Skip to content
439 linesCodeBlameRaw
1---
2title: What g1t can't do yet
3description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned.
4---
5
6This page lists what g1t cannot do today. Each entry says what you can't
7do, why, what to do instead, and where it stands.
8
9Where it stands is one of:
10
11- **Planned**: we intend to build it. We don't give dates we can't keep.
12- **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs
13 something the platform does not offer yet.
14- **Not scheduled**: no work is planned on it now.
15
16Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/).
17
18If you hit a limit that is not here, tell us at
19[g1t.sh/support](https://g1t.sh/support), and we will add it.
20
21## Git
22
23### No git over SSH
24
25You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does
26not work.
27
28- **Why.** SSH needs inbound TCP connections on port 22. g1t runs on
29 Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta
30 for inbound TCP; we have applied and are waiting.
31- **Instead.** Use the HTTPS remote with an
32 [access token](/guides/git/#authentication). It does everything SSH would:
33 clone, fetch and push. SSH keys you add under **Settings → SSH keys** are
34 kept for when SSH arrives.
35- **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh).
36
37### Repositories up to 1 GB, files up to 32 MB, no LFS
38
39A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is
40not supported. A push that would cross either is declined before it is
41stored, and git prints why. See [Size limits](/guides/git/#size-limits).
42
43- **Why.** These are the limits of Cloudflare Artifacts, where every
44 repository is stored.
45- **Instead.** Keep large binaries out of the repository: in a release
46 bucket, a package registry or object storage, fetched at build time.
47- **Status.** Large file storage is planned. Raising the limits themselves
48 depends on Cloudflare.
49
50### Pushes up to 100 MB each
51
52A single push can carry up to 100 MB. A larger one is refused with HTTP
53`413` before g1t sees it.
54
55- **Why.** Cloudflare's network limits the size of one request body on the
56 plan g1t.sh is on.
57- **Instead.** Push history in steps, oldest first:
58 `git push origin <older-commit>:refs/heads/main`, then a newer one, then
59 `main`. Each push sends only what the last did not.
60- **Status.** Depends on Cloudflare.
61
62### Imports and mirrors up to 40 MB
63
64Importing or mirroring a repository copies it in one piece of at most
6540 MB, after compression.
66
67- **Why.** The copy is held in memory while it moves, and a Worker has
68 128 MB for everything it is doing at once.
69- **Instead.** Clone the repository yourself and push it to g1t, in steps if
70 it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across).
71- **Status.** Streaming the copy, so size stops mattering, is planned.
72
73### Partial clone works, but is not promised
74
75`git clone --filter=blob:none` returns a real partial clone today. We don't
76promise it will keep doing so.
77
78- **Why.** Cloudflare's documentation says filters are not supported, but
79 they work with git's protocol version 2. We have asked whether that is
80 intended.
81- **Instead.** Use it, and fall back to `--depth=1` for a shallow clone,
82 which is supported.
83- **Status.** Depends on Cloudflare.
84
85### No server-side hooks of your own
86
87You can't run a script of your own on g1t when a push arrives, before or
88after its refs move.
89
90- **Why.** The git store has no hook for this. g1t's own checks run in front
91 of it, in g1t's code: [protected branches](/guides/git/#protected-branches)
92 and [push protection](/guides/security/#push-protection).
93- **Instead.** Protect the default branch and make your workflows
94 [required checks](/guides/pull-requests/#required-status-checks). To react
95 after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`.
96- **Status.** Not scheduled for your own scripts. A hook in the store,
97 which would let g1t enforce more before refs move, depends on Cloudflare.
98
99### Very large pushes are scanned after they land, not before
100
101A very large push is too large for push protection to read before it is
102stored, so it is let through, and g1t scans every commit it added
103afterwards, in the background. A secret found that way is an open alert
104rather than a refused push, and the workspace's owners are emailed when one
105looks real. Most pushes are scanned before they land.
106
107- **Why.** Scanning reads the whole push inside a Worker, which has 128 MB
108 for everything it is doing at once. Past a certain size, scanning could fail
109 the push outright, and refusing such pushes would block importing real
110 repositories.
111- **Instead.** To have a large history checked before it lands, push it in
112 steps (see above), so each push is scanned first. Secrets already in
113 history are listed under
114 [Secrets in history](/guides/security/#secrets-in-history).
