Skip to content

g1t/services/runner/src/model-env.ts

510 lines21,406 bytesCodeBlame
1/**
2 * The kinds of work a g1t agent does, as model routes and billing name
3 * them. A workspace routes each to a provider (Integrations → Models).
4 */
5export type AgentTask = "implement" | "review" | "update" | "plan";
6
7/**
8 * What the router routes: every kind of agent job. Revising a change and
9 * answering a question are routed on their own, and go to the workspace's
10 * `implement` route (`taskOf`).
11 */
12export type JobKind = AgentTask | "revise" | "answer";
13
14/** The route and the bill a job goes on. */
15export function taskOf(kind: JobKind): AgentTask {
16 return kind === "revise" || kind === "answer" ? "implement" : kind;
17}
18
19/**
20 * How capable, and how costly, a model is: `small` (fast and cheap, for
21 * work a smaller model does as well), `large` (the standard, most
22 * changes) and `frontier` (the most capable, for hard work only).
23 */
24export type Tier = "small" | "large" | "frontier";
25
26/** Cheapest first. */
27export const TIERS: Tier[] = ["small", "large", "frontier"];
28
29/** Per million tokens, in US dollars: what the provider lists. */
30export type TokenPrice = { input: number; output: number; cacheRead: number; cacheWrite: number };
31
32/** Where one kind of work goes: what people see, and what is sent. */
33export type ModelRoute = {
34 /** The model's public name, e.g. `Claude Sonnet 5.5`. */
35 modelName: string;
36 /** The identifier sent to the provider. */
37 model: string;
38 /**
39 * The provider's list price, for estimates (the savings report, routing
40 * by cost). Never what anyone is charged: runs are charged what AI
41 * Gateway priced them at.
42 */
43 price?: TokenPrice;
44};
45
46/**
47 * How hard the model thinks before it answers, on models that take it
48 * (Claude Haiku 5.5 and later): more effort, more thinking tokens.
49 */
50export type Effort = "low" | "medium" | "high" | "xhigh" | "max";
51
52export const EFFORTS: Effort[] = ["low", "medium", "high", "xhigh", "max"];
53
54/** How a job's rule decides: a tier, or `change` to size the change it reads. */
55export type TaskRule = Tier | "change";
56
57/**
58 * Learning from a repository's own runs: of its last `window` runs of the
59 * same kind, a cheaper tier that finished at least `stepDownAt` of at
60 * least `minRuns` takes the work; a tier that finished less than
61 * `stepUpAt` of at least `minRuns` hands it up.
62 */
63export type Learning = { window: number; minRuns: number; stepDownAt: number; stepUpAt: number };
64
65/**
66 * g1t's routing policy. Nobody assigning an agent has to pick a model:
67 * "Auto" decides here, by the work, and the operator changes the policy in
68 * one place (`AGENT_ROUTING` in wrangler.jsonc), never in code.
69 */
70export type AgentRouting = {
71 /** The model behind each tier: the catalogue. */
72 tiers: Record<Tier, ModelRoute>;
73 /** The tier each kind of job starts from, or `change` to size it. */
74 tasks: Record<JobKind, TaskRule>;
75 /**
76 * The effort each kind of job runs at, whatever tier it lands on; left
77 * out, the harness's own default. Only on g1t's tiers: a route that
78 * names its own model is sent as it is.
79 */
80 effort: Partial<Record<JobKind, Effort>>;
81 /** The largest change `change` sends to the small tier. */
82 smallChange: { files: number; lines: number };
83 /** A change larger than this (either) is reviewed on the frontier tier. */
84 largeChange: { files: number; lines: number };
85 /** Issue labels that keep work off the small tier. */
86 largeLabels: string[];
87 /** Issue labels that send work to the frontier tier. */
88 frontierLabels: string[];
89 /** Issue labels that let changes and answers start on the small tier. */
90 smallLabels: string[];
91 /** Failed attempts at the same work, in a row, before the frontier tier. */
92 frontierAfter: number;
93 learning: Learning;
94};
95
96/** What a change is, as far as routing cares. */
97export type ChangeSize = {
98 files: number;
99 /** Lines added and removed. */
100 lines: number;
101 /**
102 * What it touches that runs, configures or guards things: CI, secrets,
103 * infrastructure, ownership (work's confidence.rs `sensitive`).
