g1t/services/billing/src/storage.rs
| 1 | //! Usage other services meter through the month, charged once it is over: |
| 2 | //! security scans, search embeddings, and two billing measures itself each |
| 3 | //! day: private repository storage and git operations. |
| 4 | //! |
| 5 | //! Each reports what it cost g1t so far this month (`note_pending`), so the |
| 6 | //! workspace's limit counts it as it happens. When the month is over, |
| 7 | //! billing charges it once: at cost plus the margin, on the account's |
| 8 | //! terms, after the plan's included usage and the trial credit (see |
| 9 | //! `credits`), dated the month's last second so it falls in that month's |
| 10 | //! statement and invoice. |
| 11 | //! |
| 12 | //! The forge is free for every workspace up to the same amounts, on the |
| 13 | //! plan or not; past them, a workspace on the plan pays at cost plus the |
| 14 | //! margin and is never refused or slowed, and a free workspace is never |
| 15 | //! charged but is held to them. |
| 16 | //! |
| 17 | //! **Git operations.** Cloudflare Artifacts charges g1t $0.15 per 1,000 |
| 18 | //! operations (clones, fetches, pushes) from 2026-10-14. The repos service |
| 19 | //! counts those through g1t's git endpoints. Every workspace has |
| 20 | //! `GIT_OPERATIONS_INCLUDED` (50,000) a month free; past it, the plan pays |
| 21 | //! at cost plus the margin, and a free workspace is slowed down instead |
| 22 | //! (the repos service's `GIT_OPERATIONS_FREE_CAP`, the same number). |
| 23 | //! |
| 24 | //! **Actions cache.** The actions service reports what each workspace's |
| 25 | //! `actions/cache` entries held each day (source `cache`), at what R2 |
| 26 | //! charges g1t to store them ($0.015 a GB-month). Only the plan is charged |
| 27 | //! for it, from the first byte; a free workspace is never charged, and its |
| 28 | //! repositories are held to the cache's quota like everyone's. |
| 29 | //! |
| 30 | //! **Storage.** The git store does not report a repository's size, so the |
| 31 | //! repos service counts the packs pushed through g1t's git endpoints (see |
| 32 | //! `g1t_contracts::repos::StorageArgs`): a lower bound. Each day billing |
| 33 | //! records what each workspace's private repositories hold and what is |
| 34 | //! free that day (`FREE_PRIVATE_STORAGE_BYTES`, 1 GB, for everyone). Like |
| 35 | //! Cloudflare's own storage billing, a month's GB-months are the days' |
| 36 | //! amounts past the free one, added up and divided by 30, and only the |
| 37 | //! plan is charged for them. A free workspace is never charged for |
| 38 | //! storage: pushes to its private repositories stop once they hold its |
| 39 | //! free amount. Public repositories are never charged. |
| 40 | |
| 41 | use g1t_contracts::billing::PlanKind; |
| 42 | use g1t_contracts::new_id; |
| 43 | use g1t_contracts::repos::{GitOperationsArgs, StorageArgs, WorkspaceGitOperations, WorkspaceStorage}; |
| 44 | use g1t_contracts::time::rfc3339; |
| 45 | use g1t_kit::now_ms; |
| 46 | use serde::Deserialize; |
| 47 | use worker::Result; |
| 48 | |
| 49 | use crate::credits::{self, Drawn, Eligible}; |
| 50 | use crate::{Billing, optional}; |
| 51 | |
| 52 | /// Sources billing charges itself when the month is over. |
| 53 | pub(crate) const CHARGED_HERE: [&str; 5] = ["security", "context", "storage", "git", "cache"]; |
