| 1 | --- |
| 2 | title: What g1t can't do yet |
| 3 | description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned. |
| 4 | --- |
| 5 | |
| 6 | This page lists what g1t cannot do today. Each entry says what you can't |
| 7 | do, why, what to do instead, and where it stands. |
| 8 | |
| 9 | Where it stands is one of: |
| 10 | |
| 11 | - **Planned**: we intend to build it. We don't give dates we can't keep. |
| 12 | - **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs |
| 13 | something the platform does not offer yet. |
| 14 | - **Not scheduled**: no work is planned on it now. |
| 15 | |
| 16 | Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/). |
| 17 | |
| 18 | If you hit a limit that is not here, tell us at |
| 19 | [g1t.sh/support](https://g1t.sh/support), and we will add it. |
| 20 | |
| 21 | ## Git |
| 22 | |
| 23 | ### No git over SSH |
| 24 | |
| 25 | You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does |
| 26 | not work. |
| 27 | |
| 28 | - **Why.** SSH needs inbound TCP connections on port 22. g1t runs on |
| 29 | Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta |
| 30 | for inbound TCP; we have applied and are waiting. |
| 31 | - **Instead.** Use the HTTPS remote with an |
| 32 | [access token](/guides/git/#authentication). It does everything SSH would: |
| 33 | clone, fetch and push. SSH keys you add under **Settings → SSH keys** are |
| 34 | kept for when SSH arrives. |
| 35 | - **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh). |
| 36 | |
| 37 | ### Repositories up to 1 GB, files up to 32 MB, no LFS |
| 38 | |
| 39 | A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is |
| 40 | not supported. A push that would cross either is declined before it is |
| 41 | stored, and git prints why. See [Size limits](/guides/git/#size-limits). |
| 42 | |
| 43 | - **Why.** These are the limits of Cloudflare Artifacts, where every |
| 44 | repository is stored. |
| 45 | - **Instead.** Keep large binaries out of the repository: in a release |
| 46 | bucket, a package registry or object storage, fetched at build time. |
| 47 | - **Status.** Large file storage is planned. Raising the limits themselves |
| 48 | depends on Cloudflare. |
| 49 | |
| 50 | ### Pushes up to 100 MB each |
| 51 | |
| 52 | A single push can carry up to 100 MB. A larger one is refused with HTTP |
| 53 | `413` before g1t sees it. |
| 54 | |
| 55 | - **Why.** Cloudflare's network limits the size of one request body on the |
| 56 | plan g1t.sh is on. |
| 57 | - **Instead.** Push history in steps, oldest first: |
| 58 | `git push origin <older-commit>:refs/heads/main`, then a newer one, then |
| 59 | `main`. Each push sends only what the last did not. |
| 60 | - **Status.** Depends on Cloudflare. |
| 61 | |
| 62 | ### Imports and mirrors up to 40 MB |
| 63 | |
| 64 | Importing or mirroring a repository copies it in one piece of at most |
| 65 | 40 MB, after compression. |
| 66 | |
| 67 | - **Why.** The copy is held in memory while it moves, and a Worker has |
| 68 | 128 MB for everything it is doing at once. |
| 69 | - **Instead.** Clone the repository yourself and push it to g1t, in steps if |
| 70 | it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across). |
| 71 | - **Status.** Streaming the copy, so size stops mattering, is planned. |
| 72 | |
| 73 | ### Partial clone works, but is not promised |
| 74 | |
| 75 | `git clone --filter=blob:none` returns a real partial clone today. We don't |
| 76 | promise it will keep doing so. |
| 77 | |
| 78 | - **Why.** Cloudflare's documentation says filters are not supported, but |
| 79 | they work with git's protocol version 2. We have asked whether that is |
| 80 | intended. |
| 81 | - **Instead.** Use it, and fall back to `--depth=1` for a shallow clone, |
| 82 | which is supported. |
| 83 | - **Status.** Depends on Cloudflare. |
| 84 | |
| 85 | ### No server-side hooks of your own |
| 86 | |
| 87 | You can't run a script of your own on g1t when a push arrives, before or |
| 88 | after its refs move. |
| 89 | |
| 90 | - **Why.** The git store has no hook for this. g1t's own checks run in front |
| 91 | of it, in g1t's code: [protected branches](/guides/git/#protected-branches) |
| 92 | and [push protection](/guides/security/#push-protection). |
| 93 | - **Instead.** Protect the default branch and make your workflows |
| 94 | [required checks](/guides/pull-requests/#required-status-checks). To react |
