flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/deploy/stack.jsonc

273 lines9,284 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow1// Everything g1t deploys to Cloudflare, in one place. Read by
2// scripts/deploy.mjs (plan, deploy), deploy/self-host/configs.mjs (what a
3// self-hosted installation runs) and the tests in scripts/deploy/.
4// docs/DEPLOYING.md explains each field and how to add a unit.
5//
6// What is written here is what the Wrangler configs cannot say. The rest is
7// read from each unit's wrangler.jsonc, never copied: its D1 databases and
8// migrations, the services it binds to, its KV, R2, queues and routes. The
9// shared crates and packages a unit is built from are read from Cargo's and
10// npm's workspace metadata. `worker` and `d1` are written here too, so the
11// file reads as an inventory, and a test checks they match the configs.
12{
13 // Deployed in this order. A stage starts only when the one before it
14 // succeeded. A unit binds only to units in its own stage or an earlier
15 // one (a test checks it), so new code never calls a service that has
16 // not shipped yet. Within a stage, units go out in parallel.
17 //
18 // migrations: every pending D1 migration, before any code.
19 // core: the services, reached through service bindings.
20 // edge: public endpoints other than the site: API, MCP, models, g1t.page, status.
21 // front: the site, sudo and the docs.
22 "stages": ["migrations", "core", "edge", "front"],
23
24 // Names for the resources the configs refer to by id, for setup
25 // commands and the docs. A test checks every KV id in a config is here.
26 "resources": {
27 "kv": {
28 "16a4232cb746418db53782aa068be693": "g1t-actions-blobs",
29 "e627b571f07047e187c03e1fc2b3bbdd": "g1t-avatars",
30 "14bc5c233d4c46a5bbf23b5367cce5fd": "g1t-domains",
31 "be765052d0124c2a935b3db4dff99f1f": "g1t-repos-git-cache"
32 }
33 },
34
35 // Each deployable unit, by short name (`--only events,web`).
36 //
37 // kind: rust-worker (worker-build), ts-worker (Wrangler bundles it),
38 // react-router (vite build first), astro (astro build first).
39 // secrets: names only; set with `npx wrangler secret put NAME` in its folder.
40 // setup: one-time steps no config can say, for a first deploy.
41 // self_host: what deploy/self-host does with it: "run" (in the one
42 // workerd), "off" (bound to the off Worker), "separate" (a
43 // process of its own), or "none".
44 // inputs: files outside its folder it is built from that no workspace
45 // metadata names (a test finds such imports).
Fast pages, required checks on the branch, self-hosted runners, honest incidents46 // image: a Containers image (docs/DEPLOYING.md, "The runner's images"):
47 // dockerfile the image a deploy ships: the base plus the binary
48 // crate the crate that binary is built from (and what it uses)
49 // base { context: the base's folder, lock: the file that
50 // records the base that was pushed }; the base is
51 // rebuilt only when its folder changes
52 // repository where both are pushed in Cloudflare's registry
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow53 "units": {
54 "events": {
55 "path": "services/events",
56 "kind": "rust-worker",
57 "worker": "g1t-events",
58 "d1": { "database": "g1t-events", "migrations": "migrations" },
59 "stage": "core",
60 "secrets": [],
61 "self_host": "run"
62 },
63 "identity": {
64 "path": "services/identity",
65 "kind": "rust-worker",
66 "worker": "g1t-identity",
67 "d1": { "database": "g1t", "migrations": "migrations" },
68 "stage": "core",
69 "secrets": ["GITHUB_APP_CLIENT_SECRET", "IDENTITY_KEY"],
70 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
71 "self_host": "run"
72 },
73 "repos": {
74 "path": "services/repos",
75 "kind": "rust-worker",
76 "worker": "g1t-repos",
77 "d1": { "database": "g1t-repos", "migrations": "migrations" },
78 "stage": "core",
79 "secrets": ["REPOS_KEY"],
80 "setup": ["The Artifacts namespace `g1t` (the ARTIFACTS binding)"],
81 "self_host": "run"
82 },
83 "work": {
84 "path": "services/work",
85 "kind": "rust-worker",
86 "worker": "g1t-work",
87 "d1": { "database": "g1t-work", "migrations": "migrations" },
88 "stage": "core",
89 "secrets": [],
90 "self_host": "run"
91 },
92 "search": {
93 "path": "services/search",
94 "kind": "rust-worker",
95 "worker": "g1t-search",
96 "d1": { "database": "g1t-search", "migrations": "migrations" },
97 "stage": "core",
98 "secrets": [],
99 "self_host": "run"
100 },
101 "projects": {
102 "path": "services/projects",
103 "kind": "ts-worker",
104 "worker": "g1t-projects",
105 "d1": { "database": "g1t-projects", "migrations": "migrations" },
106 "stage": "core",
107 "secrets": [],
108 "self_host": "run"
109 },
110 "billing": {
111 "path": "services/billing",
112 "kind": "rust-worker",
113 "worker": "g1t-billing",
114 "d1": { "database": "g1t-billing", "migrations": "migrations" },
115 "stage": "core",
116 "secrets": ["STRIPE_SECRET_KEY", "CLOUDFLARE_USAGE_TOKEN"],
117 "self_host": "run"
118 },
119 "integrations": {