| 54 | |
| 55 | /// Sources only the plan is charged for: a free workspace's are not kept. |
| 56 | pub(crate) const PLAN_ONLY: [&str; 1] = ["cache"]; |
| 57 | |
| 58 | /// What Artifacts charges g1t, when the price book cannot be read: $0.50 |
| 59 | /// a GB-month of storage, and $0.15 per 1,000 git operations. |
| 60 | pub(crate) const STORAGE_MICROS_PER_GB_MONTH: i64 = 500_000; |
| 61 | pub(crate) const GIT_MICROS_PER_THOUSAND: i64 = 150_000; |
| 62 | |
| 63 | /// When Cloudflare starts charging for Artifacts operations: none before |
| 64 | /// count. |
| 65 | pub(crate) const GIT_BILLING_STARTS: &str = "2026-10-14T00"; |
| 66 | |
| 67 | /// What git operations past the free amount cost g1t, at |
| 68 | /// `micros_per_thousand`: nothing up to it. |
| 69 | pub(crate) fn git_cost(operations: u64, included: u64, micros_per_thousand: f64) -> i64 { |
| 70 | let past = operations.saturating_sub(included); |
| 71 | (past as f64 * micros_per_thousand / 1000.0).ceil() as i64 |
| 72 | } |
| 73 | |
| 74 | /// The first hour of `month` to count git operations from. |
| 75 | pub(crate) fn git_since(month: &str) -> String { |
| 76 | let start = format!("{month}-01T00"); |
| 77 | if start.as_str() < GIT_BILLING_STARTS { GIT_BILLING_STARTS.to_owned() } else { start } |
| 78 | } |
| 79 | |
| 80 | /// A gigabyte, as Cloudflare bills storage. |
| 81 | pub(crate) const GB: f64 = 1_000_000_000.0; |
| 82 | |
| 83 | /// GB-months from a month's daily measures, each `(private, free)` bytes: |
| 84 | /// what was past the free amount each day, over 30 days. |
| 85 | pub(crate) fn storage_gb_months(days: &[(i64, i64)]) -> f64 { |
| 86 | days.iter().map(|(private, free)| (private - free).max(0) as f64).sum::<f64>() / GB / 30.0 |
| 87 | } |
| 88 | |
| 89 | /// What `gb_months` cost g1t at `micros_per_gb_month`, rounded up. |
| 90 | pub(crate) fn storage_cost(gb_months: f64, micros_per_gb_month: f64) -> i64 { |
| 91 | (gb_months * micros_per_gb_month).ceil() as i64 |
| 92 | } |
| 93 | |
| 94 | /// What a source is called on the statement. |
| 95 | pub(crate) fn title(source: &str) -> &'static str { |
| 96 | match source { |
| 97 | "security" => "Security scans", |
| 98 | "context" => "Search embeddings", |
| 99 | "storage" => "Private repository storage past the free amount", |
| 100 | "git" => "Git operations past the free amount", |
| 101 | "cache" => "Actions cache storage", |
| 102 | "domains" => "Custom domains", |
| 103 | _ => "Metered usage", |
| 104 | } |
| 105 | } |
| 106 | |
| 107 | /// A usage entry to put on the ledger. |
| 108 | pub(crate) struct UsageLine<'a> { |
| 109 | pub workspace: &'a str, |
| 110 | /// What the workspace is charged, after terms and what paid for it. |
| 111 | pub charged: i64, |
| 112 | pub description: &'a str, |
| 113 | pub repo: Option<&'a str>, |
| 114 | pub task: &'a str, |
| 115 | pub cost: i64, |
| 116 | pub reference: &'a str, |
| 117 | pub created_at: &'a str, |
| 118 | pub drawn: Drawn, |
| 119 | } |
| 120 | |
| 121 | impl Billing { |
| 122 | /// Puts a usage entry on the ledger and takes it off the balance, as |
| 123 | /// one write. |
| 124 | pub(crate) async fn post_usage(&self, line: UsageLine<'_>) -> Result<()> { |
| 125 | self.db |
| 126 | .batch(vec![ |
| 127 | self.db |
| 128 | .prepare( |
| 129 | "INSERT INTO ledger |
| 130 | (id, workspace, kind, amount_micros, description, repo, task, cost_micros, reference, |