| 95 | after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`. |
| 96 | - **Status.** Not scheduled for your own scripts. A hook in the store, |
| 97 | which would let g1t enforce more before refs move, depends on Cloudflare. |
| 98 | |
| 99 | ### Very large pushes are scanned after they land, not before |
| 100 | |
| 101 | A very large push is too large for push protection to read before it is |
| 102 | stored, so it is let through, and g1t scans every commit it added |
| 103 | afterwards, in the background. A secret found that way is an open alert |
| 104 | rather than a refused push, and the workspace's owners are emailed when one |
| 105 | looks real. Most pushes are scanned before they land. |
| 106 | |
| 107 | - **Why.** Scanning reads the whole push inside a Worker, which has 128 MB |
| 108 | for everything it is doing at once. Past a certain size, scanning could fail |
| 109 | the push outright, and refusing such pushes would block importing real |
| 110 | repositories. |
| 111 | - **Instead.** To have a large history checked before it lands, push it in |
| 112 | steps (see above), so each push is scanned first. Secrets already in |
| 113 | history are listed under |
| 114 | [Secrets in history](/guides/security/#secrets-in-history). |
| 115 | - **Status.** Planned: scanning while the push streams, at any size. |
| 116 | |
| 117 | ### Deleting history does not free storage |
| 118 | |
| 119 | Storage is counted from what is pushed, and the count only grows. Deleting |
| 120 | a branch, or force-pushing over commits, does not lower it. |
| 121 | |
| 122 | - **Why.** The git store does not say whether or when it reclaims space |
| 123 | from objects nothing points to any more, or report how much a repository |
| 124 | holds. So g1t cannot see it either. |
| 125 | - **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in |
| 126 | a private repository and counts against you, tell us at |
| 127 | [g1t.sh/support](https://g1t.sh/support). |
| 128 | - **Status.** Depends on Cloudflare. See |
| 129 | [private repository storage](/guides/usage-and-billing/#private-repository-storage). |
| 130 | |
| 131 | ## Pull requests and forks |
| 132 | |
| 133 | ### Forks are only for pull requests |
| 134 | |
| 135 | You can't fork a repository into your own workspace. On g1t, a fork is a |
| 136 | pull request's own working copy, made when the pull request is opened. |
| 137 | |
| 138 | - **Why.** We built forks to isolate agents' work, one per pull request. |
| 139 | See [Forks and branches](/concepts/forks/). |
| 140 | - **Instead.** To contribute, open a pull request: it gets its own fork. To |
| 141 | start a copy of your own, clone the repository and push it to a new one |
| 142 | in your workspace; pushing creates it. |
| 143 | - **Status.** Not scheduled. |
| 144 | |
| 145 | ### Pull request forks are removed a day after they close |
| 146 | |
| 147 | A day after a pull request merges or closes, its fork's git data is |
| 148 | removed. The pull request's changes stay readable: its head is kept in the |
| 149 | repository as `refs/pull/<pull request id>/head`. Pushing to the fork, or |
| 150 | reopening the pull request, makes the fork again from there. |
| 151 | |
| 152 | - **Why.** Cloudflare has not documented whether a fork shares stored |
| 153 | objects with its source or copies them, so forks are not kept longer |
| 154 | than they are useful. |
| 155 | - **Instead.** Nothing you need to do. To keep working on a closed pull |
| 156 | request's change, fetch `refs/pull/<pull request id>/head` and push it |
| 157 | to a branch. |
| 158 | - **Status.** Clear fork storage rules depend on Cloudflare. |
| 159 | |
| 160 | ### Some dependency update options are not applied yet |
| 161 | |
| 162 | g1t reads and checks every option of a `dependabot.yml` file, but does not |
| 163 | act on all of them yet: |
| 164 | |
| 165 | - Version update pull requests are opened for npm, Cargo, Go and pip only. |
| 166 | Entries for other ecosystems are checked and listed, and open nothing. |
| 167 | |
| 168 | - A multi-ecosystem group opens one pull request per ecosystem, not one |
| 169 | for the group. |
| 170 | - Registries that sign in with OIDC are not used. |
| 171 | |
| 172 | - **Instead.** Keep a separate entry per ecosystem and directory, and |
| 173 | check the Security page, which lists what each entry reads but does not |
| 174 | act on. See [Dependency updates](/guides/dependency-updates/#options). |
