g1t/services/packages/wrangler.jsonc

76 lines3,523 bytesCodeBlame
1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-packages",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 // Runs next to its database: a request makes several queries in turn,
7 // and each would otherwise cross the distance to it.
8 "placement": { "mode": "off" },
9 "main": "build/index.js",
10 "build": { "command": "node ../../scripts/build-rust-worker.mjs" },
11 "workers_dev": false,
12 // Made by `npx wrangler d1 create g1t-packages`; put its id here.
13 "d1_databases": [
14 {
15 "binding": "DB",
16 "database_name": "g1t-packages",
17 "database_id": "e541c872-a2a8-47aa-bfe8-419d0d50fe3c",
18 "migrations_dir": "migrations"
19 }
20 ],
21 // Every package's files, by digest (src/store). Made by
22 // `npx wrangler r2 bucket create g1t-packages`.
23 "r2_buckets": [{ "binding": "BLOBS", "bucket_name": "g1t-packages" }],
24 // Pulls and token requests (src/limits.rs): anonymous ones per client
25 // address, signed-in ones per person, workspace or agent. Self-hosted
26 // installations have neither binding, and no limit.
27 "ratelimits": [
28 { "name": "ANONYMOUS_LIMIT", "namespace_id": "4101", "simple": { "limit": 300, "period": 60 } },
29 { "name": "SIGNED_LIMIT", "namespace_id": "4102", "simple": { "limit": 5000, "period": 60 } }
30 ],
31 "services": [
32 // Who a token or password belongs to.
33 { "binding": "IDENTITY", "service": "g1t-identity" },
34 // The repository an image is linked to, by name.
35 { "binding": "REPOS", "service": "g1t-repos" },
36 // package.* events and the audit log.
37 { "binding": "EVENTS", "service": "g1t-events" },
38 // Whether a workspace is on the plan, and its free package storage
39 // (src/quota.rs); asked at most every five minutes per workspace.
40 { "binding": "BILLING", "service": "g1t-billing" }
41 ],
42 // BLOB_STORE: r2 (the BLOBS binding) or s3 (S3_ENDPOINT, S3_BUCKET,
43 // S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, S3_REGION, and optionally
44 // S3_PUBLIC_ENDPOINT for signed downloads), as self-hosting uses.
45 // MAX_REQUEST_BYTES: the most a request body may hold: the zone plan's
46 // limit (Free: 100 MB). A layer pushed in one request over it is
47 // refused with a message naming it (docs: guides/containers).
48 // REGISTRY_HOST: what package addresses start with.
49 // PROTECTED_WORKSPACES: as identity's; their packages are never hidden
50 // by a workspace.deleting (flagon-io always, whatever it says).
51 // STORAGE_LIMITS: "on" refuses a free workspace's pushes past its free
52 // package storage (billing's entitlements); self-hosting turns it off.
53 // Secrets: PACKAGES_TOKEN_SECRET (at least 32 characters) signs the
54 // registry's tokens. R2_ACCESS_KEY_ID and R2_SECRET_ACCESS_KEY
55 // (optional), with R2_ACCOUNT_ID and R2_BUCKET below, let large
56 // downloads go straight to R2 with a signed URL; without them they
57 // stream through the Worker.
58 "vars": {
59 "BLOB_STORE": "r2",
60 "R2_ACCOUNT_ID": "1e6f2cffa3f445920836e8ebe446bb58",
61 "R2_BUCKET": "g1t-packages",
62 "MAX_REQUEST_BYTES": "100000000",
63 "REGISTRY_HOST": "g1t.sh",
64 "STORAGE_LIMITS": "on",
65 "PROTECTED_WORKSPACES": "flagon-io"
66 },
67 // Every hour, expired uploads are let go, and blobs no version has used
68 // for a day are deleted.
69 "triggers": { "crons": ["37 * * * *"] },
70 // Workspaces renamed or deleted, repositories that change visibility,
71 // are renamed, move or are purged.
72 "queues": {
73 "consumers": [{ "queue": "g1t-events-packages", "max_batch_size": 20, "max_batch_timeout": 1 }]
74 },
75 "observability": { "enabled": true }
76}