flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/apps/sudo/README.md

81 lines3,739 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Billing accounts, terms and enterprises; g1t is no longer free1# sudo
2
3g1t's staff console, at <https://sudo.g1t.sh>. Staff use it to manage how
4accounts pay: comp a workspace, set custom terms (a discount, a ceiling on
5unpaid usage, an end date), create Enterprise accounts that pay for several
6workspaces, move workspaces on and off them, issue credits, and see where
7every account stands this month with its ledger and audit log.
8
9It holds no data. Everything goes to the billing service's staff methods
10(`admin_*`, see `BillingAdminApi` in `packages/contracts/src/billing.ts`),
11and each change is recorded there with the staff member's email.
12
13## How it is locked
14
151. **Cloudflare Access** sits in front of `sudo.g1t.sh` and signs people in.
162. **The worker checks Access's work** on every request, the stylesheet
17 included (`run_worker_first`): it verifies the `Cf-Access-Jwt-Assertion`
18 JWT itself (RS256 against the team's published keys, audience, issuer,
19 expiry), then requires its email to be in `STAFF_EMAILS`. That email is
20 who every change is recorded as. See `app/lib/access.ts`.
213. **It fails closed.** Until `ACCESS_TEAM_DOMAIN`, `ACCESS_AUD` and
22 `STAFF_EMAILS` are all set, every request gets a 403 saying sudo is not
23 configured.
244. **Changes** are POSTs only, and only from sudo's own pages (`Origin`, or
25 `Referer`, must be `https://sudo.g1t.sh`). Terms, enterprise moves and new
26 enterprises show a confirmation step first; a credit needs the workspace's
27 slug typed out.
285. **The pages ship no JavaScript.** The content security policy forbids
29 every script and inline style; responses are `no-store`, `noindex` and
30 cannot be framed. The worker has no `workers.dev` address or preview URLs.
31
32## Setting up Access (once, in the Cloudflare dashboard)
33
341. **Zero Trust → Access → Applications → Add an application → Self-hosted.**
35 - Application name: `sudo`.
36 - Session duration: short, such as 8 hours.
37 - Public hostname: `sudo.g1t.sh` (path empty, so it covers everything).
sudo: Access is on, and everyone at g1t.sh is staff382. **Add a policy** (`g1t staff`): action *Allow*, include *Emails* → the
39 owner's address, and *Emails ending in* → `g1t.sh` for everyone with a
40 g1t address (the same entries as `STAFF_EMAILS`, where a domain is
41 written `@g1t.sh`). Add more staff here *and* in `STAFF_EMAILS`; either
42 one alone is not enough.
Billing accounts, terms and enterprises; g1t is no longer free433. Save, then open the application's **Overview** (or *Basic information*)
44 and copy the **Application Audience (AUD) tag**.
454. Find the **team domain** under **Zero Trust → Settings → Custom pages**
46 (or *Team name and domain*): it looks like `<team>.cloudflareaccess.com`.
475. Put both into `wrangler.jsonc`:
48
49 ```jsonc
50 "vars": {
51 "ACCESS_TEAM_DOMAIN": "<team>.cloudflareaccess.com",
52 "ACCESS_AUD": "<the AUD tag>",
sudo: Access is on, and everyone at g1t.sh is staff53 "STAFF_EMAILS": "syntaqx@gmail.com, @g1t.sh"
Billing accounts, terms and enterprises; g1t is no longer free54 }
55 ```
56
576. Deploy: `scripts/deploy.sh sudo` (after `billing`, whose `admin_*`
58 methods it calls).
59
60Visit <https://sudo.g1t.sh>: Access asks you to sign in, then the accounts
61list opens. Anyone else gets Access's own refusal; anyone Access lets in who
62is not in `STAFF_EMAILS` gets a 403 from the worker.
63
sudo: WARP sign-in, and comped accounts say Comped64## Signing in through WARP
65
66Staff signed in to the Zero Trust org in the Cloudflare One agent (WARP)
67reach sudo without the login page: the org allows WARP sessions as Access
68sign-ins (8 hours), the sudo app accepts them, and the `g1t staff` policy
69is also on the WARP enrollment app, so staff can enroll their devices.
70The same two checks still apply: the Access policy, and `STAFF_EMAILS`.
71
Billing accounts, terms and enterprises; g1t is no longer free72## Working on it
73
74```sh
75npm run typecheck -w @g1t/sudo
76npm test -w @g1t/sudo # JWT verification, forms, money
77npm run build -w @g1t/sudo
78```
79
80`npm run dev` serves the pages, but every request is refused without a real
81Access token, by design.