| 175 | - **Status.** Planned. |
| 176 | |
| 177 | ### No conflict resolution in the browser |
| 178 | |
| 179 | You can't resolve a merge conflict on the pull request's page. |
| 180 | |
| 181 | - **Instead.** Ask g1t to resolve it, or fix it on the command line. |
| 182 | See [Conflicts](/guides/pull-requests/#conflicts). |
| 183 | - **Status.** Planned. |
| 184 | |
| 185 | ## Actions and runners |
| 186 | |
| 187 | ### Docker shares the job's network |
| 188 | |
| 189 | A job's Docker Engine runs its containers on the job's own network, not on |
| 190 | networks of their own. A service is reached at `localhost` and by its |
| 191 | name, as on GitHub, but two containers cannot listen on the same port, and |
| 192 | `docker network create` gives no separation between containers. |
| 193 | |
| 194 | - **Why.** Jobs run in Cloudflare Containers, which let a container run |
| 195 | Docker but not route a container network of its own out, or change its |
| 196 | packet filter. Sharing the job's network is also what keeps the job's |
| 197 | guardrails on every container. |
| 198 | - **Instead.** Give containers that would clash different ports. |
| 199 | - **Status.** Not scheduled. |
| 200 | |
| 201 | ### No `type=gha` build cache |
| 202 | |
| 203 | Buildx's GitHub Actions cache backend (`cache-to: type=gha`) is skipped on |
| 204 | g1t, and the build runs without a cache. |
| 205 | |
| 206 | - **Why.** It talks to GitHub's cache service, which g1t's cache does not |
| 207 | speak yet. |
| 208 | - **Instead.** Use a registry cache in g1t's container registry |
| 209 | (`type=registry`), or `type=local` with `actions/cache`. See |
| 210 | [caching image builds](/guides/actions/#caching-image-builds). |
| 211 | - **Status.** Planned. |
| 212 | |
| 213 | ### No multi-platform image builds on g1t's machines |
| 214 | |
| 215 | Building an image for another platform, such as `linux/arm64`, needs QEMU's |
| 216 | emulators, which g1t's machines do not have set up. |
| 217 | |
| 218 | - **Instead.** Build other platforms on a |
| 219 | [self-hosted runner](/guides/self-hosted-runners/) of that architecture, |
| 220 | or one with QEMU set up. |
| 221 | - **Status.** Planned. |
| 222 | |
| 223 | ### Linux only on g1t's machines |
| 224 | |
| 225 | A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own |
| 226 | machines. |
| 227 | |
| 228 | - **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux, |
| 229 | macOS and Windows, on x64 and arm64. |
| 230 | - **Status.** Not scheduled. |
| 231 | |
| 232 | ### No `gh` command in jobs |
| 233 | |
| 234 | The runner does not include the `gh` command, and pointing it at g1t |
| 235 | (`GH_HOST=g1t.sh`) does not work. |
| 236 | |
| 237 | - **Why.** Most of `gh`'s commands use a GraphQL API, and the rest expect |
| 238 | the REST API under `/api/v3` on the same host. g1t's API is REST, at |
| 239 | `api.g1t.sh`. |
| 240 | - **Instead.** Call the API with `curl` and the job's token. See |
| 241 | [calling g1t's API from a job](/guides/actions/#calling-g1ts-api-from-a-job). |
| 242 | - **Status.** Not scheduled. |
| 243 | |
| 244 | ### One Ruby for `ruby/setup-ruby` |
| 245 | |
| 246 | On g1t's machines, `ruby/setup-ruby` finds Ruby 3.3, which the runner |
| 247 | includes, and fails for any other version. |
| 248 | |
| 249 | - **Why.** Its prebuilt Rubies are for other Linux systems, so on Debian it |
| 250 | uses only the Rubies already in `RUNNER_TOOL_CACHE`. |
| 251 | - **Instead.** Use 3.3, run the job in a `container:` with the Ruby you |
| 252 | need (such as `ruby:3.4`), or build it in a step with `ruby-build`. See |
| 253 | [languages and their setup actions](/guides/actions/#languages-and-their-setup-actions). |
| 254 | - **Status.** Not scheduled. |
| 255 | |
| 256 | ### Machine sizes, time and storage |
| 257 | |
| 258 | | Limit | Value | |
| 259 | | --- | --- | |
| 260 | | Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. | |
| 261 | | One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. | |
| 262 | | One cache entry | 2 GiB, compressed. A larger one is not saved. | |
| 263 | | A repository's caches | 10 GiB together. Past it, the entries restored longest ago are removed. | |
| 264 | | One artifact | 5 GiB, zipped. Kept 14 days unless the repository says otherwise, at most 90. | |
| 265 | | A run's artifacts | 10 GiB together. | |
| 266 | |
