Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| GitHub Actions on g1t, part two: running workflows | 1 | # The sandbox a g1t agent works in, and where GitHub Actions jobs run: |
| 2 | # git, the agent, the g1t runner, and the toolchains an agent or a | |
| 3 | # workflow needs to build and test a change. | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 4 | # Build context: the repository root. |
| 5 | ||
| 6 | # The same Debian release as the runtime image, so glibc matches. | |
| 7 | FROM rust:1-slim-bookworm AS build | |
| 8 | WORKDIR /src | |
| 9 | COPY Cargo.toml Cargo.lock ./ | |
| Build the sandbox image with the API crate present | 10 | # Cargo needs every workspace member present to resolve the workspace. |
| 11 | COPY apps/api apps/api | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 12 | COPY crates crates |
| 13 | COPY services services | |
| 14 | RUN cargo build --release --package g1t-runner | |
| 15 | ||
| Actions: workflow_run, workflow.completed, artifacts on the run page, Node 24 | 16 | FROM node:24-bookworm-slim |
| GitHub Actions on g1t, part two: running workflows | 17 | # Workflows expect GitHub's runner layout under /home/runner, and sudo |
| 18 | # without a password. | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 19 | RUN apt-get update \ |
| Show the model behind each choice; toolchains in the sandbox | 20 | && apt-get install -y --no-install-recommends \ |
| 21 | git ca-certificates curl build-essential pkg-config libssl-dev \ | |
| 22 | python3 python3-pip python3-venv golang-go ripgrep jq \ | |
| GitHub Actions on g1t, part two: running workflows | 23 | sudo unzip zip xz-utils wget file gnupg lsb-release \ |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 24 | && rm -rf /var/lib/apt/lists/* \ |
| 25 | && npm install --global @anthropic-ai/claude-code \ | |
| GitHub Actions on g1t, part two: running workflows | 26 | && mkdir /work && chown node:node /work \ |
| 27 | && mkdir -p /home/runner/work /home/runner/_temp /home/runner/_tool /home/runner/_actions \ | |
| 28 | && chown -R node:node /home/runner \ | |
| 29 | && echo 'node ALL=(ALL) NOPASSWD:ALL' > /etc/sudoers.d/node \ | |
| 30 | && chmod 0440 /etc/sudoers.d/node | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 31 | COPY --from=build /src/target/release/g1t-runner /usr/local/bin/g1t-runner |
| 32 | # Claude Code refuses to skip permission prompts as root. | |
| 33 | USER node | |
| 34 | ENV HOME=/home/node | |
| Show the model behind each choice; toolchains in the sandbox | 35 | # Rust, for the agent's own use, installed for the user it runs as. |
| 36 | RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \ | |
| 37 | | sh -s -- -y --profile minimal --default-toolchain stable | |
| 38 | ENV PATH=/home/node/.cargo/bin:$PATH | |
| Issues and pull requests replace intents and attempts | 39 | # Commits are the g1t agent's; the harness does not sign them as its own. |
| 40 | RUN mkdir -p /home/node/.claude \ | |
| 41 | && echo '{"includeCoAuthoredBy": false}' > /home/node/.claude/settings.json | |
| Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed) | 42 | ENTRYPOINT ["g1t-runner"] |