115- **Status.** Planned: scanning while the push streams, at any size.
116
117### Deleting history does not free storage
118
119Storage is counted from what is pushed, and the count only grows. Deleting
120a branch, or force-pushing over commits, does not lower it.
121
122- **Why.** The git store does not say whether or when it reclaims space
123 from objects nothing points to any more, or report how much a repository
124 holds. So g1t cannot see it either.
125- **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in
126 a private repository and counts against you, tell us at
127 [g1t.sh/support](https://g1t.sh/support).
128- **Status.** Depends on Cloudflare. See
129 [private repository storage](/guides/usage-and-billing/#private-repository-storage).
130
131## Pull requests and forks
132
133### Forks are only for pull requests
134
135You can't fork a repository into your own workspace. On g1t, a fork is a
136pull request's own working copy, made when the pull request is opened.
137
138- **Why.** We built forks to isolate agents' work, one per pull request.
139 See [Forks and branches](/concepts/forks/).
140- **Instead.** To contribute, open a pull request: it gets its own fork. To
141 start a copy of your own, clone the repository and push it to a new one
142 in your workspace; pushing creates it.
143- **Status.** Not scheduled.
144
145### Pull request forks are removed a day after they close
146
147A day after a pull request merges or closes, its fork's git data is
148removed. The pull request's changes stay readable: its head is kept in the
149repository as `refs/pull/<pull request id>/head`. Pushing to the fork, or
150reopening the pull request, makes the fork again from there.
151
152- **Why.** Cloudflare has not documented whether a fork shares stored
153 objects with its source or copies them, so forks are not kept longer
154 than they are useful.
155- **Instead.** Nothing you need to do. To keep working on a closed pull
156 request's change, fetch `refs/pull/<pull request id>/head` and push it
157 to a branch.
158- **Status.** Clear fork storage rules depend on Cloudflare.
159
160### Some dependency update options are not applied yet
161
162g1t reads and checks every option of a `dependabot.yml` file, but does not
163act on all of them yet:
164
165- Version update pull requests are opened for npm, Cargo, Go and pip only.
166 Entries for other ecosystems are checked and listed, and open nothing.
167
168- A multi-ecosystem group opens one pull request per ecosystem, not one
169 for the group.
170- Registries that sign in with OIDC are not used.
171
172- **Instead.** Keep a separate entry per ecosystem and directory, and
173 check the Security page, which lists what each entry reads but does not
174 act on. See [Dependency updates](/guides/dependency-updates/#options).
175- **Status.** Planned.
176
177### No conflict resolution in the browser
178
179You can't resolve a merge conflict on the pull request's page.
180
181- **Instead.** Ask g1t to resolve it, or fix it on the command line.
182 See [Conflicts](/guides/pull-requests/#conflicts).
183- **Status.** Planned.
184
185## Actions and runners
186
187### Docker shares the job's network
188
189A job's Docker Engine runs its containers on the job's own network, not on
190networks of their own. A service is reached at `localhost` and by its
191name, as on GitHub, but two containers cannot listen on the same port, and
192`docker network create` gives no separation between containers.
193
194- **Why.** Jobs run in Cloudflare Containers, which let a container run
195 Docker but not route a container network of its own out, or change its
196 packet filter. Sharing the job's network is also what keeps the job's
197 guardrails on every container.
198- **Instead.** Give containers that would clash different ports.
199- **Status.** Not scheduled.
200
201### No `type=gha` build cache
202
203Buildx's GitHub Actions cache backend (`cache-to: type=gha`) is skipped on
204g1t, and the build runs without a cache.
205
206- **Why.** It talks to GitHub's cache service, which g1t's cache does not
207 speak yet.
208- **Instead.** Use a registry cache in g1t's container registry
209 (`type=registry`), or `type=local` with `actions/cache`. See
210 [caching image builds](/guides/actions/#caching-image-builds).
211- **Status.** Planned.
212
213### No multi-platform image builds on g1t's machines
214
215Building an image for another platform, such as `linux/arm64`, needs QEMU's
216emulators, which g1t's machines do not have set up.
217
218- **Instead.** Build other platforms on a
219 [self-hosted runner](/guides/self-hosted-runners/) of that architecture,
220 or one with QEMU set up.
221- **Status.** Planned.
222
223### Linux only on g1t's machines
224
225A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own
226machines.