104 */
105 sensitive: string[];
106};
107
108/** One past run of the same kind of job in the repository, for learning. */
109export type PastOutcome = {
110 /** The tier it ran on, when it ran on one of g1t's. */
111 tier: Tier | null;
112 /** It finished, and did not leave a change g1t had low confidence in. */
113 ok: boolean;
114};
115
116/** What g1t knows about one piece of work when it routes it. */
117export type RouteSignals = {
118 /** The change the work reads; null or absent when g1t does not know it. */
119 change?: ChangeSize | null;
120 /** Labels on the issue the work is for. */
121 labels?: string[];
122 /** The last attempt at the same work failed. Same as `failures: 1`. */
123 retry?: boolean;
124 /** Failed attempts at the same work, in a row, most recent last. */
125 failures?: number;
126 /** The last attempt finished, but left a change g1t has low confidence in. */
127 lowConfidence?: boolean;
128 /** Recent runs of the same kind in this repository, newest first. */
129 history?: PastOutcome[];
130 /** A tier the workspace chose for this work instead of Auto. */
131 chosen?: Tier | null;
132};
133
134/** The router's answer: the tier, and why, in one line people can read. */
135export type Routed = {
136 tier: Tier;
137 /** E.g. `Used a fast model (Claude Haiku 4.5): small change, 3 files and 80 lines.` */
138 reason: string;
139};
140
141/** The routing g1t ships with, for whatever the configuration leaves out. */
142export const DEFAULT_ROUTING: AgentRouting = {
143 tiers: {
144 // Prompts up to 100,000 tokens; past that, five times as much.
145 small: {
146 modelName: "Claude Haiku 5.5",
147 model: "claude-haiku-5-5",
148 price: { input: 0.1, output: 0.5, cacheRead: 0.01, cacheWrite: 0.125 },
149 },
150 large: {
151 modelName: "Claude Sonnet 5.5",
152 model: "claude-sonnet-5-5",
153 price: { input: 2, output: 10, cacheRead: 0.1, cacheWrite: 2.5 },
154 },
155 frontier: {
156 modelName: "Claude Opus 5.5",
157 model: "claude-opus-5-5",
158 price: { input: 4, output: 20, cacheRead: 0.2, cacheWrite: 5 },
159 },
160 },
161 // Plans start on the fast model thinking hard, and go up a tier when
162 // one fails or leaves low confidence, as any work does.
163 tasks: { implement: "large", revise: "large", answer: "small", review: "change", update: "small", plan: "small" },
164 effort: { plan: "high", answer: "medium", update: "low" },
165 smallChange: { files: 10, lines: 200 },
166 largeChange: { files: 60, lines: 3000 },
167 largeLabels: ["security"],
168 frontierLabels: ["architecture"],
169 smallLabels: ["documentation", "docs", "typo"],
170 frontierAfter: 2,
171 learning: { window: 20, minRuns: 5, stepDownAt: 0.9, stepUpAt: 0.5 },
172};
173
174function isTier(value: unknown): value is Tier {
175 return value === "small" || value === "large" || value === "frontier";
176}
177
178/**
179 * The routing in `AGENT_ROUTING`, with anything it leaves out taken from
180 * `DEFAULT_ROUTING`. An unset or unreadable value is the default, and so is
181 * any single rule that names no tier.
