Skip to content
282 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Billing accounts, terms and enterprises; g1t is no longer free1# sudo
2
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales3g1t's staff console, at <https://sudo.g1t.sh>: the back office g1t is
4building for itself, for sales, support and finance. It is organised the
5way customers know g1t: by **workspace**.
6
7The sidebar (`app/lib/nav.ts`) has Overview and Reach out at the top, then
8sections that fold open to their pages: Customers, Revenue, Platform,
9Support and Team. Each fold is a `<details>`, drawn open for the section
10holding the current page; on a phone the same menu sits behind a "Menu"
11button in the top bar. Pages not built yet are marked **Soon**: each is a
12real page (`routes/soon.tsx`, made from its entry in `nav.ts`) saying what
13it will do, why, and what it will have, so the sidebar doubles as the
14roadmap.
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace15
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales16- **Overview** (`/`): this month charged, cost and margin; the last six
17 months as a chart; this month by kind of usage; paying workspaces; how
18 many are stopped, near their limit or declined (each a link into Reach
19 out); open invoices; follow-ups due; and the five most urgent signals.
20 From billing's `admin_overview` and `admin_signals`.
21- **Reach out** (`/reach-out`): every workspace worth a word, most urgent
22 first (at limit, declined, near limit, high spend, growing, established,
23 first payment), with its owners, the reason in a sentence, the figure,
24 and its sales stage and owner at g1t. Filter by why and by whose
sudo: Invoices, Audit log, and follow-ups due25 (everyone's, unassigned, mine), or show only **follow-ups due** (a next
26 step due today or earlier, on a deal not won or lost; one per
27 workspace). Rows show the next step and its day. Each row opens the
28 workspace's Sales.
29- **Invoices** (`/invoices`): every invoice g1t has sent, workspaces' and
30 enterprises', newest first (`admin_invoices`, at most 200). Filter by
31 status and month; totals for what is listed (amount, paid, outstanding);
32 each links to its workspace or enterprise and to Stripe's page (https
33 only).
34- **Audit log** (`/audit`): every change made in sudo, and what Stripe told
35 billing, newest first, 100 a page with "Older" (`admin_audit`). Filter by
36 staff email and kind of change; each line links to its workspace or
37 enterprise.
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales38- **Workspaces** (`/workspaces`): every workspace, newest first, 50 to a
Stripe webhooks, enterprise invoices, and sudo for both39 page, with its owners, members, who it is billed to, its terms, this
40 month's usage against its limit, what it was charged and what it cost
41 g1t. Search by workspace, owner, email or enterprise (across the whole
42 list); filter to stopped or warning, comped or custom, or on an
43 enterprise. Billing's figures are fetched for exactly the page shown, so
44 the filters, and the totals over the list, cover that page; the page
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales45 says so when there is more than one. A workspace's page shows its members;
46 **Sales** (its stage, the staff member who has it, the next step and its
47 date, and notes, newest first; `admin_sales`, `admin_set_sales`,
48 `admin_add_note`); and under **Billing** its limit in words (trust, the
49 owners' own spend limit or the default, the most they may set, how it
50 grows), its last six months as a chart, its invoices (`admin_workspace_invoices`,
51 with Stripe's page and PDF), its terms, who it is billed to (move it onto or off an
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace52 enterprise), a credit form, a Stripe billing link, its ledger and its
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales53 audit log. If billing does not answer for sales or invoices, the page
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member54 still opens and says so in those sections. A protected workspace (one
55 nobody can ever delete: identity's `PROTECTED_WORKSPACES`, and
56 flagon-io always) says so beside its name.
57- **Deleted workspaces** (`/workspaces/deleted`, linked from Workspaces):
58 workspaces their owners deleted, newest first (`admin_deleted_workspaces`),
59 each with who deleted it and when, when it is purged, what went with it
60 (repositories, projects, members, counted at the deletion) and the days
61 left. An owner deletes a workspace with everything in it in one step, and
62 identity keeps it 30 days (`WORKSPACE_RESTORE_DAYS`) so support can undo a
63 deletion that was a mistake or not theirs to make. **Restore**
64 (`admin_restore_workspace`) brings it back with its members and tokens,
65 and its repositories, projects and apps with `workspace.restored`; its
66 plan stays ended, so its owners start it again from Billing. Check that
67 whoever asks is an owner of it before restoring. **Purge now**
68 (`admin_purge_workspace`, the slug typed to confirm) removes it at once,
69 as the sweep does every 15 minutes once its 30 days are up; never for a
70 protected workspace. Both go in the workspace's audit log, as g1t, and in
71 sudo's (`workspace_restored`, `workspace_purged`), naming the staff
72 member.
Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)73- **A person's page** (`/users/<username>`, linked from a workspace's
74 members): their addresses (remove one, with a reason they see), their
75 security log, and **Delete account**. Delete only when the person asks
76 (from one of the account's confirmed addresses) or for abuse: give the
77 reason, which goes in sudo's audit log (`account_deleted`), and type the
78 username (`admin_delete_account`). It does what deleting their own
79 account from Settings does: signs them out everywhere, ends their tokens,
80 SSH keys, deploy keys they added and applications, takes them out of
81 every workspace, team and repository, and emails their addresses that
Staff delete an account with the workspaces it alone owns82 staff deleted it. While the account is the **only owner of a live
83 workspace**, the page lists those workspaces, each linking to its page,
84 and the form becomes **Delete account and the workspaces it alone
85 owns**: the reason, the username typed, and a box ticked to say the
86 named workspaces go too (`admin_delete_account` with
87 `withSoleWorkspaces`). Use it for an account g1t no longer needs, such
88 as a retired test account and its personal workspace; for a customer,
89 prefer another owner first (an owner makes one under People). Identity
90 checks every one of those workspaces before anything is deleted: one
91 that is protected, or whose billing cannot settle (`close_workspace`:
92 an unpaid invoice, prepaid credit, usage still metering, an enterprise
93 account), refuses the whole deletion, and the page says which and why
94 beside each, instead of the form. Then it deletes each workspace exactly
95 as its owner would (billing closes it, `workspace.deleting`, its
96 repositories and apps go with it, kept 30 days), with the staff member
97 as who deleted it, and the account last. Each workspace is recorded in
98 its own audit log as g1t (rule `staff`) and in sudo's
99 (`workspace_deleted`, with the reason); the account in sudo's
100 (`account_deleted`, naming the workspaces). Should one fail on the way
101 (a card declined that moment), the account is not deleted and the
102 error names the workspace and any that went before; restore those from
103 Deleted workspaces, or try again. Accounts that can never be deleted (`g1t`, `g1t-agent`, `ghost`,
Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)104 and whatever identity's `PROTECTED_ACCOUNTS` names, by username or id)
105 are marked **Protected** and offer no form. A deleted account's page
106 says so, with who deleted it, why, when it is purged, and **Restore** and
Staff delete an account with the workspaces it alone owns107 **Purge now**, as on Deleted accounts; both work at once, with no wait.
108 When workspaces were deleted with it, it lists them too, each with its
109 own **Purge now** (`admin_purge_workspace`, the slug typed; identity
110 purges only a workspace that is still deleted, never a protected one),
111 so staff can remove everything straight away. Purge the workspaces
112 first: once the account is purged its page is gone (they stay on
113 Deleted workspaces). To undo it all, restore the account first, then
114 each workspace, so it comes back with its owner.
Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)115- **Deleted accounts** (`/users/deleted`, linked from Workspaces):
116 accounts deleted by the person or by staff, newest first
117 (`admin_deleted_accounts`), each with who deleted it (the person, or the
118 staff member and why), when it is purged, the days left and what it
119 left (workspaces, teams, repositories, tokens, SSH keys). Identity keeps
120 each 30 days (`ACCOUNT_RESTORE_DAYS`). **Restore**
121 (`admin_restore_account`) clears the deletion and puts back the
122 memberships, teams and repository roles it left where they still exist;
123 its sessions, tokens and keys stay ended, and the person signs in with
124 their password. Check that whoever asks owns one of its addresses first.
125 **Purge now** (`admin_purge_account`, the username typed) removes it at
126 once, as the sweep does every 15 minutes once its 30 days are up: its
127 row, addresses, keys, two-factor secret, GitHub link, profile and
128 security log go; its username is kept in `deleted_users` and never given
129 out again; what it wrote shows as `ghost`. Both go in sudo's audit log
130 (`account_restored`, `account_purged`), naming the staff member. There
131 is no API route for deleting an account; only the site and sudo can.
Merge branch 'worktree-agent-a8385d293d42c913a'132- **Aliases** (`/aliases`, under Customers): names that lead to a
133 workspace, set by staff only; there is no way for a customer to make
134 one, and nothing user-facing mentions them. `g1t`, the product's name,
135 leads to `flagon-io`, Flagon, Inc. (seeded by identity's migration
136 `0029_workspace_aliases.sql`), so nobody mistakes the trading name for
137 the organization. Every address under an alias leads to the workspace:
138 pages answer with a 301 to the same page (`/g1t/g1t/issues` to
139 `/flagon-io/g1t/issues`), git over HTTPS is answered in place as the
140 workspace's repository (pushes do not follow redirects), the API and MCP
141 run the call again under the workspace's slug, and the package
142 registries answer a 301 (308 for a publish). An alias points at the
143 workspace's id, so it follows a rename; it goes when the workspace is
144 purged. Each row shows the workspace, why the alias exists, and who added
145 it and when. **Add** (`admin_set_alias`) takes the alias, the
146 workspace's slug and why: identity refuses the site's own routes
147 (`settings`, `api`…), anyone's username, a workspace's slug (deleted, or
148 held after a rename for another workspace) and an existing alias.