| 131 | created_at, billed_to, credit_micros, trial_micros, oss_micros) |
| 132 | VALUES (?, ?, 'usage', ?, ?, ?, ?, ?, ?, ?, 'g1t', ?, ?, ?)", |
| 133 | ) |
| 134 | .bind(&[ |
| 135 | new_id("led", now_ms()).into(), |
| 136 | line.workspace.into(), |
| 137 | (-(line.charged as f64)).into(), |
| 138 | line.description.into(), |
| 139 | optional(line.repo), |
| 140 | line.task.into(), |
| 141 | (line.cost as f64).into(), |
| 142 | line.reference.into(), |
| 143 | line.created_at.into(), |
| 144 | (line.drawn.credit as f64).into(), |
| 145 | (line.drawn.trial as f64).into(), |
| 146 | (line.drawn.oss as f64).into(), |
| 147 | ])?, |
| 148 | self.db |
| 149 | .prepare( |
| 150 | "INSERT INTO accounts (workspace, balance_micros, created_at) VALUES (?1, ?2, ?3) |
| 151 | ON CONFLICT (workspace) DO UPDATE SET balance_micros = balance_micros + ?2", |
| 152 | ) |
| 153 | .bind(&[line.workspace.into(), (-(line.charged as f64)).into(), rfc3339(now_ms()).into()])?, |
| 154 | ]) |
| 155 | .await?; |
| 156 | Ok(()) |
| 157 | } |
| 158 | |
| 159 | /// Writes down what a source cost g1t so far in `month`, what it will |
| 160 | /// be charged, and how much of it there was (`detail`, for the Billing |
| 161 | /// page), replacing the last figure. |
| 162 | pub(crate) async fn set_pending( |
| 163 | &self, |
| 164 | workspace: &str, |
| 165 | source: &str, |
| 166 | month: &str, |
| 167 | cost_micros: i64, |
| 168 | detail: Option<&str>, |
| 169 | ) -> Result<()> { |
| 170 | let charge = credits::with_margin(cost_micros, self.margin_percent); |
| 171 | self.db |
| 172 | .prepare( |
| 173 | "INSERT INTO pending_usage (workspace, source, month, charge_micros, cost_micros, updated_at, detail) |
| 174 | VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7) |
| 175 | ON CONFLICT (workspace, source, month) DO UPDATE SET |
| 176 | charge_micros = ?4, cost_micros = ?5, updated_at = ?6, detail = COALESCE(?7, detail)", |
| 177 | ) |
| 178 | .bind(&[ |
| 179 | workspace.to_lowercase().into(), |
| 180 | source.into(), |
| 181 | month.into(), |
| 182 | (charge as f64).into(), |
| 183 | (cost_micros.max(0) as f64).into(), |
| 184 | rfc3339(now_ms()).into(), |
| 185 | optional(detail), |
| 186 | ])? |
| 187 | .run() |
| 188 | .await?; |
| 189 | Ok(()) |
| 190 | } |
| 191 | |
| 192 | /// Charges every month that is over for the usage billing charges |
| 193 | /// itself, once each. |
| 194 | pub(crate) async fn charge_pending(&self) -> Result<()> { |
| 195 | if self.stripe.is_none() { |
| 196 | return Ok(()); |
| 197 | } |
| 198 | let now = rfc3339(now_ms()); |
| 199 | let current = credits::month_of(&now); |
| 200 | #[derive(Deserialize)] |
| 201 | struct Row { |
| 202 | workspace: String, |
| 203 | source: String, |
| 204 | month: String, |
| 205 | cost_micros: Option<i64>, |
| 206 | } |
| 207 | let marks = CHARGED_HERE.iter().map(|s| format!("'{s}'")).collect::<Vec<_>>().join(", "); |
| 208 | let due = self |
| 209 | .db |
| 210 | .prepare(format!( |
| 211 | "SELECT workspace, source, month, cost_micros FROM pending_usage |
| 212 | WHERE month < ? AND charged_at IS NULL AND source IN ({marks}) ORDER BY month LIMIT 50" |
| 213 | )) |
| 214 | .bind(&[current.as_str().into()])? |
| 215 | .all() |
| 216 | .await? |
| 217 | .results::<Row>()?; |
| 218 | for row in due { |