227
228- **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux,
229 macOS and Windows, on x64 and arm64.
230- **Status.** Not scheduled.
231
232### No `gh` command in jobs
233
234The runner does not include the `gh` command, and pointing it at g1t
235(`GH_HOST=g1t.sh`) does not work.
236
237- **Why.** Most of `gh`'s commands use a GraphQL API, and the rest expect
238 the REST API under `/api/v3` on the same host. g1t's API is REST, at
239 `api.g1t.sh`.
240- **Instead.** Call the API with `curl` and the job's token. See
241 [calling g1t's API from a job](/guides/actions/#calling-g1ts-api-from-a-job).
242- **Status.** Not scheduled.
243
244### One Ruby for `ruby/setup-ruby`
245
246On g1t's machines, `ruby/setup-ruby` finds Ruby 3.3, which the runner
247includes, and fails for any other version.
248
249- **Why.** Its prebuilt Rubies are for other Linux systems, so on Debian it
250 uses only the Rubies already in `RUNNER_TOOL_CACHE`.
251- **Instead.** Use 3.3, run the job in a `container:` with the Ruby you
252 need (such as `ruby:3.4`), or build it in a step with `ruby-build`. See
253 [languages and their setup actions](/guides/actions/#languages-and-their-setup-actions).
254- **Status.** Not scheduled.
255
256### Machine sizes, time and storage
257
258| Limit | Value |
259| --- | --- |
260| Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. |
261| One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. |
262| One cache entry | 2 GiB, compressed. A larger one is not saved. |
263| A repository's caches | 10 GiB together. Past it, the entries restored longest ago are removed. |
264| One artifact | 5 GiB, zipped. Kept 14 days unless the repository says otherwise, at most 90. |
265| A run's artifacts | 10 GiB together. |
266
267The machine sizes are Cloudflare Containers' instance sizes. For more, use a
268[self-hosted runner](/guides/self-hosted-runners/). See
269[Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache).
270
271### Workflow features not supported yet
272
273- Actions that upload or download artifacts with the toolkit's artifact
274 library themselves. The library refuses to run against any server but
275 github.com. `actions/upload-artifact`, `actions/download-artifact` and
276 `actions/upload-artifact/merge` work, as g1t runs them itself.
277- A cache entry between 100 and 128 MB saved by an action built on the
278 toolkit, such as `setup-node` with `cache: npm`. The toolkit sends an
279 entry under 128 MB in one request, and g1t takes at most 100 MB in one
280 request, as for [pushes](#pushes-up-to-100-mb-each). The step warns and
281 the job goes on; smaller and larger entries are saved.
282- `on: delete`: deleting a branch or tag starts no workflows. New branches
283 and tags start `create` and `push` workflows.
284
285See [Not yet](/guides/actions/#not-yet). **Status.** Planned.
286
287### No npm trusted publishing or provenance
288
289A workflow on g1t can't publish to npm with trusted publishing, or with
290`--provenance`.
291
292- **Why.** Both trade the job's OIDC token with npm and Sigstore, which
293 accept tokens only from the CI services they list. g1t's
294 [OIDC tokens](/guides/actions/#oidc-tokens) work with any cloud that
295 lets you add an issuer, and npm does not.
296- **Instead.** Publish with a granular access token in a secret
297 (`NODE_AUTH_TOKEN`); see [npm](/guides/actions/#npm).
298- **Status.** Depends on npm.
299
300## Deployments
301
302### Static sites and Workers only
303
304Deployments run static sites and Workers projects. You can't deploy a
305long-running server, a container, or an app that needs a process that stays
306up.
307
308- **Why.** Apps run on Cloudflare Workers, which run only while they answer a
309 request. That is why an app nobody visits costs nothing.
310- **Instead.** Deploy the server from a workflow to wherever it runs today,
311 with its credentials in [secrets](/guides/secrets-and-variables/).
312- **Status.** A runtime for servers is planned.
313
314### Some Workers bindings are not provisioned
315
316A Workers project deploys without D1, KV, R2, Durable Objects, Queues,
317service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its
318cron triggers are not scheduled.
319
320- **Why.** Each of these is a resource g1t has to create and bill per
321 project, and that is not built yet.
322- **Instead.** Check that a binding exists before using it. The deployment
323 lists each binding it left out, and warns when its cron triggers will
324 not run.
325- **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects).
