g1t/services/identity/wrangler.jsonc

69 lines3,109 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Initial g1t: services, event bus, intents and attempts1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-identity",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
Agents as a team: lifecycle, merge queue, billing and a new shell6 // Runs next to its database: a request makes several queries in turn,
7 // and each would otherwise cross the distance to it.
Fast pages, required checks on the branch, self-hosted runners, honest incidents8 "placement": { "mode": "off" },
API and MCP server, Rust identity service, registration, site redesign9 "main": "build/index.js",
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member10 // Staff waitlist summaries, and purging deleted workspaces once their
11 // restore window passes (src/lib.rs `scheduled`).
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas12 "triggers": { "crons": ["*/15 * * * *"] },
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow13 "build": { "command": "node ../../scripts/build-rust-worker.mjs" },
Initial g1t: services, event bus, intents and attempts14 // Reached only through service bindings.
15 "workers_dev": false,
16 "d1_databases": [
17 {
18 "binding": "DB",
19 "database_name": "g1t",
20 "database_id": "b7d49c93-2666-4006-a3c3-073a01838dc9",
21 "migrations_dir": "migrations"
22 }
23 ],
Email verification, password reset, and Git for AI scale positioning24 "send_email": [{ "name": "EMAIL", "remote": true }],
Workspace names and icons, and a component kit for every control25 // Uploaded avatars, keyed by the SHA-256 of their bytes. Only this
26 // service writes them; the site reads them to serve /avatars/<hash>.
27 "kv_namespaces": [{ "binding": "AVATARS", "id": "e627b571f07047e187c03e1fc2b3bbdd" }],
Agents and memory, checks and conflicts, profiles, slug renames, custom domains28 // Renaming a workspace publishes workspace.renamed, so every service
29 // moves what it keeps under the old slug.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look30 "services": [
31 { "binding": "EVENTS", "service": "g1t-events" },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member32 // Deleting a workspace counts what goes with it, and has billing
33 // settle it first; staff restores and purges are recorded in sudo's
34 // audit log, which billing keeps (src/deletion.rs).
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look35 { "binding": "REPOS", "service": "g1t-repos" },
36 { "binding": "PROJECTS", "service": "g1t-projects" },
37 { "binding": "BILLING", "service": "g1t-billing" }
38 ],
39 // Signing in with GitHub (src/github.rs), through g1t's GitHub App.
40 // Its client ID is public. Secrets: GITHUB_APP_CLIENT_SECRET, the app's
41 // client secret, and IDENTITY_KEY, 64 hex characters, which seals the
42 // GitHub user tokens kept for each linked account. Without the client ID
43 // and secret, nobody is offered GitHub sign-in.
44 //
45 // Invites (src/invites.rs): g1t.sh is invite-only, so every new account
46 // needs an invite code; "open" lets anyone register. Unset means
47 // invite. Each person may have INVITES_PER_USER invites out, each
48 // working INVITE_TTL_DAYS; owners of INVITE_STAFF_WORKSPACES (g1t's own)
49 // have no limit. IDENTITY_KEY also seals invite codes so their makers
50 // can copy them again.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas51 //
52 // The waitlist: whoever asks for access gets one confirmation, and
53 // WAITLIST_NOTIFY_EMAIL gets a summary of new requests at most every
54 // 15 minutes, linking to sudo's Waitlist. Empty sends none.
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member55 //
56 // PROTECTED_WORKSPACES: workspaces nobody can ever delete, by owner,
57 // token or staff, as comma-separated slugs or workspace ids. flagon-io
58 // is protected whatever this says (src/deletion.rs).
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look59 "vars": {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member60 "PROTECTED_WORKSPACES": "flagon-io",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look61 "GITHUB_APP_CLIENT_ID": "Iv23liZS94alfjIUn1eW",
62 "REGISTRATION_MODE": "invite",
63 "INVITES_PER_USER": "5",
64 "INVITE_TTL_DAYS": "30",
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas65 "INVITE_STAFF_WORKSPACES": "flagon-io",
66 "WAITLIST_NOTIFY_EMAIL": "hey@flagon.io"
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look67 },
Initial g1t: services, event bus, intents and attempts68 "observability": { "enabled": true }
69}