Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 1 | // Everything g1t deploys to Cloudflare, in one place. Read by |
| 2 | // scripts/deploy.mjs (plan, deploy), deploy/self-host/configs.mjs (what a | |
| 3 | // self-hosted installation runs) and the tests in scripts/deploy/. | |
| 4 | // docs/DEPLOYING.md explains each field and how to add a unit. | |
| 5 | // | |
| 6 | // What is written here is what the Wrangler configs cannot say. The rest is | |
| 7 | // read from each unit's wrangler.jsonc, never copied: its D1 databases and | |
| 8 | // migrations, the services it binds to, its KV, R2, queues and routes. The | |
| 9 | // shared crates and packages a unit is built from are read from Cargo's and | |
| 10 | // npm's workspace metadata. `worker` and `d1` are written here too, so the | |
| 11 | // file reads as an inventory, and a test checks they match the configs. | |
| 12 | { | |
| 13 | // Deployed in this order. A stage starts only when the one before it | |
| 14 | // succeeded. A unit binds only to units in its own stage or an earlier | |
| 15 | // one (a test checks it), so new code never calls a service that has | |
| 16 | // not shipped yet. Within a stage, units go out in parallel. | |
| 17 | // | |
| 18 | // migrations: every pending D1 migration, before any code. | |
| 19 | // core: the services, reached through service bindings. | |
| 20 | // edge: public endpoints other than the site: API, MCP, models, g1t.page, status. | |
| 21 | // front: the site, sudo and the docs. | |
| 22 | "stages": ["migrations", "core", "edge", "front"], | |
| 23 | ||
| 24 | // Names for the resources the configs refer to by id, for setup | |
| 25 | // commands and the docs. A test checks every KV id in a config is here. | |
| 26 | "resources": { | |
| 27 | "kv": { | |
| 28 | "16a4232cb746418db53782aa068be693": "g1t-actions-blobs", | |
| 29 | "e627b571f07047e187c03e1fc2b3bbdd": "g1t-avatars", | |
| 30 | "14bc5c233d4c46a5bbf23b5367cce5fd": "g1t-domains", | |
| 31 | "be765052d0124c2a935b3db4dff99f1f": "g1t-repos-git-cache" | |
| 32 | } | |
| 33 | }, | |
| 34 | ||
| 35 | // Each deployable unit, by short name (`--only events,web`). | |
| 36 | // | |
| 37 | // kind: rust-worker (worker-build), ts-worker (Wrangler bundles it), | |
| 38 | // react-router (vite build first), astro (astro build first). | |
| 39 | // secrets: names only; set with `npx wrangler secret put NAME` in its folder. | |
| 40 | // setup: one-time steps no config can say, for a first deploy. | |
| 41 | // self_host: what deploy/self-host does with it: "run" (in the one | |
| 42 | // workerd), "off" (bound to the off Worker), "separate" (a | |
| 43 | // process of its own), or "none". | |
| 44 | // inputs: files outside its folder it is built from that no workspace | |
| 45 | // metadata names (a test finds such imports). | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 46 | // image: a Containers image (docs/DEPLOYING.md, "The runner's images"): |
| 47 | // dockerfile the image a deploy ships: the base plus the binary | |
| 48 | // crate the crate that binary is built from (and what it uses) | |
| 49 | // base { context: the base's folder, lock: the file that | |
| 50 | // records the base that was pushed }; the base is | |
| 51 | // rebuilt only when its folder changes | |
| 52 | // repository where both are pushed in Cloudflare's registry | |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 53 | "units": { |
| 54 | "events": { | |
| 55 | "path": "services/events", | |
| 56 | "kind": "rust-worker", | |
| 57 | "worker": "g1t-events", | |
| 58 | "d1": { "database": "g1t-events", "migrations": "migrations" }, | |
| 59 | "stage": "core", | |
| 60 | "secrets": [], | |
| 61 | "self_host": "run" | |
| 62 | }, | |
| 63 | "identity": { | |
| 64 | "path": "services/identity", | |
| 65 | "kind": "rust-worker", | |
| 66 | "worker": "g1t-identity", | |
| 67 | "d1": { "database": "g1t", "migrations": "migrations" }, | |
| 68 | "stage": "core", | |