326
327### Build and size limits
328
329A build stops after 45 minutes. A static site can have up to 20,000 files
330and 25 MiB per file, which are Cloudflare's limits. See
331[Static sites](/guides/deployments/#static-sites).
332
333## Data residency
334
335You can't choose where a workspace's data is stored. g1t's databases keep
336their primary copy in the United States, with read copies in other regions
337so pages load fast. Repositories are not pinned to a region.
338
339- **Why.** Cloudflare fixes the region of a repository store when it is
340 created, and g1t has one store so far.
341- **Instead.** None today, if your data must stay in the EU.
342- **Status.** EU residency, with an EU-only repository store and databases,
343 is planned.
344
345## Billing
346
347### Some costs are not fully defined yet
348
349Cloudflare starts billing for Artifacts, where repositories are stored, on
350October 14, 2026, and has not yet said exactly which calls count as a
351billable operation.
352
353- **What g1t does.** It counts every clone, fetch and push through its git
354 endpoints. Each day it checks what Cloudflare billed it for containers and
355 apps against what was used. When a cost moves,
356 g1t's price moves with it, and every change is listed with its reason on
357 [g1t.sh/pricing](https://g1t.sh/pricing).
358- **What this means for you.** Prices can change while Cloudflare's beta
359 products settle. They follow cost.
360 See [How prices are set](/guides/usage-and-billing/#how-prices-are-set)
361 and [git operations](/guides/usage-and-billing/#git-operations).
362- **Status.** Depends on Cloudflare.
363
364### Payments are in test mode
365
366While payments are in test mode, no real card is charged, so a card check
367proves nothing. g1t's hosted models are open only to a few invited
368workspaces, g1t's own among them. Every other workspace, trial or not,
369runs its agents on its own model provider; without one, assigning an agent
370is refused with a message that says so.
371
372- **Instead.** Connect your own [model provider](/guides/models/). Your
373 agents then run on your keys, and the provider bills you directly.
374- **Status.** Planned: hosted models for every workspace once payments go
375 live.
376
377## Agents
378
379### Confidence is a judgement, not a guarantee
380
381The confidence g1t gives an agent's change, high, medium or low, is
382worked out from what g1t can observe: checks, reviews, revisions, the size
383and reach of the change. It cannot tell whether the change is correct.
384
385- **Instead.** Keep **Ask a person before merging low-confidence changes**
386 on, and make your workflows required checks. A high rating on a
387 repository with weak tests means less. See
388 [How sure the agent is](/guides/working-with-g1t/#how-sure-the-agent-is).
389- **Status.** The signals and their weights may change as we learn from
390 real changes.
391
392### Agents' model calls go through g1t
393
394An agent's model requests always pass through g1t's model proxy,
395`models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox
396straight at a provider.
397
398- **Why.** So that no key is ever inside a sandbox, and so budgets, caps and
399 the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox).
400- **Status.** Not planned. This is by design.
401
402## Accounts, status and self-hosting
403
404### Sign-up needs an invite
405
406g1t is invite-only for now. See [Invites](/guides/authentication/#invites).
407**Status.** Opening sign-up is planned.
408
409### Fine-grained tokens for workspaces you belong to
410
411A fine-grained personal access token can name a workspace as its resource
412owner only when you are a member of it. For a repository where you are an
413outside collaborator, use a classic token. A workspace's
414[rules for tokens](/guides/authentication/#a-workspaces-rules-for-tokens)
415cover personal access tokens only, not applications you signed in to with
416OAuth. **Status.** Planned.
417
418### No uptime commitment during the beta
419
420g1t does not promise a particular uptime or offer a service level agreement
421unless you have a written agreement with us. Several of the Cloudflare
422products g1t is built on are in beta and have none either.
423[status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing,
424and every incident. Sandboxes are not checked there yet. See
425[Status and incidents](/guides/status/). **Status.** Not scheduled during
426the beta.
427
428### Self-hosting is early
429
430[Running g1t yourself](/guides/self-hosting/) gives you the core forge:
431accounts, repositories over HTTP, issues and pull requests. g1t's agent,
432Actions, deployments, git over SSH, the REST API and MCP are off, and it is
433not ready for the open internet. **Status.** Planned, in phases.
434
435### Not built yet
436
437
438- **Releases and package registries.** Planned.
439- **Wikis.** Not scheduled. Keep docs in the repository.