Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Initial g1t: services, event bus, intents and attempts | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-identity", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 6 | // Runs next to its database: a request makes several queries in turn, |
| 7 | // and each would otherwise cross the distance to it. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 8 | "placement": { "mode": "off" }, |
| API and MCP server, Rust identity service, registration, site redesign | 9 | "main": "build/index.js", |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 10 | // Staff waitlist summaries, and purging deleted workspaces once their |
| 11 | // restore window passes (src/lib.rs `scheduled`). | |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 12 | "triggers": { "crons": ["*/15 * * * *"] }, |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 13 | "build": { "command": "node ../../scripts/build-rust-worker.mjs" }, |
| Initial g1t: services, event bus, intents and attempts | 14 | // Reached only through service bindings. |
| 15 | "workers_dev": false, | |
| 16 | "d1_databases": [ | |
| 17 | { | |
| 18 | "binding": "DB", | |
| 19 | "database_name": "g1t", | |
| 20 | "database_id": "b7d49c93-2666-4006-a3c3-073a01838dc9", | |
| 21 | "migrations_dir": "migrations" | |
| 22 | } | |
| 23 | ], | |
| Email verification, password reset, and Git for AI scale positioning | 24 | "send_email": [{ "name": "EMAIL", "remote": true }], |
| Workspace names and icons, and a component kit for every control | 25 | // Uploaded avatars, keyed by the SHA-256 of their bytes. Only this |
| 26 | // service writes them; the site reads them to serve /avatars/<hash>. | |
| 27 | "kv_namespaces": [{ "binding": "AVATARS", "id": "e627b571f07047e187c03e1fc2b3bbdd" }], | |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 28 | // Renaming a workspace publishes workspace.renamed, so every service |
| 29 | // moves what it keeps under the old slug. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 30 | "services": [ |
| 31 | { "binding": "EVENTS", "service": "g1t-events" }, | |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 32 | // Deleting a workspace counts what goes with it, and has billing |
| 33 | // settle it first; staff restores and purges are recorded in sudo's | |
| 34 | // audit log, which billing keeps (src/deletion.rs). | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 35 | { "binding": "REPOS", "service": "g1t-repos" }, |
| 36 | { "binding": "PROJECTS", "service": "g1t-projects" }, | |
| 37 | { "binding": "BILLING", "service": "g1t-billing" } | |
| 38 | ], | |
| 39 | // Signing in with GitHub (src/github.rs), through g1t's GitHub App. | |
| 40 | // Its client ID is public. Secrets: GITHUB_APP_CLIENT_SECRET, the app's | |
| 41 | // client secret, and IDENTITY_KEY, 64 hex characters, which seals the | |
| 42 | // GitHub user tokens kept for each linked account. Without the client ID | |
| 43 | // and secret, nobody is offered GitHub sign-in. | |
| 44 | // | |
| 45 | // Invites (src/invites.rs): g1t.sh is invite-only, so every new account | |
| 46 | // needs an invite code; "open" lets anyone register. Unset means | |
| 47 | // invite. Each person may have INVITES_PER_USER invites out, each | |
| 48 | // working INVITE_TTL_DAYS; owners of INVITE_STAFF_WORKSPACES (g1t's own) | |
| 49 | // have no limit. IDENTITY_KEY also seals invite codes so their makers | |
| 50 | // can copy them again. | |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 51 | // |
| 52 | // The waitlist: whoever asks for access gets one confirmation, and | |
| 53 | // WAITLIST_NOTIFY_EMAIL gets a summary of new requests at most every | |
| 54 | // 15 minutes, linking to sudo's Waitlist. Empty sends none. | |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 55 | // |
| 56 | // PROTECTED_WORKSPACES: workspaces nobody can ever delete, by owner, | |
| 57 | // token or staff, as comma-separated slugs or workspace ids. flagon-io | |
| 58 | // is protected whatever this says (src/deletion.rs). | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 59 | "vars": { |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 60 | "PROTECTED_WORKSPACES": "flagon-io", |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 61 | "GITHUB_APP_CLIENT_ID": "Iv23liZS94alfjIUn1eW", |
| 62 | "REGISTRATION_MODE": "invite", | |
| 63 | "INVITES_PER_USER": "5", | |
| 64 | "INVITE_TTL_DAYS": "30", | |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 65 | "INVITE_STAFF_WORKSPACES": "flagon-io", |
| 66 | "WAITLIST_NOTIFY_EMAIL": "hey@flagon.io" | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 67 | }, |
| Initial g1t: services, event bus, intents and attempts | 68 | "observability": { "enabled": true } |
| 69 | } |