| 69 | "secrets": ["GITHUB_APP_CLIENT_SECRET", "IDENTITY_KEY"], | |
| 70 | "setup": ["Email Sending on g1t.sh (the EMAIL binding)"], | |
| 71 | "self_host": "run" | |
| 72 | }, | |
| 73 | "repos": { | |
| 74 | "path": "services/repos", | |
| 75 | "kind": "rust-worker", | |
| 76 | "worker": "g1t-repos", | |
| 77 | "d1": { "database": "g1t-repos", "migrations": "migrations" }, | |
| 78 | "stage": "core", | |
| 79 | "secrets": ["REPOS_KEY"], | |
| 80 | "setup": ["The Artifacts namespace `g1t` (the ARTIFACTS binding)"], | |
| 81 | "self_host": "run" | |
| 82 | }, | |
| 83 | "work": { | |
| 84 | "path": "services/work", | |
| 85 | "kind": "rust-worker", | |
| 86 | "worker": "g1t-work", | |
| 87 | "d1": { "database": "g1t-work", "migrations": "migrations" }, | |
| 88 | "stage": "core", | |
| 89 | "secrets": [], | |
| 90 | "self_host": "run" | |
| 91 | }, | |
| 92 | "search": { | |
| 93 | "path": "services/search", | |
| 94 | "kind": "rust-worker", | |
| 95 | "worker": "g1t-search", | |
| 96 | "d1": { "database": "g1t-search", "migrations": "migrations" }, | |
| 97 | "stage": "core", | |
| 98 | "secrets": [], | |
| 99 | "self_host": "run" | |
| 100 | }, | |
| 101 | "projects": { | |
| 102 | "path": "services/projects", | |
| 103 | "kind": "ts-worker", | |
| 104 | "worker": "g1t-projects", | |
| 105 | "d1": { "database": "g1t-projects", "migrations": "migrations" }, | |
| 106 | "stage": "core", | |
| 107 | "secrets": [], | |
| 108 | "self_host": "run" | |
| 109 | }, | |
| 110 | "billing": { | |
| 111 | "path": "services/billing", | |
| 112 | "kind": "rust-worker", | |
| 113 | "worker": "g1t-billing", | |
| 114 | "d1": { "database": "g1t-billing", "migrations": "migrations" }, | |
| 115 | "stage": "core", | |
| 116 | "secrets": ["STRIPE_SECRET_KEY", "CLOUDFLARE_USAGE_TOKEN"], | |
| 117 | "self_host": "run" | |
| 118 | }, | |
| 119 | "integrations": { | |
| 120 | "path": "services/integrations", | |
| 121 | "kind": "rust-worker", | |
| 122 | "worker": "g1t-integrations", | |
| 123 | "d1": { "database": "g1t-integrations", "migrations": "migrations" }, | |
| 124 | "stage": "core", | |
| 125 | "secrets": ["INTEGRATIONS_KEY", "GITHUB_APP_PRIVATE_KEY", "GITHUB_APP_WEBHOOK_SECRET"], | |
| 126 | "self_host": "run" | |
| 127 | }, | |
| 128 | "webhooks": { | |
| 129 | "path": "services/webhooks", | |
| 130 | "kind": "rust-worker", | |
| 131 | "worker": "g1t-webhooks", | |
| 132 | "d1": { "database": "g1t-webhooks", "migrations": "migrations" }, | |
| 133 | "stage": "core", | |
| 134 | "secrets": ["WEBHOOKS_KEY"], | |
| 135 | "self_host": "run" | |
| 136 | }, | |
| 137 | "actions": { | |
| 138 | "path": "services/actions", | |
| 139 | "kind": "rust-worker", | |
| 140 | "worker": "g1t-actions", | |
| 141 | "d1": { "database": "g1t-actions", "migrations": "migrations" }, | |
| 142 | "stage": "core", | |
| 143 | "secrets": ["ACTIONS_KEY"], | |
| 144 | "self_host": "run" | |
| 145 | }, | |
| 146 | "security": { | |
| 147 | "path": "services/security", | |
| 148 | "kind": "rust-worker", | |
| 149 | "worker": "g1t-security", | |
| 150 | "d1": { "database": "g1t-security", "migrations": "migrations" }, | |
| 151 | "stage": "core", | |
| 152 | "secrets": [], | |
| 153 | "self_host": "run" | |
| 154 | }, | |
| 155 | "deployments": { | |
| 156 | "path": "services/deployments", | |
| 157 | "kind": "ts-worker", | |
| 158 | "worker": "g1t-deployments", | |
| 159 | "d1": { "database": "g1t-deployments", "migrations": "migrations" }, | |
| 160 | "stage": "core", | |
| 161 | "secrets": ["CLOUDFLARE_API_TOKEN"], | |
| 162 | "setup": [ | |
| 163 | "Workers for Platforms, and the dispatch namespace: scripts/setup-deployments.sh", | |
| 164 | "Custom domains (Cloudflare for SaaS on g1t.page): scripts/setup-custom-domains.sh" | |
| 165 | ], | |
| 166 | "self_host": "run" | |
| 167 | }, | |
| 168 | "runner": { | |
| 169 | "path": "services/runner", | |
| 170 | "kind": "ts-worker", | |
| 171 | "worker": "g1t-runner", | |
| 172 | "stage": "core", | |
