g1t/README.md

226 lines11,201 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1# g1t
2
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look3The open-source git platform where people and agents ship software
4together, from the first issue to production on the edge. It runs on
5Cloudflare Workers and Artifacts.
Agents as a team: lifecycle, merge queue, billing and a new shell6
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look7- **Collaborate.** Git over HTTPS, public and private repositories, issues,
8 pull requests, line comments and reviews, protected branches, workspaces,
9 profiles and site-wide search.
Cleanup: clippy is quiet outside billing, the README says g1t, and http-cache-semantics is 4.3.010- **Agents as teammates.** Assign an issue to g1t or mention `@g1t`, or
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look11 connect Claude Code, Codex, OpenCode or Cursor over MCP. Hand g1t an
12 outcome and a planner splits it into issues with dependencies that agents
13 take up as they unblock. Agents see what the others are changing, ask each
14 other and you, and work under guardrails, with their own credentials and
15 an audit log.
16- **Ship safely.** Checks run by g1t in clean sandboxes, GitHub Actions
17 workflows as they are, a merge queue that tests changes together, conflicts
18 found on every push, and why-blame from any line to the session that
19 wrote it.
20- **Run it.** A preview of every pull request and production on merge, on
21 `g1t.page`, with custom domains. Apps nobody visits cost nothing.
22- **Secure and healthy.** Push protection, history scanning, dependency
23 upkeep that an agent lands, and an audit log on every workspace.
24- **Open and fair.** MIT licensed and self-hostable (an early Docker Compose
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily25 version of the core forge, in `deploy/self-host`). The forge is free; compute is what it costs
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look26 plus 20%, never per seat.
Agents as a team: lifecycle, merge queue, billing and a new shell27
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look28g1t is made by Flagon, Inc. It is also an entry in Cloudflare's **Build the
29Next-Gen Git Platform** competition, which asks what a git platform looks
30like when many of the people using it are agents
31([the challenge](https://blog.cloudflare.com/next-git-platform-on-cloudflare/),
32[rules and dates](https://www.cloudflare.com/git-competition/)).
33[docs/PLAN.md](docs/PLAN.md) says how g1t answers the brief and what is
34built so far.
Agents as a team: lifecycle, merge queue, billing and a new shell35
36## Where things are
37
API and MCP server, Rust identity service, registration, site redesign38- Site: <https://g1t.sh>
Issues and pull requests replace intents and attempts39- Docs: <https://docs.g1t.sh>
API and MCP server, Rust identity service, registration, site redesign40- API: <https://api.g1t.sh> · MCP: <https://mcp.g1t.sh>
41- Plan and design: [docs/PLAN.md](docs/PLAN.md)
Agents as a team: lifecycle, merge queue, billing and a new shell42- Demo walk-through: [docs/DEMO.md](docs/DEMO.md)
API and MCP server, Rust identity service, registration, site redesign43
44## Status
45
46Working today:
47
OAuth 2.1 sign-in for MCP clients and other applications48- Accounts with email verification and password reset. Applications sign
49 in through the browser with OAuth 2.1, so connecting an MCP client needs
50 no pasted token; tools without a browser use a device code.
Agents as a team: lifecycle, merge queue, billing and a new shell51- Workspaces that own repositories, with members and roles. Every account
52 creates one before anything else, and usernames and workspaces share one
53 namespace.
54- Access tokens that belong to a workspace instead of a person, for CI and
55 integrations, so nothing needs a shared service account.
Issues and pull requests replace intents and attempts56- Public and private repositories, and git over HTTPS, including creating a
57 repository by pushing to it.
Fast pages, required checks on the branch, self-hosted runners, honest incidents58- Issues with labels and comments; a description can say what done means,
59 under a Definition of done.
Pull requests from branches60- Pull requests with a diff and a recorded agent session: in a
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise61 fork of their own, which is how agents work, or from a branch pushed to
Pull requests from branches62 the repository. Several can be made for one issue.
Fast pages, required checks on the branch, self-hosted runners, honest incidents63- Checks: the repository's workflows run on every pull request, a
64 person's or an agent's, and report a check each. The default branch
65 names the required checks a merge needs; an agent whose change fails a
66 check is sent back with the failing jobs' logs. A repository with no
67 workflows gets a starter CI workflow in one click.
Acceptance checks in sandboxes, line comments and review verdicts68- Review: comments on lines of a change, and approve or request-changes
69 verdicts, from people and from agents.
Agents as a team: lifecycle, merge queue, billing and a new shell70- Overlap: each pull request shows which others in progress change the
71 same files, while the work is still going on.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily72- Catch-up: when `main` has moved under a pull request, g1t merges it in,
Cleanup: clippy is quiet outside billing, the README says g1t, and http-cache-semantics is 4.3.073 and g1t resolves any conflict.
