Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Initial g1t: services, event bus, intents and attempts | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-repos", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| Agents as a team: lifecycle, merge queue, billing and a new shell | 6 | // Runs next to its database: a request makes several queries in turn, |
| 7 | // and each would otherwise cross the distance to it. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 8 | "placement": { "mode": "off" }, |
| Rust repos service with shipping; pull requests kept in the model | 9 | "main": "build/index.js", |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 10 | "build": { "command": "node ../../scripts/build-rust-worker.mjs" }, |
| Initial g1t: services, event bus, intents and attempts | 11 | "workers_dev": false, |
| 12 | "d1_databases": [ | |
| 13 | { | |
| 14 | "binding": "DB", | |
| 15 | "database_name": "g1t-repos", | |
| 16 | "database_id": "f9544c51-c3bf-4621-a96f-8a6d5cf24a97", | |
| 17 | "migrations_dir": "migrations" | |
| 18 | } | |
| 19 | ], | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 20 | // The git store. Every repository made before sharding is in `g1t`. |
| 21 | // More namespaces (src/shards.rs) are more bindings, named in | |
| 22 | // ARTIFACTS_NAMESPACES below, e.g. | |
| 23 | // { "binding": "ARTIFACTS_1", "namespace": "g1t-us-1" }, | |
| 24 | // { "binding": "ARTIFACTS_EU", "namespace": "g1t-eu", "jurisdiction": "eu" } | |
| 25 | // and new repositories go to those named in ARTIFACTS_NEW_REPOS. | |
| Initial g1t: services, event bus, intents and attempts | 26 | "artifacts": [{ "binding": "ARTIFACTS", "namespace": "g1t" }], |
| Mission control shows where you are needed and what agents landed without you; git answers in about 200ms | 27 | // Shared between isolates (src/shared.rs): the git store's credentials |
| 28 | // (src/store.rs) and the ref listings git asks for first | |
| 29 | // (src/refs_cache.rs), every value sealed with the REPOS_KEY secret (64 | |
| 30 | // hex characters). Without the binding or the secret each isolate keeps | |
| 31 | // only its own. Made by `npx wrangler kv namespace create g1t-repos-git-cache`: | |
| 32 | "kv_namespaces": [{ "binding": "GIT_CACHE", "id": "be765052d0124c2a935b3db4dff99f1f" }], | |
| Merge branch 'worktree-agent-a1b995daa94e4e1b7' | 33 | // Packs for fresh clones (wants and no haves), kept under the |
| 34 | // repository's refs version so the next clone of the same commit skips | |
| 35 | // the git store (src/pack_cache.rs). Without the binding nothing is | |
| 36 | // kept. Made with a lifecycle rule that deletes packs after 7 days and | |
| 37 | // unfinished uploads after 1: | |
| 38 | // npx wrangler r2 bucket create g1t-git-packs | |
| 39 | // npx wrangler r2 bucket lifecycle add g1t-git-packs expire-packs packs/ --expire-days 7 --abort-multipart-days 1 | |
| 40 | "r2_buckets": [{ "binding": "GIT_PACKS", "bucket_name": "g1t-git-packs" }], | |
| Initial g1t: services, event bus, intents and attempts | 41 | "services": [ |
| 42 | { "binding": "IDENTITY", "service": "g1t-identity" }, | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 43 | { "binding": "EVENTS", "service": "g1t-events" }, |
| 44 | // Push protection asks which secrets were allowed, and records the rest. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 45 | { "binding": "SECURITY", "service": "g1t-security" }, |
| 46 | // Whether a workspace far past its free git operations is on the | |
| 47 | // plan (src/git_ops.rs); asked only then. | |
| 48 | { "binding": "BILLING", "service": "g1t-billing" } | |
| Initial g1t: services, event bus, intents and attempts | 49 | ], |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 50 | // A free workspace past this many git operations in a month is slowed |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 51 | // to this many an hour, never charged (src/git_ops.rs). It is billing's |
| 52 | // GIT_OPERATIONS_INCLUDED, the amount free for every workspace: past it, | |
| 53 | // a workspace on the plan pays at cost plus 20% and is never slowed. | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 54 | // FREE_PRIVATE_STORAGE_BYTES: a free workspace's private repositories may |
| 55 | // hold this much (1 GB); past it, pushes to them stop. Billing reads the | |
| 56 | // same amount. | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 57 | // |
| 58 | // The git store (docs/ARTIFACTS.md): | |
| 59 | // REPO_STORAGE_LIMIT_BYTES: pushes stop before a repository holds this | |
| 60 | // much; the store holds 1 GB (src/pack_limits.rs). | |
| 61 | // LARGE_PUSHES: a push too large to scan for secrets (24 MiB) is | |
| 62 | // "refuse"d, or streamed to the store "unscanned" (src/git_http.rs). | |
| 63 | // FORK_RETENTION_DAYS: a pull request working copy is removed this long | |
| 64 | // after its pull request merges or closes (src/forks.rs). | |
| 65 | // ARTIFACTS_NAMESPACES: JSON, each Artifacts binding and its namespace; | |
| 66 | // ARTIFACTS_NEW_REPOS: comma-separated namespaces new repositories go | |
| 67 | // to (empty: g1t); ARTIFACTS_EU_NAMESPACE: for EU residency (src/shards.rs). | |
| 68 | // ARTIFACTS_REMOTE_BASE (optional): where remotes start, | |
| 69 | // https://<account>.artifacts.cloudflare.net/git, so a new isolate | |
| 70 | // needs no info() call before its first credential (src/store.rs). | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 71 | "vars": { |
| 72 | "GIT_OPERATIONS_FREE_CAP": "50000", | |
| 73 | "GIT_OPERATIONS_FREE_HOURLY": "60", | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 74 | "FREE_PRIVATE_STORAGE_BYTES": "1000000000", |
| 75 | "REPO_STORAGE_LIMIT_BYTES": "950000000", | |
| 76 | "LARGE_PUSHES": "unscanned", | |
| Pull request forks are removed a day after they merge or close, not a week | 77 | "FORK_RETENTION_DAYS": "1", |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 78 | "ARTIFACTS_NAMESPACES": "{\"ARTIFACTS\":\"g1t\"}", |
| 79 | "ARTIFACTS_NEW_REPOS": "" | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 80 | }, |
| 81 | // Every hour, deleted repositories whose 30 days to be restored have | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 82 | // passed are purged, their git data with them (src/lifecycle.rs), and |
| 83 | // pull request working copies past FORK_RETENTION_DAYS are removed | |
| 84 | // (src/forks.rs). | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 85 | "triggers": { "crons": ["23 * * * *"] }, |
| 86 | // A workspace renamed moves its repositories to the new slug; one | |
| 87 | // deleted purges the repositories it left in Recently deleted. | |
| Agents and memory, checks and conflicts, profiles, slug renames, custom domains | 88 | "queues": { |
| 89 | "consumers": [{ "queue": "g1t-events-repos", "max_batch_size": 20, "max_batch_timeout": 1 }] | |
| 90 | }, | |
| Initial g1t: services, event bus, intents and attempts | 91 | "observability": { "enabled": true } |
| 92 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.