182 */
183export function parseRouting(json: string | undefined): AgentRouting {
184 let given: Partial<AgentRouting> = {};
185 try {
186 const parsed: unknown = json ? JSON.parse(json) : {};
187 given = parsed && typeof parsed === "object" && !Array.isArray(parsed) ? (parsed as Partial<AgentRouting>) : {};
188 } catch {
189 console.log("AGENT_ROUTING is not JSON; using the default routing");
190 }
191 const tasks = { ...DEFAULT_ROUTING.tasks };
192 for (const [kind, rule] of Object.entries(given.tasks ?? {})) {
193 if (kind in tasks && (isTier(rule) || rule === "change")) tasks[kind as JobKind] = rule;
194 }
195 const effort = { ...DEFAULT_ROUTING.effort };
196 for (const [kind, level] of Object.entries(given.effort ?? {})) {
197 if (kind in tasks && EFFORTS.includes(level as Effort)) effort[kind as JobKind] = level as Effort;
198 }
199 const tiers = { ...DEFAULT_ROUTING.tiers };
200 for (const tier of TIERS) {
201 const route = given.tiers?.[tier];
202 if (route && typeof route.model === "string" && route.model) {
203 // A model named without a price has none: estimates leave it out
204 // rather than price it as another model.
205 tiers[tier] = { modelName: route.modelName || route.model, model: route.model, ...(route.price ? { price: route.price } : {}) };
206 }
207 }
208 const labels = (list: unknown, fallback: string[]) =>
209 Array.isArray(list) ? list.filter((label): label is string => typeof label === "string") : fallback;
210 return {
211 tiers,
212 tasks,
213 effort,
214 smallChange: { ...DEFAULT_ROUTING.smallChange, ...given.smallChange },
215 largeChange: { ...DEFAULT_ROUTING.largeChange, ...given.largeChange },
216 largeLabels: labels(given.largeLabels, DEFAULT_ROUTING.largeLabels),
217 frontierLabels: labels(given.frontierLabels, DEFAULT_ROUTING.frontierLabels),
218 smallLabels: labels(given.smallLabels, DEFAULT_ROUTING.smallLabels),
219 frontierAfter: typeof given.frontierAfter === "number" && given.frontierAfter >= 1 ? given.frontierAfter : DEFAULT_ROUTING.frontierAfter,
220 learning: { ...DEFAULT_ROUTING.learning, ...given.learning },
221 };
222}
223
224/** How each tier is named to people. */
225export const TIER_LABEL: Record<Tier, { noun: string; used: string }> = {
226 small: { noun: "fast", used: "Used a fast model" },
227 large: { noun: "standard", used: "Used the standard model" },
228 frontier: { noun: "most capable", used: "Used the most capable model" },
229};
230
231const up = (tier: Tier): Tier => TIERS[Math.min(TIERS.indexOf(tier) + 1, TIERS.length - 1)];
232const down = (tier: Tier): Tier => TIERS[Math.max(TIERS.indexOf(tier) - 1, 0)];
233const rank = (tier: Tier) => TIERS.indexOf(tier);
234
235function plural(n: number, one: string, many: string): string {
236 return `${n} ${n === 1 ? one : many}`;
237}
238
239/** How a tier did in the repository's recent runs of the same kind. */
240export function record(history: PastOutcome[], tier: Tier, window: number): { runs: number; ok: number } {
241 const recent = history.slice(0, window).filter((run) => run.tier === tier);
242 return { runs: recent.length, ok: recent.filter((run) => run.ok).length };
243}
244
245/**
246 * Where one job runs, and why. In order:
247 *
248 * 1. A tier the workspace chose for this work is used as chosen.
249 * 2. The job's rule gives the starting tier: a fixed tier, or for
250 * `change`, the change's size (small and touching nothing sensitive:
251 * small; larger than `largeChange`: frontier; unknown or anything
252 * else: large). Issue labels move it: `frontierLabels` to the frontier,
253 * `largeLabels` off the small tier, `smallLabels` let a change or an
254 * answer start small.
255 * 3. Escalation: `frontierAfter` failures in a row go to the frontier; one
256 * failure, or a last attempt that left low confidence, one tier up.
257 * 4. Otherwise, learning from the repository's own runs of the same kind:
258 * one tier down when the cheaper tier finished nearly all of its recent
259 * ones (never for sensitive or labelled work), one tier up when this
260 * tier failed half of its own.