| 173 | "secrets": ["AI_GATEWAY_TOKEN"], | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 174 | "setup": [ |
| 175 | "Containers on the account; Docker on the machine that builds a new image", | |
| 176 | "The base image, once: node scripts/deploy.mjs build-base" | |
| 177 | ], | |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 178 | "image": { |
| 179 | "dockerfile": "services/runner/Dockerfile", | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 180 | // The binary the image adds to its base (scripts/build-runner.mjs). |
| 181 | "crate": "g1t-runner", | |
| 182 | "base": { "context": "services/runner/base", "lock": "services/runner/base.json" }, | |
| 183 | "repository": "g1t-runner" | |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 184 | }, |
| 185 | "self_host": "off" | |
| 186 | }, | |
| 187 | "context": { | |
| 188 | "path": "services/context", | |
| 189 | "kind": "ts-worker", | |
| 190 | "worker": "g1t-context", | |
| 191 | "d1": { "database": "g1t-context", "migrations": "migrations" }, | |
| 192 | "stage": "core", | |
| 193 | "secrets": [], | |
| 194 | "setup": [ | |
| 195 | "The Vectorize index: npx wrangler vectorize create g1t-context --dimensions=768 --metric=cosine, with metadata indexes on workspace, kind, project and private" | |
| 196 | ], | |
| 197 | "self_host": "off" | |
| 198 | }, | |
| 199 | "og": { | |
| 200 | "path": "services/og", | |
| 201 | "kind": "ts-worker", | |
| 202 | "worker": "g1t-og", | |
| 203 | "stage": "core", | |
| 204 | "secrets": [], | |
| 205 | "setup": ["Browser Rendering on the account (the BROWSER binding)"], | |
| 206 | // The roadmap cards read the site's roadmap. | |
| 207 | "inputs": ["apps/web/app/lib/roadmap.ts"], | |
| 208 | "self_host": "none" | |
| 209 | }, | |
| 210 | "api": { | |
| 211 | "path": "apps/api", | |
| 212 | "kind": "rust-worker", | |
| 213 | "worker": "g1t-api", | |
| 214 | "stage": "edge", | |
| 215 | "secrets": [], | |
| 216 | "self_host": "none" | |
| 217 | }, | |
| 218 | "models": { | |
| 219 | "path": "services/models", | |
| 220 | "kind": "ts-worker", | |
| 221 | "worker": "g1t-models", | |
| 222 | "stage": "edge", | |
| 223 | "secrets": ["AI_GATEWAY_TOKEN"], | |
| 224 | "setup": ["The AI Gateway `g1t`"], | |
| 225 | "self_host": "none" | |
| 226 | }, | |
| 227 | "pages": { | |
| 228 | "path": "services/pages", | |
| 229 | "kind": "ts-worker", | |
| 230 | "worker": "g1t-pages", | |
| 231 | "stage": "edge", | |
| 232 | "secrets": [], | |
| 233 | "setup": ["A proxied wildcard DNS record on g1t.page (`*`, AAAA 100::): scripts/setup-deployments.sh"], | |
| 234 | "self_host": "none" | |
| 235 | }, | |
| 236 | "status": { | |
| 237 | "path": "apps/status", | |
| 238 | "kind": "ts-worker", | |
| 239 | "worker": "g1t-status", | |
| 240 | "d1": { "database": "g1t-status", "migrations": "migrations" }, | |
| 241 | "stage": "edge", | |
| 242 | "secrets": ["STATUS_SECRET"], | |
| 243 | "setup": ["Email Sending on g1t.sh (the EMAIL binding)"], | |
| 244 | "self_host": "separate" | |
| 245 | }, | |
| 246 | "web": { | |
| 247 | "path": "apps/web", | |
| 248 | "kind": "react-router", | |
| 249 | "worker": "g1t", | |
| 250 | "stage": "front", | |
| 251 | "secrets": [], | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 252 | "setup": ["The R2 bucket g1t-downloads, for the self-hosted runner's releases: npx wrangler r2 bucket create g1t-downloads"], |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 253 | "self_host": "run" |
| 254 | }, | |
| 255 | "sudo": { | |
| 256 | "path": "apps/sudo", | |
| 257 | "kind": "react-router", | |
| 258 | "worker": "g1t-sudo", | |
| 259 | "stage": "front", | |
| 260 | "secrets": [], | |
| 261 | "setup": ["A Cloudflare Access application on sudo.g1t.sh; its AUD tag is ACCESS_AUD"], | |
| 262 | "self_host": "none" | |
| 263 | }, | |
| 264 | "docs": { | |
| 265 | "path": "apps/docs", | |
| 266 | "kind": "astro", | |
| 267 | "worker": "g1t-docs", | |
| 268 | "stage": "front", | |
| 269 | "secrets": [], | |
| 270 | "self_host": "none" | |
| 271 | } | |
| 272 | } | |
| 273 | } |