| 267 | The machine sizes are Cloudflare Containers' instance sizes. For more, use a |
| 268 | [self-hosted runner](/guides/self-hosted-runners/). See |
| 269 | [Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache). |
| 270 | |
| 271 | ### Workflow features not supported yet |
| 272 | |
| 273 | - Actions that upload or download artifacts with the toolkit's artifact |
| 274 | library themselves. The library refuses to run against any server but |
| 275 | github.com. `actions/upload-artifact`, `actions/download-artifact` and |
| 276 | `actions/upload-artifact/merge` work, as g1t runs them itself. |
| 277 | - A cache entry between 100 and 128 MB saved by an action built on the |
| 278 | toolkit, such as `setup-node` with `cache: npm`. The toolkit sends an |
| 279 | entry under 128 MB in one request, and g1t takes at most 100 MB in one |
| 280 | request, as for [pushes](#pushes-up-to-100-mb-each). The step warns and |
| 281 | the job goes on; smaller and larger entries are saved. |
| 282 | - `on: delete`: deleting a branch or tag starts no workflows. New branches |
| 283 | and tags start `create` and `push` workflows. |
| 284 | |
| 285 | See [Not yet](/guides/actions/#not-yet). **Status.** Planned. |
| 286 | |
| 287 | ### No npm trusted publishing or provenance |
| 288 | |
| 289 | A workflow on g1t can't publish to npm with trusted publishing, or with |
| 290 | `--provenance`. |
| 291 | |
| 292 | - **Why.** Both trade the job's OIDC token with npm and Sigstore, which |
| 293 | accept tokens only from the CI services they list. g1t's |
| 294 | [OIDC tokens](/guides/actions/#oidc-tokens) work with any cloud that |
| 295 | lets you add an issuer, and npm does not. |
| 296 | - **Instead.** Publish with a granular access token in a secret |
| 297 | (`NODE_AUTH_TOKEN`); see [npm](/guides/actions/#npm). |
| 298 | - **Status.** Depends on npm. |
| 299 | |
| 300 | ## Deployments |
| 301 | |
| 302 | ### Static sites and Workers only |
| 303 | |
| 304 | Deployments run static sites and Workers projects. You can't deploy a |
| 305 | long-running server, a container, or an app that needs a process that stays |
| 306 | up. |
| 307 | |
| 308 | - **Why.** Apps run on Cloudflare Workers, which run only while they answer a |
| 309 | request. That is why an app nobody visits costs nothing. |
| 310 | - **Instead.** Deploy the server from a workflow to wherever it runs today, |
| 311 | with its credentials in [secrets](/guides/secrets-and-variables/). |
| 312 | - **Status.** A runtime for servers is planned. |
| 313 | |
| 314 | ### Some Workers bindings are not provisioned |
| 315 | |
| 316 | A Workers project deploys without D1, KV, R2, Durable Objects, Queues, |
| 317 | service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its |
| 318 | cron triggers are not scheduled. |
| 319 | |
| 320 | - **Why.** Each of these is a resource g1t has to create and bill per |
| 321 | project, and that is not built yet. |
| 322 | - **Instead.** Check that a binding exists before using it. The deployment |
| 323 | lists each binding it left out, and warns when its cron triggers will |
| 324 | not run. |
| 325 | - **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects). |
| 326 | |
| 327 | ### Build and size limits |
| 328 | |
| 329 | A build stops after 45 minutes. A static site can have up to 20,000 files |
| 330 | and 25 MiB per file, which are Cloudflare's limits. See |
| 331 | [Static sites](/guides/deployments/#static-sites). |
| 332 | |
| 333 | ## Data residency |
| 334 | |
| 335 | You can't choose where a workspace's data is stored. g1t's databases keep |
| 336 | their primary copy in the United States, with read copies in other regions |
| 337 | so pages load fast. Repositories are not pinned to a region. |
| 338 | |
| 339 | - **Why.** Cloudflare fixes the region of a repository store when it is |
| 340 | created, and g1t has one store so far. |
| 341 | - **Instead.** None today, if your data must stay in the EU. |
| 342 | - **Status.** EU residency, with an EU-only repository store and databases, |
| 343 | is planned. |
| 344 | |
| 345 | ## Billing |
| 346 | |
| 347 | ### Some costs are not fully defined yet |
| 348 | |
| 349 | Cloudflare starts billing for Artifacts, where repositories are stored, on |
| 350 | October 14, 2026, and has not yet said exactly which calls count as a |
| 351 | billable operation. |
| 352 | |
| 353 | - **What g1t does.** It counts every clone, fetch and push through its git |