261 */
262export function route(kind: JobKind, signals: RouteSignals, routing: AgentRouting = DEFAULT_ROUTING): Routed {
263 const say = (tier: Tier, why: string): Routed => ({
264 tier,
265 reason: `${TIER_LABEL[tier].used} (${routing.tiers[tier].modelName}): ${why}.`,
266 });
267 if (signals.chosen && isTier(signals.chosen)) {
268 return say(signals.chosen, `the workspace chose the ${TIER_LABEL[signals.chosen].noun} model for this work`);
269 }
270
271 const labels = new Set((signals.labels ?? []).map((label) => label.toLowerCase()));
272 const has = (list: string[]) => list.find((label) => labels.has(label.toLowerCase()));
273 const rule = routing.tasks[kind] ?? "large";
274 let tier: Tier;
275 let why: string;
276 // Sensitive or labelled work is never stepped down by learning.
277 let pinned = false;
278 if (rule === "change") {
279 const change = signals.change;
280 if (!change || change.files === 0) {
281 [tier, why] = ["large", "the change's size is not known"];
282 } else if (change.sensitive.length > 0) {
283 [tier, why, pinned] = ["large", `it touches ${change.sensitive.join(", ")}`, true];
284 } else if (change.files > routing.largeChange.files || change.lines > routing.largeChange.lines) {
285 [tier, why] = ["frontier", `large change, ${plural(change.files, "file", "files")} and ${plural(change.lines, "line", "lines")}`];
286 } else if (change.files <= routing.smallChange.files && change.lines <= routing.smallChange.lines) {
287 [tier, why] = ["small", `small change, ${plural(change.files, "file", "files")} and ${plural(change.lines, "line", "lines")}`];
288 } else {
289 [tier, why] = ["large", `a change of ${plural(change.files, "file", "files")} and ${plural(change.lines, "line", "lines")}`];
290 }
291 } else {
292 tier = rule;
293 why = DEFAULT_WHY[kind];
294 }
295 const frontierLabel = has(routing.frontierLabels);
296 const largeLabel = has(routing.largeLabels);
297 const smallLabel = has(routing.smallLabels);
298 if (frontierLabel) {
299 [tier, why, pinned] = ["frontier", `the issue is labelled ${frontierLabel}`, true];
300 } else if (largeLabel && tier === "small") {
301 [tier, why, pinned] = ["large", `the issue is labelled ${largeLabel}`, true];
302 } else if (largeLabel) {
303 pinned = true;
304 } else if (smallLabel && tier === "large" && (kind === "implement" || kind === "revise" || kind === "answer")) {
305 [tier, why] = ["small", `the issue is labelled ${smallLabel}`];
306 }
307
308 const failures = Math.max(signals.failures ?? 0, signals.retry ? 1 : 0);
309 if (failures >= routing.frontierAfter) {
310 return say("frontier", `the last ${plural(failures, "attempt", "attempts")} at this work failed`);
311 }
312 if (failures > 0) {
313 return tier === "frontier" ? say(tier, `${why}; the last attempt failed`) : say(up(tier), "the last attempt at this work failed");
314 }
315 if (signals.lowConfidence) {
316 return tier === "frontier" ? say(tier, why) : say(up(tier), "the last attempt left a change g1t was not confident in");
317 }
318
319 const history = signals.history ?? [];
320 const { window, minRuns, stepDownAt, stepUpAt } = routing.learning;
321 const here = record(history, tier, window);
322 if (here.runs >= minRuns && here.ok / here.runs < stepUpAt && tier !== "frontier") {
323 const failed = here.runs - here.ok;
324 return say(up(tier), `the ${TIER_LABEL[tier].noun} model failed ${failed} of its last ${here.runs} runs like this here`);
325 }
326 if (!pinned && tier !== "small") {
327 const cheaper = record(history, down(tier), window);
328 if (cheaper.runs >= minRuns && cheaper.ok / cheaper.runs >= stepDownAt) {
329 return say(down(tier), `it finished ${cheaper.ok} of its last ${cheaper.runs} runs like this here`);
330 }
331 }
332 return say(tier, why);
333}
334
335/** Why each kind of job starts where it does, when nothing else decides. */
336const DEFAULT_WHY: Record<JobKind, string> = {
337 implement: "making a change",
338 revise: "revising a change",
339 answer: "answering a question",
340 review: "reviewing a change",
341 update: "catching up with the base branch",
342 plan: "planning work",
343};
344
345/**
346 * The tier one piece of work runs on: `route`'s tier, for callers that
347 * need no reason.