| 219 | // Claimed first, so two crons never charge it twice. |
| 220 | let claimed = self |
| 221 | .db |
| 222 | .prepare( |
| 223 | "UPDATE pending_usage SET charged_at = ?1 |
| 224 | WHERE workspace = ?2 AND source = ?3 AND month = ?4 AND charged_at IS NULL RETURNING workspace", |
| 225 | ) |
| 226 | .bind(&[now.as_str().into(), row.workspace.as_str().into(), row.source.as_str().into(), row.month.as_str().into()])? |
| 227 | .first::<serde_json::Value>(None) |
| 228 | .await?; |
| 229 | let cost = row.cost_micros.unwrap_or(0); |
| 230 | if claimed.is_none() || cost <= 0 { |
| 231 | continue; |
| 232 | } |
| 233 | let base = credits::with_margin(cost, self.margin_percent); |
| 234 | let (charge, terms_note) = self.charged(&row.workspace, base).await?; |
| 235 | let drawn = self.draw(&row.workspace, charge, &row.month, &Eligible { trial: true, repo: None, cover_rest: false }).await?; |
| 236 | let detail = if row.source == "storage" { |
| 237 | let gb_months = self.gb_months(&row.workspace, &row.month).await?; |
| 238 | format!(": {gb_months:.2} GB-months") |
| 239 | } else { |
| 240 | String::new() |
| 241 | }; |
| 242 | let description = format!("{} in {}{detail}{terms_note}{}", title(&row.source), row.month, drawn.note()); |
| 243 | let reference = format!("{}/{}/{}", row.source, row.workspace, row.month); |
| 244 | let created_at = credits::month_end(&row.month); |
| 245 | self.post_usage(UsageLine { |
| 246 | workspace: &row.workspace, |
| 247 | charged: charge - drawn.total(), |
| 248 | description: &description, |
| 249 | repo: None, |
| 250 | task: &row.source, |
| 251 | cost, |
| 252 | reference: &reference, |
| 253 | created_at: &created_at, |
| 254 | drawn, |
| 255 | }) |
| 256 | .await?; |
| 257 | } |
| 258 | Ok(()) |
| 259 | } |
| 260 | |
| 261 | /// A workspace's private storage past the free amount in `month`. |
| 262 | async fn gb_months(&self, workspace: &str, month: &str) -> Result<f64> { |
| 263 | #[derive(Deserialize)] |
| 264 | struct Day { |
| 265 | private_bytes: i64, |
| 266 | free_bytes: i64, |
| 267 | } |
| 268 | let days = self |
| 269 | .db |
| 270 | .prepare("SELECT private_bytes, free_bytes FROM storage_days WHERE workspace = ? AND substr(day, 1, 7) = ?") |
| 271 | .bind(&[workspace.into(), month.into()])? |
| 272 | .all() |
| 273 | .await? |
| 274 | .results::<Day>()?; |
| 275 | Ok(storage_gb_months(&days.iter().map(|d| (d.private_bytes, d.free_bytes)).collect::<Vec<_>>())) |
| 276 | } |
| 277 | |
| 278 | /// Once a day: what each workspace's private repositories hold, and |
| 279 | /// what this month's storage past the free amount comes to so far. |
| 280 | pub(crate) async fn measure_storage(&self) -> Result<()> { |
| 281 | let Some(repos) = &self.repos else { return Ok(()) }; |
| 282 | let list: Vec<WorkspaceStorage> = g1t_kit::call(repos, "storage", &StorageArgs {}).await?; |
| 283 | let now = rfc3339(now_ms()); |
| 284 | let (day, month) = (&now[..10], credits::month_of(&now)); |
| 285 | let price = self.price("private_storage").await?.map_or(STORAGE_MICROS_PER_GB_MONTH as f64, |(cost, _)| cost); |
| 286 | for workspace in list { |
| 287 | let slug = workspace.namespace.to_lowercase(); |
| 288 | let plan = self.has_plan(&slug).await?; |
| 289 | // The same free amount for everyone: the plan pays past it. |
| 290 | let free = self.plans.free_storage_bytes; |
| 291 | self.db |
| 292 | .prepare( |