| 354 | endpoints. Each day it checks what Cloudflare billed it for containers and |
| 355 | apps against what was used. When a cost moves, |
| 356 | g1t's price moves with it, and every change is listed with its reason on |
| 357 | [g1t.sh/pricing](https://g1t.sh/pricing). |
| 358 | - **What this means for you.** Prices can change while Cloudflare's beta |
| 359 | products settle. They follow cost. |
| 360 | See [How prices are set](/guides/usage-and-billing/#how-prices-are-set) |
| 361 | and [git operations](/guides/usage-and-billing/#git-operations). |
| 362 | - **Status.** Depends on Cloudflare. |
| 363 | |
| 364 | ### Payments are in test mode |
| 365 | |
| 366 | While payments are in test mode, no real card is charged, so a card check |
| 367 | proves nothing. g1t's hosted models are open only to a few invited |
| 368 | workspaces, g1t's own among them. Every other workspace, trial or not, |
| 369 | runs its agents on its own model provider; without one, assigning an agent |
| 370 | is refused with a message that says so. |
| 371 | |
| 372 | - **Instead.** Connect your own [model provider](/guides/models/). Your |
| 373 | agents then run on your keys, and the provider bills you directly. |
| 374 | - **Status.** Planned: hosted models for every workspace once payments go |
| 375 | live. |
| 376 | |
| 377 | ## Agents |
| 378 | |
| 379 | ### Confidence is a judgement, not a guarantee |
| 380 | |
| 381 | The confidence g1t gives an agent's change, high, medium or low, is |
| 382 | worked out from what g1t can observe: checks, reviews, revisions, the size |
| 383 | and reach of the change. It cannot tell whether the change is correct. |
| 384 | |
| 385 | - **Instead.** Keep **Ask a person before merging low-confidence changes** |
| 386 | on, and make your workflows required checks. A high rating on a |
| 387 | repository with weak tests means less. See |
| 388 | [How sure the agent is](/guides/working-with-g1t/#how-sure-the-agent-is). |
| 389 | - **Status.** The signals and their weights may change as we learn from |
| 390 | real changes. |
| 391 | |
| 392 | ### Agents' model calls go through g1t |
| 393 | |
| 394 | An agent's model requests always pass through g1t's model proxy, |
| 395 | `models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox |
| 396 | straight at a provider. |
| 397 | |
| 398 | - **Why.** So that no key is ever inside a sandbox, and so budgets, caps and |
| 399 | the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox). |
| 400 | - **Status.** Not planned. This is by design. |
| 401 | |
| 402 | ## Accounts, status and self-hosting |
| 403 | |
| 404 | ### Sign-up needs an invite |
| 405 | |
| 406 | g1t is invite-only for now. See [Invites](/guides/authentication/#invites). |
| 407 | **Status.** Opening sign-up is planned. |
| 408 | |
| 409 | ### Fine-grained tokens for workspaces you belong to |
| 410 | |
| 411 | A fine-grained personal access token can name a workspace as its resource |
| 412 | owner only when you are a member of it. For a repository where you are an |
| 413 | outside collaborator, use a classic token. A workspace's |
| 414 | [rules for tokens](/guides/authentication/#a-workspaces-rules-for-tokens) |
| 415 | cover personal access tokens only, not applications you signed in to with |
| 416 | OAuth. **Status.** Planned. |
| 417 | |
| 418 | ### No uptime commitment during the beta |
| 419 | |
| 420 | g1t does not promise a particular uptime or offer a service level agreement |
| 421 | unless you have a written agreement with us. Several of the Cloudflare |
| 422 | products g1t is built on are in beta and have none either. |
| 423 | [status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing, |
| 424 | and every incident. Sandboxes are not checked there yet. See |
| 425 | [Status and incidents](/guides/status/). **Status.** Not scheduled during |
| 426 | the beta. |
| 427 | |
| 428 | ### Self-hosting is early |
| 429 | |
| 430 | [Running g1t yourself](/guides/self-hosting/) gives you the core forge: |
| 431 | accounts, repositories over HTTP, issues and pull requests. g1t's agent, |
| 432 | Actions, deployments, git over SSH, the REST API and MCP are off, and it is |
| 433 | not ready for the open internet. **Status.** Planned, in phases. |
| 434 | |
| 435 | ### Not built yet |
| 436 | |
| 437 | |
| 438 | - **Releases and package registries.** Planned. |
| 439 | - **Wikis.** Not scheduled. Keep docs in the repository. |