348 */
349export function chooseTier(kind: JobKind, signals: RouteSignals, routing: AgentRouting = DEFAULT_ROUTING): Tier {
350 return route(kind, signals, routing).tier;
351}
352
353/** The tier a model ran as, by its public name or id; null when none of g1t's. */
354export function tierOfModel(model: string | null | undefined, routing: AgentRouting): Tier | null {
355 if (!model) return null;
356 return TIERS.find((tier) => routing.tiers[tier].modelName === model || routing.tiers[tier].model === model) ?? null;
357}
358
359/** The settings that decide where model requests go. */
360export type ModelRouting = {
361 /**
362 * The provider's key. Not needed when the gateway holds it and requests
363 * authenticate to the gateway instead.
364 */
365 ANTHROPIC_API_KEY?: string;
366 /** A Cloudflare AI Gateway id; empty sends requests to the provider directly. */
367 AI_GATEWAY_ID: string;
368 CLOUDFLARE_ACCOUNT_ID: string;
369 /** Authenticates to the gateway, if it requires it. */
370 AI_GATEWAY_TOKEN?: string;
371};
372
373/**
374 * What a run is for, attached to each of its requests at the gateway.
375 * `session` is the run's id there: billing finds the run's requests by it
376 * and settles the run to what the gateway priced them at.
377 */
378export type RunTags = { repo: string; pull: number; session?: string };
379
380/**
381 * A session id for a run that goes straight to the gateway (no model
382 * proxy): `rs_` and 24 hex characters, which billing's log filter needs
383 * no escaping for.
384 */
385export function gatewaySession(): string {
386 const bytes = crypto.getRandomValues(new Uint8Array(12));
387 return `rs_${Array.from(bytes, (b) => b.toString(16).padStart(2, "0")).join("")}`;
388}
389
390/** Whether there is a way to reach a model at all. */
391export function canReachModel(env: ModelRouting): boolean {
392 return Boolean(env.ANTHROPIC_API_KEY || (env.AI_GATEWAY_ID && env.AI_GATEWAY_TOKEN));
393}
394
395/**
396 * The model variables of a run on g1t's hosted models: the tier's model
397 * for the work, and the small tier's for the harness's own small tasks.
398 */
399export function tierVars(routing: AgentRouting, tier: Tier): Record<string, string> {
400 const route = routing.tiers[tier];
401 return {
402 ANTHROPIC_MODEL: route.model,
403 // Recorded at the top of the session, so anyone can see what ran.
404 AGENT_MODEL_NAME: route.modelName,
405 ANTHROPIC_DEFAULT_HAIKU_MODEL: routing.tiers.small.model,
406 ANTHROPIC_SMALL_FAST_MODEL: routing.tiers.small.model,
407 };
408}
409
410/** Where the sandbox sends model requests, and what it sends with them. */
411export function modelEnv(
412 env: ModelRouting,
413 routing: AgentRouting,
414 task: AgentTask,
415 tier: Tier,
416 tags: RunTags,
417): Record<string, string> {
418 const vars = tierVars(routing, tier);
419 if (env.ANTHROPIC_API_KEY) vars.ANTHROPIC_API_KEY = env.ANTHROPIC_API_KEY;
420 if (!env.AI_GATEWAY_ID) return vars;
421
422 vars.ANTHROPIC_BASE_URL = `https://gateway.ai.cloudflare.com/v1/${env.CLOUDFLARE_ACCOUNT_ID}/${env.AI_GATEWAY_ID}/anthropic`;
423 // The gateway logs these with every request, so spend and failures can
424 // be read per kind of work, tier, repository and pull request; and by
425 // the run's session, which billing settles the run's charge by.