74- Reviews written by g1t, on request: line comments, a summary and
Agents as a team: lifecycle, merge queue, billing and a new shell75 a verdict.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily76- Importing a public repository from any git host by its address, and
77 public or private repositories through g1t's GitHub App, imported once,
78 mirrored, or pushed back to GitHub.
Issues and pull requests replace intents and attempts79- Merging: lands a pull request on `main`, closes its issue naming the pull
80 request that resolved it, and closes the others for that issue as
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily81 superseded. When `main` has moved, the pull request is brought up to date
82 first, or refused where the repository requires that, so no commit is
83 lost.
Issues and pull requests replace intents and attempts84- g1t agents: g1t's own agents working on an issue in sandboxes on
README says what is working today; the free allowance says what it covers85 Cloudflare Containers, seeing each pull request through checks, an
86 agent's review, revisions and catch-up.
87- Outcomes: a brief planned into issues with dependencies, which agents
88 take up as their dependencies land.
89- The merge queue: pull requests tested together with what is ahead of
90 them before they land, with failures sent back to the agent that wrote
91 them. Required approvals and checks per repository.
92- Checks in detail on every pull request, and conflicts worked out on
93 every push, before a merge is tried.
94- Agents as records: every run with its live steps, cost and session, Stop
95 and Message, and memory at two levels (project and workspace) that
96 agents write and read.
97- Projects with deployments on g1t.page: a preview for every pull request,
98 production on merge, dependencies between projects, custom domains.
99- GitHub Actions workflows from `.g1t/workflows`, secrets and variables,
100 webhooks and integrations (Sentry, Datadog, Jira, Linear).
101- Profiles, workspaces with display names, icons and renameable slugs.
102- Usage billing with no seats: what it costs g1t plus a markup, a public
103 price book, usage limits and itemised invoices.
Issues and pull requests replace intents and attempts104- A REST API, an OpenAPI document and an MCP server over the same operations.
API and MCP server, Rust identity service, registration, site redesign105- An event bus: every state change is published, logged and delivered to
106 subscribers.
107
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily108Not built yet: what the Soon pages in each project's menu describe. Git
109over SSH waits on inbound TCP on port 22, which on Cloudflare
Say why git over SSH is not on yet110means Workers inbound TCP, a beta g1t has applied for and is waiting on.
111Use HTTPS until then. See the build order in the plan.
API and MCP server, Rust identity service, registration, site redesign112
113## Try it
114
115```sh
OAuth 2.1 sign-in for MCP clients and other applications116# 1. Create an account and a workspace at https://g1t.sh/register.
API and MCP server, Rust identity service, registration, site redesign117
OAuth 2.1 sign-in for MCP clients and other applications118# 2. Connect Claude Code, then run /mcp in it to sign in through your browser.
119claude mcp add --transport http g1t https://mcp.g1t.sh
API and MCP server, Rust identity service, registration, site redesign120
Issues and pull requests replace intents and attempts121# 3. Ask it to open a pull request for an open issue.
API and MCP server, Rust identity service, registration, site redesign122```
123
Issues and pull requests replace intents and attempts124[Getting started](https://docs.g1t.sh/quickstart/) walks through this in
125full. An assistant can do it for you from <https://g1t.sh/llms.txt>.
API and MCP server, Rust identity service, registration, site redesign126
127## Layout
128
129| Path | What it is |
130| --- | --- |
131| `apps/web` | The site: server-rendered React on a Worker. Holds no data. |
Issues and pull requests replace intents and attempts132| `apps/docs` | The documentation site, with the API explorer. |
API and MCP server in Rust; a public index at the API root133| `apps/api` | REST API and MCP server. Rust. |
Issues and pull requests replace intents and attempts134| `services/identity` | Accounts, workspaces, sessions, keys and tokens. Rust. |
135| `services/repos` | Repository registry, contents, forks, diffs, landing, git over HTTPS. Rust. |
Acceptance checks in sandboxes, line comments and review verdicts136| `services/work` | Issues, pull requests, reviews, check runs and sessions. Rust. |
Events service in Rust, with RFC 3339 times and accurate push events137| `services/events` | The event bus and its log. Rust. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily138| `services/search` | Site-wide search and Explore. Rust. |
139| `services/billing` | Usage, the price book, limits, invoices and payments. Rust. |
140| `services/actions` | GitHub Actions workflows, runs, caches and self-hosted runners. Rust. |
141| `services/security` | Push protection findings, history scanning and dependency upkeep. Rust. |
142| `services/integrations` | Model providers, alerts, trackers and the GitHub App. Rust. |
143| `services/webhooks` | Webhook deliveries. Rust. |
144| `services/runner` | Starts sandboxes: for g1t agents, workflow jobs and the merge queue. TypeScript. |
145| `services/projects` | Projects and the dependencies between them. TypeScript. |