| 293 | "INSERT INTO storage_days (workspace, day, private_bytes, free_bytes) VALUES (?1, ?2, ?3, ?4) |
| 294 | ON CONFLICT (workspace, day) DO UPDATE SET private_bytes = ?3, free_bytes = ?4", |
| 295 | ) |
| 296 | .bind(&[slug.as_str().into(), day.into(), (workspace.private_bytes as f64).into(), (free as f64).into()])? |
| 297 | .run() |
| 298 | .await?; |
| 299 | // Only the plan pays for storage past its amount. A free |
| 300 | // workspace is never charged: the repos service stops its pushes |
| 301 | // to private repositories once it is full (see git_ops.rs there). |
| 302 | let gb_months = if plan { self.gb_months(&slug, &month).await? } else { 0.0 }; |
| 303 | if gb_months > 0.0 { |
| 304 | let detail = format!("{gb_months:.2} GB-months past the free {}", crate::features::bytes(free)); |
| 305 | self.set_pending(&slug, "storage", &month, storage_cost(gb_months, price), Some(&detail)).await?; |
| 306 | } |
| 307 | } |
| 308 | Ok(()) |
| 309 | } |
| 310 | |
| 311 | /// Git operations this month for each workspace, from the repos |
| 312 | /// service: what is past the free amount goes to the month's pending |
| 313 | /// usage for workspaces on the plan, which are never slowed or refused |
| 314 | /// for them. Free workspaces are never charged for them. |
| 315 | pub(crate) async fn measure_git(&self) -> Result<()> { |
| 316 | let Some(repos) = &self.repos else { return Ok(()) }; |
| 317 | let month = credits::month_of(&rfc3339(now_ms())); |
| 318 | let list: Vec<WorkspaceGitOperations> = |
| 319 | g1t_kit::call(repos, "git_operations", &GitOperationsArgs { since: Some(git_since(&month)), month: month.clone(), namespace: None }).await?; |
| 320 | let price = self.price("git_operations").await?.map_or(GIT_MICROS_PER_THOUSAND as f64, |(cost, _)| cost); |
| 321 | for workspace in list { |
| 322 | let slug = workspace.namespace.to_lowercase(); |
| 323 | if self.plan_kind(&slug).await? == PlanKind::Free { |
| 324 | continue; |
| 325 | } |
| 326 | let cost = git_cost(workspace.operations, self.plans.git_included, price); |
| 327 | if cost > 0 { |
| 328 | let detail = format!( |
| 329 | "{} operations, {} of them free", |
| 330 | crate::features::thousands(workspace.operations), |
| 331 | crate::features::thousands(self.plans.git_included) |
| 332 | ); |
| 333 | self.set_pending(&slug, "git", &month, cost, Some(&detail)).await?; |
| 334 | } |
| 335 | } |
| 336 | Ok(()) |
| 337 | } |
| 338 | |
| 339 | /// The workspace's git operations this month, as last measured. |
| 340 | pub(crate) async fn git_operations_this_month(&self, workspace: &str) -> Result<u64> { |
| 341 | let Some(repos) = &self.repos else { return Ok(0) }; |
| 342 | let month = credits::month_of(&rfc3339(now_ms())); |
| 343 | let list: Result<Vec<WorkspaceGitOperations>> = |
| 344 | g1t_kit::call(repos, "git_operations", &GitOperationsArgs { since: Some(format!("{month}-01T00")), month, namespace: Some(workspace.to_lowercase()) }).await; |
| 345 | Ok(list |
| 346 | .ok() |
| 347 | .and_then(|list| list.into_iter().find(|w| w.namespace.eq_ignore_ascii_case(workspace))) |
| 348 | .map_or(0, |w| w.operations)) |
| 349 | } |
| 350 | } |
| 351 | |
| 352 | #[cfg(test)] |
| 353 | mod tests { |
| 354 | use super::*; |
| 355 | |
| 356 | #[test] |
| 357 | fn storage_past_the_free_amount_is_counted_by_the_day() { |