426 const headers = [`cf-aig-metadata: ${JSON.stringify({ task, tier, ...tags })}`];
427 if (env.AI_GATEWAY_TOKEN) {
428 vars.AI_GATEWAY_TOKEN = env.AI_GATEWAY_TOKEN;
429 headers.push(`cf-aig-authorization: Bearer ${env.AI_GATEWAY_TOKEN}`);
430 // With the provider's key stored in the gateway, the sandbox never
431 // holds it. The harness still wants the variable set.
432 vars.ANTHROPIC_API_KEY ??= env.AI_GATEWAY_TOKEN;
433 }
434 vars.ANTHROPIC_CUSTOM_HEADERS = headers.join("\n");
435 return vars;
436}
437
438/** Lines added and removed across a change's files. */
439export function changeSize(files: { additions: number; deletions: number }[], sensitive: string[]): ChangeSize {
440 return {
441 files: files.length,
442 lines: files.reduce((sum, file) => sum + file.additions + file.deletions, 0),
443 sensitive,
444 };
445}
446
447/** A past run of the same work, as the work service lists it. */
448export type PastAttempt = {
449 status: string;
450 halted?: string | null;
451 title?: string | null;
452 /** The pull request or issue it was for. */
453 number?: number | null;
454 /** The model it ran on, by its public name. */
455 model?: string | null;
456 confidence?: { level: string } | null;
457};
458
459/**
460 * Whether the latest attempt at the same work failed: it failed, or g1t
461 * stopped it at a cap of its guardrails. A person stopping it is not a
462 * failure. `title` narrows it to the same plan, whose runs have no pull
463 * request to tell them apart.
464 */
465export function lastAttemptFailed(newestFirst: PastAttempt[], title?: string): boolean {
466 const last = newestFirst[0];
467 if (!last) return false;
468 if (title !== undefined && (last.title ?? "").trim() !== title.trim()) return false;
469 return last.status === "failed" || (last.status === "stopped" && Boolean(last.halted));
470}
471
472/** Whether a past run failed: it failed, or g1t stopped it at a cap of its guardrails. */
473function failed(run: PastAttempt): boolean {
474 return run.status === "failed" || (run.status === "stopped" && Boolean(run.halted));
475}
476
477/**
478 * How many of the latest attempts at the same work failed in a row. A
479 * finished one, or a person stopping one, ends the count. `title` narrows
480 * it to the same plan, as for `lastAttemptFailed`.
481 */
482export function failuresInARow(newestFirst: PastAttempt[], title?: string): number {
483 let count = 0;
484 for (const run of newestFirst) {
485 if (title !== undefined && (run.title ?? "").trim() !== title.trim()) break;
486 if (!failed(run)) break;
487 count += 1;
488 }
489 return count;
490}
491
492/** Whether the latest attempt finished but left a change g1t was not confident in. */
493export function leftLowConfidence(newestFirst: PastAttempt[]): boolean {
494 const last = newestFirst[0];
495 return Boolean(last && last.status === "succeeded" && last.confidence?.level === "low");
496}
497
498/**
499 * The repository's recent runs of one kind, as learning reads them: the
500 * tier each ran on, and whether it did the work. Runs still going say
501 * nothing yet, and a person stopping one is not the model's failure.
502 */
503export function outcomesOf(newestFirst: PastAttempt[], routing: AgentRouting): PastOutcome[] {
504 return newestFirst
505 .filter((run) => run.status === "succeeded" || failed(run))
506 .map((run) => ({
507 tier: tierOfModel(run.model, routing),
508 ok: run.status === "succeeded" && run.confidence?.level !== "low",
509 }));
510}