149 Reserved names such as `g1t` can be aliases, and an alias is nobody's to
150 register or rename a workspace to while it exists. **Remove**
151 (`admin_remove_alias`) needs a reason. Both go in sudo's audit log
152 (`alias_added`, `alias_removed`), naming the staff member. `@g1t` in
153 text still means g1t's agent: it links to how the agent works, never to
154 `/g1t`.
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace155- **Enterprises**: customers that pay for several workspaces with one
156 bill, one limit and one set of terms. Each has its workspaces (add or
Stripe webhooks, enterprise invoices, and sudo for both157 remove them), combined usage, terms, credits, ledger and audit log, and
158 **Invoices**: where they go (the billing email, which also makes its
159 Stripe customer), a "Send invoice now" button, and every invoice with
160 its status (open, paid, overdue, void), a line per workspace, and a link
161 to Stripe's hosted invoice page. An invoice also goes out on its own as
162 each month closes: one Stripe invoice, a line per workspace for what it
163 owes, net 30, emailed by Stripe.
Merge branch 'main' into actions-toolkit-oidc-artifacts164- **Agents & models** (`/agents`, under Platform): billing's model
165 catalogue, every model g1t can use (`admin_models`). **Check for new
166 models** lists each provider's models now, through the model proxy's
167 `Discovery` entrypoint (the `MODELS` binding), as the daily check does;
168 the result says what each provider listed, what is new or gone, or why a
169 provider could not be listed. **Defaults**: the model behind each of
170 Auto's tiers, the harness's background model and the AI Gateway's first
171 Claude (an available, priced Claude each, shown with what a typical run
172 costs on it), and each kind of job's starting tier and effort. A change
173 needs a reason and shows a review first, the current and new value side
174 by side with what a typical run would cost on each, before **Save**
175 (`admin_set_model_default`); runs pick it up within a minute. A default
176 that has fallen back (its model retired or no longer listed) says so.
177 **New models**: each model a check found, with its prices filled in
178 where known; confirm its name, tier and prices per million tokens (and
179 long-prompt prices) and **Approve**, or **Retire** it
180 (`admin_decide_model`). **Catalogue**: every other model with its status,
181 context, prices, typical run and when its provider last listed it, each
182 with **Retire** or **Restore**. **Checks**: the latest checks of each
183 provider. Every change names the staff member and why in the audit log
184 (account `models`). See docs/BILLING_OPERATIONS.md, "The model
185 catalogue".
Stripe webhooks, enterprise invoices, and sudo for both186- **Stripe**: whether billing's key is in test or live mode (or off), the
187 webhook Stripe calls (URL, endpoint id, events, who registered it and
188 when), and the events Stripe sent lately with what billing did with
189 each. "Register webhook" (or "Replace") has billing delete the endpoint
190 it made before, create a new one and keep its signing secret, which no
191 one sees. Do it once per mode, and again after switching to live keys.
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace192
A menu shaped by how g1t works, Soon pages for every promise, and sudo for sales193Sales changes are not money, so they have no confirmation step; they are
194still POSTs from sudo's own pages, recorded with who made them.
195
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace196Billing's internal account ids (`ws_<slug>` for a workspace's own,
197`ent_…` for an enterprise) are never shown as names; an enterprise's id
198appears only as small "Billing account id" text. Old `/accounts/…` links
199redirect to the workspace or enterprise they meant.
200
201**Cards stay on Stripe.** sudo never shows a card field. To help a customer
202update their card or see invoices, staff make a Stripe billing link on the
203workspace's page (it is recorded) and send it to the owner.
Billing accounts, terms and enterprises; g1t is no longer free204
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace205It holds no data. Workspaces, owners and members come from identity's
206staff methods (`admin_workspaces`, `admin_workspace`; `IdentityAdminApi` in
207`packages/contracts/src/identity.ts`); everything about money goes to the
208billing service's (`admin_*`, `BillingAdminApi` in
209`packages/contracts/src/billing.ts`), where each change is recorded with
210the staff member's email. Both are reached over service bindings only, and
211nothing but sudo binds to them.