120 "path": "services/integrations",
121 "kind": "rust-worker",
122 "worker": "g1t-integrations",
123 "d1": { "database": "g1t-integrations", "migrations": "migrations" },
124 "stage": "core",
125 "secrets": ["INTEGRATIONS_KEY", "GITHUB_APP_PRIVATE_KEY", "GITHUB_APP_WEBHOOK_SECRET"],
126 "self_host": "run"
127 },
128 "webhooks": {
129 "path": "services/webhooks",
130 "kind": "rust-worker",
131 "worker": "g1t-webhooks",
132 "d1": { "database": "g1t-webhooks", "migrations": "migrations" },
133 "stage": "core",
134 "secrets": ["WEBHOOKS_KEY"],
135 "self_host": "run"
136 },
137 "actions": {
138 "path": "services/actions",
139 "kind": "rust-worker",
140 "worker": "g1t-actions",
141 "d1": { "database": "g1t-actions", "migrations": "migrations" },
142 "stage": "core",
143 "secrets": ["ACTIONS_KEY"],
144 "self_host": "run"
145 },
146 "security": {
147 "path": "services/security",
148 "kind": "rust-worker",
149 "worker": "g1t-security",
150 "d1": { "database": "g1t-security", "migrations": "migrations" },
151 "stage": "core",
152 "secrets": [],
153 "self_host": "run"
154 },
155 "deployments": {
156 "path": "services/deployments",
157 "kind": "ts-worker",
158 "worker": "g1t-deployments",
159 "d1": { "database": "g1t-deployments", "migrations": "migrations" },
160 "stage": "core",
161 "secrets": ["CLOUDFLARE_API_TOKEN"],
162 "setup": [
163 "Workers for Platforms, and the dispatch namespace: scripts/setup-deployments.sh",
164 "Custom domains (Cloudflare for SaaS on g1t.page): scripts/setup-custom-domains.sh"
165 ],
166 "self_host": "run"
167 },
168 "runner": {
169 "path": "services/runner",
170 "kind": "ts-worker",
171 "worker": "g1t-runner",
172 "stage": "core",
173 "secrets": ["AI_GATEWAY_TOKEN"],
Fast pages, required checks on the branch, self-hosted runners, honest incidents174 "setup": [
175 "Containers on the account; Docker on the machine that builds a new image",
176 "The base image, once: node scripts/deploy.mjs build-base"
177 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow178 "image": {
179 "dockerfile": "services/runner/Dockerfile",
Fast pages, required checks on the branch, self-hosted runners, honest incidents180 // The binary the image adds to its base (scripts/build-runner.mjs).
181 "crate": "g1t-runner",
182 "base": { "context": "services/runner/base", "lock": "services/runner/base.json" },
183 "repository": "g1t-runner"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow184 },
185 "self_host": "off"
186 },
187 "context": {
188 "path": "services/context",
189 "kind": "ts-worker",
190 "worker": "g1t-context",
191 "d1": { "database": "g1t-context", "migrations": "migrations" },
192 "stage": "core",
193 "secrets": [],
194 "setup": [
195 "The Vectorize index: npx wrangler vectorize create g1t-context --dimensions=768 --metric=cosine, with metadata indexes on workspace, kind, project and private"
196 ],
197 "self_host": "off"
198 },
199 "og": {
200 "path": "services/og",
201 "kind": "ts-worker",
202 "worker": "g1t-og",
203 "stage": "core",
204 "secrets": [],
205 "setup": ["Browser Rendering on the account (the BROWSER binding)"],
206 // The roadmap cards read the site's roadmap.
207 "inputs": ["apps/web/app/lib/roadmap.ts"],
208 "self_host": "none"
209 },
210 "api": {
211 "path": "apps/api",
212 "kind": "rust-worker",
213 "worker": "g1t-api",
214 "stage": "edge",
215 "secrets": [],
216 "self_host": "none"
217 },
218 "models": {
219 "path": "services/models",
220 "kind": "ts-worker",
221 "worker": "g1t-models",
222 "stage": "edge",
223 "secrets": ["AI_GATEWAY_TOKEN"],
224 "setup": ["The AI Gateway `g1t`"],
225 "self_host": "none"
226 },
227 "pages": {
228 "path": "services/pages",
229 "kind": "ts-worker",
230 "worker": "g1t-pages",
231 "stage": "edge",
232 "secrets": [],
233 "setup": ["A proxied wildcard DNS record on g1t.page (`*`, AAAA 100::): scripts/setup-deployments.sh"],
234 "self_host": "none"
235 },
236 "status": {
237 "path": "apps/status",
238 "kind": "ts-worker",
239 "worker": "g1t-status",
240 "d1": { "database": "g1t-status", "migrations": "migrations" },
241 "stage": "edge",
242 "secrets": ["STATUS_SECRET"],
243 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
244 "self_host": "separate"
245 },
246 "web": {
247 "path": "apps/web",
248 "kind": "react-router",
249 "worker": "g1t",
250 "stage": "front",
251 "secrets": [],
Fast pages, required checks on the branch, self-hosted runners, honest incidents252 "setup": ["The R2 bucket g1t-downloads, for the self-hosted runner's releases: npx wrangler r2 bucket create g1t-downloads"],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow253 "self_host": "run"
254 },
255 "sudo": {
256 "path": "apps/sudo",
257 "kind": "react-router",
258 "worker": "g1t-sudo",
259 "stage": "front",
260 "secrets": [],
261 "setup": ["A Cloudflare Access application on sudo.g1t.sh; its AUD tag is ACCESS_AUD"],
262 "self_host": "none"
263 },
264 "docs": {
265 "path": "apps/docs",
266 "kind": "astro",
267 "worker": "g1t-docs",
268 "stage": "front",
269 "secrets": [],
270 "self_host": "none"
271 }
272 }
273}