146| `services/deployments` | Builds, previews and production on `g1t.page`. TypeScript. |
147| `services/pages` | Serves every app deployed on `g1t.page`, and custom domains. TypeScript. |
148| `services/models` | The model proxy at `models.g1t.sh`. TypeScript. |
149| `services/context` | The context hub: catalog, search and scorecards. TypeScript. |
150| `services/og` | Social cards at `og.g1t.sh`: a PNG per page, showing only what anyone may see. TypeScript. |
151| `apps/status` | `status.g1t.sh`. TypeScript. |
152| `apps/sudo` | g1t's own staff console. |
Fast pages, required checks on the branch, self-hosted runners, honest incidents153| `crates/runner` | The program inside a sandbox: runs an agent, a workflow job or a merge queue build, and reports back. Rust. |
API and MCP server, Rust identity service, registration, site redesign154| `crates/contracts` | Types and service interfaces for the Rust services. |
155| `crates/kit` | Plumbing shared by Rust services on Workers. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily156| `crates/actions` | Reads workflows and evaluates their expressions. Rust. |
157| `crates/scan` | Secret and lockfile scanning, shared by services. Rust. |
158| `crates/secrets` | Secrets at rest and signatures. Rust. |
API and MCP server, Rust identity service, registration, site redesign159| `crates/sshd` | Git over SSH, bridged to Artifacts. Not deployed yet. |
160| `packages/contracts` | The same interfaces for TypeScript callers. |
Issues and pull requests replace intents and attempts161| `packages/theme` | Design tokens and the logo, shared by the site and the docs. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily162| `deploy` | `stack.jsonc`, every deployable part and its resources; `self-host`, the Docker Compose version. |
API and MCP server, Rust identity service, registration, site redesign163
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily164Each service is its own Worker, and each one that keeps data has its own
165database. They call each other through service bindings and react to each
166other through events. The core services (accounts, repositories, work,
167events, billing, Actions, security and the API) are written in Rust; the
168rest are the web apps and the Workers marked TypeScript above.
API and MCP server, Rust identity service, registration, site redesign169
170## Run your own
171
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise172### On your own machine
173
174The core forge runs in Docker, with no Cloudflare account:
175
176```sh
177docker compose -f deploy/self-host/docker-compose.yml up --build
178```
179
180Then open http://localhost:8787 and sign up. The confirmation mail is in
Merge branch 'worktree-agent-aaf03bdceac799c89'181Mailpit at http://localhost:8025. Repositories, push and clone, issues,
182pull requests and code browsing work, and the API and MCP server answer at
Merge branch 'worktree-agent-af58ac8933b0dd125'183http://localhost:8789; packages and container images are kept in the
184bundled S3-compatible store, RustFS. Agents, deployments and context search
185are off in this version.
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise186[docs/SELF_HOSTING.md](docs/SELF_HOSTING.md) says what works and what is next.
187
188### On Cloudflare
189
API and MCP server, Rust identity service, registration, site redesign190You need a Cloudflare account on the Workers Paid plan (Artifacts requires
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily191it), Node 22.22 or newer (`engines` in `package.json`; g1t is built on
192Node 24), Rust with the `wasm32-unknown-unknown` target, and
Issues and pull requests replace intents and attempts193Docker to build the sandbox image.
API and MCP server, Rust identity service, registration, site redesign194
195```sh
196npm install
197npx wrangler login
198```
199
200Then, once:
201
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily2021. Create the resources each part needs: D1 databases, queues, KV
203 namespaces, R2 buckets and the Artifacts namespace (`npx wrangler d1
204 create <name>`, `npx wrangler queues create <name>`, and so on), and set
205 each part's secrets. `deploy/stack.jsonc` lists them all.
API and MCP server, Rust identity service, registration, site redesign2062. Put your own `account_id`, database ids and hostnames in each
207 `wrangler.jsonc`.
Deploy scripts live in the repository2083. For [Deployments](https://docs.g1t.sh/guides/deployments/), which needs
209 the Workers for Platforms add-on and a zone for apps:
210 `scripts/setup-deployments.sh`.
API and MCP server, Rust identity service, registration, site redesign211
Deploy scripts live in the repository212Deploy everything, migrations first, in dependency order:
API and MCP server, Rust identity service, registration, site redesign213
214```sh
Deploy scripts live in the repository215scripts/deploy.sh
API and MCP server, Rust identity service, registration, site redesign216```
217
Deploy scripts live in the repository218Or only what changed, still in order: `scripts/deploy.sh billing web`.
219Both use your `wrangler login`, not a token in `.env`.
220
API and MCP server, Rust identity service, registration, site redesign221Create the first account by registering on your site, or with
222`node services/identity/scripts/create-user.mjs <username>`.
223
224## License
225
226[MIT](LICENSE)

This file's history is long; its oldest lines are credited to the oldest commit read.