Billing accounts, terms and enterprises; g1t is no longer free212
213## How it is locked
214
2151. **Cloudflare Access** sits in front of `sudo.g1t.sh` and signs people in.
2162. **The worker checks Access's work** on every request, the stylesheet
217 included (`run_worker_first`): it verifies the `Cf-Access-Jwt-Assertion`
218 JWT itself (RS256 against the team's published keys, audience, issuer,
219 expiry), then requires its email to be in `STAFF_EMAILS`. That email is
220 who every change is recorded as. See `app/lib/access.ts`.
2213. **It fails closed.** Until `ACCESS_TEAM_DOMAIN`, `ACCESS_AUD` and
222 `STAFF_EMAILS` are all set, every request gets a 403 saying sudo is not
223 configured.
2244. **Changes** are POSTs only, and only from sudo's own pages (`Origin`, or
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace225 `Referer`, must be `https://sudo.g1t.sh`). Terms, enterprise moves, new
Stripe webhooks, enterprise invoices, and sudo for both226 enterprises, Stripe billing links, invoice emails, invoices and the
227 webhook show a confirmation step first; a credit needs the workspace's
228 slug typed out.
Billing accounts, terms and enterprises; g1t is no longer free2295. **The pages ship no JavaScript.** The content security policy forbids
230 every script and inline style; responses are `no-store`, `noindex` and
231 cannot be framed. The worker has no `workers.dev` address or preview URLs.
232
233## Setting up Access (once, in the Cloudflare dashboard)
234
2351. **Zero Trust → Access → Applications → Add an application → Self-hosted.**
236 - Application name: `sudo`.
237 - Session duration: short, such as 8 hours.
238 - Public hostname: `sudo.g1t.sh` (path empty, so it covers everything).
sudo: Access is on, and everyone at g1t.sh is staff2392. **Add a policy** (`g1t staff`): action *Allow*, include *Emails* → the
240 owner's address, and *Emails ending in* → `g1t.sh` for everyone with a
241 g1t address (the same entries as `STAFF_EMAILS`, where a domain is
242 written `@g1t.sh`). Add more staff here *and* in `STAFF_EMAILS`; either
243 one alone is not enough.
Billing accounts, terms and enterprises; g1t is no longer free2443. Save, then open the application's **Overview** (or *Basic information*)
245 and copy the **Application Audience (AUD) tag**.
2464. Find the **team domain** under **Zero Trust → Settings → Custom pages**
247 (or *Team name and domain*): it looks like `<team>.cloudflareaccess.com`.
2485. Put both into `wrangler.jsonc`:
249
250 ```jsonc
251 "vars": {
252 "ACCESS_TEAM_DOMAIN": "<team>.cloudflareaccess.com",
253 "ACCESS_AUD": "<the AUD tag>",
sudo: Access is on, and everyone at g1t.sh is staff254 "STAFF_EMAILS": "syntaqx@gmail.com, @g1t.sh"
Billing accounts, terms and enterprises; g1t is no longer free255 }
256 ```
257
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace2586. Deploy: `scripts/deploy.sh sudo` (after `billing` and `identity`, whose
259 `admin_*` methods it calls).
Billing accounts, terms and enterprises; g1t is no longer free260
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace261Visit <https://sudo.g1t.sh>: Access asks you to sign in, then the workspaces
Billing accounts, terms and enterprises; g1t is no longer free262list opens. Anyone else gets Access's own refusal; anyone Access lets in who
263is not in `STAFF_EMAILS` gets a 403 from the worker.
264
sudo: WARP sign-in, and comped accounts say Comped265## Signing in through WARP
266
267Staff signed in to the Zero Trust org in the Cloudflare One agent (WARP)
268reach sudo without the login page: the org allows WARP sessions as Access
269sign-ins (8 hours), the sudo app accepts them, and the `g1t staff` policy
270is also on the WARP enrollment app, so staff can enroll their devices.
271The same two checks still apply: the Access policy, and `STAFF_EMAILS`.
272
Billing accounts, terms and enterprises; g1t is no longer free273## Working on it
274
275```sh
276npm run typecheck -w @g1t/sudo
Merge branch 'main' into actions-toolkit-oidc-artifacts277npm test -w @g1t/sudo # JWT verification, forms, money, the workspace join, paging, nav, charts, signals, models
Billing accounts, terms and enterprises; g1t is no longer free278npm run build -w @g1t/sudo
279```
280
281`npm run dev` serves the pages, but every request is refused without a real
282Access token, by design.

This file's history is long; its oldest lines are credited to the oldest commit read.