| 358 | // 3 GB private with 1 GB free, every day of a 30-day month: 2 GB-months. |
| 359 | let month = vec![(3_000_000_000, 1_000_000_000); 30]; |
| 360 | assert!((storage_gb_months(&month) - 2.0).abs() < 1e-9); |
| 361 | // Under the free amount: nothing. |
| 362 | assert_eq!(storage_gb_months(&[(500_000_000, 1_000_000_000); 30]), 0.0); |
| 363 | // The plan has the same 1 GB free: 11 GB on it all month is 10 |
| 364 | // GB-months, $5.00 to g1t, $6.00 charged, from its included usage. |
| 365 | let days = vec![(11_000_000_000, 1_000_000_000); 30]; |
| 366 | assert!((storage_gb_months(&days) - 10.0).abs() < 1e-9); |
| 367 | assert_eq!(credits::with_margin(storage_cost(storage_gb_months(&days), STORAGE_MICROS_PER_GB_MONTH as f64), 20), 6_000_000); |
| 368 | // Ten days of 4 GB past it: a third of 4 GB-months. |
| 369 | let days = vec![(5_000_000_000, 1_000_000_000); 10]; |
| 370 | assert!((storage_gb_months(&days) - 4.0 / 3.0).abs() < 1e-9); |
| 371 | } |
| 372 | |
| 373 | #[test] |
| 374 | fn storage_is_priced_at_cloudflares_rate_plus_the_margin() { |
| 375 | // $0.50 a GB-month to g1t: 2 GB-months cost $1.00, charged $1.20. |
| 376 | let cost = storage_cost(2.0, 500_000.0); |
| 377 | assert_eq!(cost, 1_000_000); |
| 378 | assert_eq!(credits::with_margin(cost, 20), 1_200_000); |
| 379 | // A fraction of a millionth rounds up. |
| 380 | assert_eq!(storage_cost(0.000_000_001, 500_000.0), 1); |
| 381 | } |
| 382 | |
| 383 | #[test] |
| 384 | fn embeddings_and_scans_are_charged_at_cost_plus_the_margin() { |
| 385 | // 10 million tokens at $0.067 a million: $0.67, charged $0.804. |
| 386 | assert_eq!(credits::with_margin(670_000, 20), 804_000); |
| 387 | assert_eq!(title("context"), "Search embeddings"); |
| 388 | assert_eq!(title("security"), "Security scans"); |
| 389 | assert!(CHARGED_HERE.contains(&"storage") && !CHARGED_HERE.contains(&"deployments")); |
| 390 | assert!(CHARGED_HERE.contains(&"git")); |
| 391 | } |
| 392 | |
| 393 | #[test] |
| 394 | fn git_operations_are_charged_past_the_free_amount_at_cloudflares_price() { |
| 395 | // $0.15 per 1,000 to g1t; 50,000 a month free for everyone. |
| 396 | let per_thousand = GIT_MICROS_PER_THOUSAND as f64; |
| 397 | let free = crate::credits::Config::default().git_included; |
| 398 | assert_eq!(free, 50_000); |
| 399 | assert_eq!(git_cost(49_000, free, per_thousand), 0); |
| 400 | assert_eq!(git_cost(50_000, free, per_thousand), 0); |
| 401 | // A workspace on the plan pushes on past it, and pays: 70,000 |
| 402 | // operations are 20,000 past it, $3.00 to g1t, $3.60 charged. |
| 403 | assert_eq!(git_cost(70_000, free, per_thousand), 3_000_000); |
| 404 | assert_eq!(credits::with_margin(git_cost(70_000, free, per_thousand), 20), 3_600_000); |
| 405 | // A million in a month: no cap, $142.50 to g1t. |
| 406 | assert_eq!(git_cost(1_000_000, free, per_thousand), 142_500_000); |
| 407 | // One past it: a fraction of a cent, rounded up to a millionth. |
| 408 | assert_eq!(git_cost(50_001, free, per_thousand), 150); |
| 409 | assert_eq!(title("git"), "Git operations past the free amount"); |
| 410 | } |
| 411 | |
| 412 | #[test] |
| 413 | fn git_operations_count_from_when_cloudflare_starts_charging() { |
| 414 | assert_eq!(git_since("2026-10"), "2026-10-14T00"); |
| 415 | assert_eq!(git_since("2026-11"), "2026-11-01T00"); |
| 416 | assert_eq!(git_since("2026-09"), "2026-10-14T00"); |
| 417 | } |
| 418 | } |