requests inside the container, and the runner service a computer per agent that keeps its snapshot in the agent homes bucket when one is attached, and says so when none is. The REST API and the agent tool can read a computer, wake it, put it to sleep and reset it. The agents, abilities, sessions, runners, billing and deploy guides say how it works and what an operator sets up; pinning a computer to your own runner, its browser and take-over come next.38 { "binding": "ARTIFACTS", "service": "g1t-artifacts" },
39 // Workspace agents' own computers: /workspaces/{ws}/agents/{agent}/computer.
40 { "binding": "AGENTS", "service": "g1t-agents" }
API reference examples use projects41 ],
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R242 // GitHub Actions artifacts older runners kept, in chunks, with KV's own
43 // expiry, read until it passes (and cache
Fast pages, required checks on the branch, self-hosted runners, honest incidents44 // entries saved before the cache moved to R2, until they expire).
API reference examples use projects45 "kv_namespaces": [{ "binding": "BLOBS", "id": "16a4232cb746418db53782aa068be693" }],
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R246 // actions/cache entries (`c/`) and artifacts (`a/`), uploaded in parts. The actions
Fast pages, required checks on the branch, self-hosted runners, honest incidents47 // service lists them and decides what is kept (services/actions/src/cache.rs).
48 "r2_buckets": [{ "binding": "ACTIONS_CACHE", "bucket_name": "g1t-actions-cache" }],
Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails49 // REST and MCP requests (src/limits.rs): per token, or per address
50 // without one. Ids and limits: RATE_LIMITS in packages/contracts.
51 "ratelimits": [
52 { "name": "API_ANONYMOUS_LIMIT", "namespace_id": "4401", "simple": { "limit": 60, "period": 60 } },
53 { "name": "API_TOKEN_LIMIT", "namespace_id": "4402", "simple": { "limit": 1000, "period": 60 } }
54 ],
55 // Logs of a tenth of requests: agents call it constantly.
56 "observability": { "enabled": true, "head_sampling_rate": 0.1 }
API reference examples use projects57}

This file's history is long; its oldest lines are credited to the oldest commit read.