flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/work/migrations/0018_guardrails.sql

22 lines961 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1-- Guardrails: what a workspace lets its agents do in a sandbox. One row
2-- for the workspace's defaults (scope 'workspace', scope_key its slug) and
3-- one per project that overrides them (scope 'project', scope_key its
4-- repository's id). A missing row inherits everything.
5CREATE TABLE guardrails (
6 scope TEXT NOT NULL,
7 scope_key TEXT NOT NULL,
8 -- The workspace's slug, for renames.
9 workspace TEXT NOT NULL,
10 -- JSON: g1t_contracts::guardrails::GuardrailSettings, unset fields inherited.
11 settings TEXT NOT NULL,
12 updated_by TEXT NOT NULL,
13 updated_at TEXT NOT NULL,
14 PRIMARY KEY (scope, scope_key)
15);
16CREATE INDEX guardrails_by_workspace ON guardrails (workspace);
17
18-- The caps a run started with, and which one stopped it.
19ALTER TABLE agent_runs ADD COLUMN budget_usd REAL;
20ALTER TABLE agent_runs ADD COLUMN time_cap_minutes INTEGER;
21-- budget or time, when g1t stopped it for reaching that cap.
22ALTER TABLE agent_runs ADD COLUMN halted TEXT;