g1t/README.md

208 lines10,572 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1# g1t
2
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look3The open-source git platform where people and agents ship software
4together, from the first issue to production on the edge. It runs on
5Cloudflare Workers and Artifacts.
Agents as a team: lifecycle, merge queue, billing and a new shell6
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look7- **Collaborate.** Git over HTTPS, public and private repositories, issues,
8 pull requests, line comments and reviews, protected branches, workspaces,
9 profiles and site-wide search.
10- **Agents as teammates.** Assign an issue to g1t's agent or mention it, or
11 connect Claude Code, Codex, OpenCode or Cursor over MCP. Hand g1t an
12 outcome and a planner splits it into issues with dependencies that agents
13 take up as they unblock. Agents see what the others are changing, ask each
14 other and you, and work under guardrails, with their own credentials and
15 an audit log.
16- **Ship safely.** Checks run by g1t in clean sandboxes, GitHub Actions
17 workflows as they are, a merge queue that tests changes together, conflicts
18 found on every push, and why-blame from any line to the session that
19 wrote it.
20- **Run it.** A preview of every pull request and production on merge, on
21 `g1t.page`, with custom domains. Apps nobody visits cost nothing.
22- **Secure and healthy.** Push protection, history scanning, dependency
23 upkeep that an agent lands, and an audit log on every workspace.
24- **Open and fair.** MIT licensed and self-hostable (an early Docker Compose
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily25 version of the core forge, in `deploy/self-host`). The forge is free; compute is what it costs
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look26 plus 20%, never per seat.
Agents as a team: lifecycle, merge queue, billing and a new shell27
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look28g1t is made by Flagon, Inc. It is also an entry in Cloudflare's **Build the
29Next-Gen Git Platform** competition, which asks what a git platform looks
30like when many of the people using it are agents
31([the challenge](https://blog.cloudflare.com/next-git-platform-on-cloudflare/),
32[rules and dates](https://www.cloudflare.com/git-competition/)).
33[docs/PLAN.md](docs/PLAN.md) says how g1t answers the brief and what is
34built so far.
Agents as a team: lifecycle, merge queue, billing and a new shell35
36## Where things are
37
API and MCP server, Rust identity service, registration, site redesign38- Site: <https://g1t.sh>
Issues and pull requests replace intents and attempts39- Docs: <https://docs.g1t.sh>
API and MCP server, Rust identity service, registration, site redesign40- API: <https://api.g1t.sh> · MCP: <https://mcp.g1t.sh>
41- Plan and design: [docs/PLAN.md](docs/PLAN.md)
Agents as a team: lifecycle, merge queue, billing and a new shell42- Demo walk-through: [docs/DEMO.md](docs/DEMO.md)
API and MCP server, Rust identity service, registration, site redesign43
44## Status
45
46Working today:
47
OAuth 2.1 sign-in for MCP clients and other applications48- Accounts with email verification and password reset. Applications sign
49 in through the browser with OAuth 2.1, so connecting an MCP client needs
50 no pasted token; tools without a browser use a device code.
Agents as a team: lifecycle, merge queue, billing and a new shell51- Workspaces that own repositories, with members and roles. Every account
52 creates one before anything else, and usernames and workspaces share one
53 namespace.
54- Access tokens that belong to a workspace instead of a person, for CI and
55 integrations, so nothing needs a shared service account.
Issues and pull requests replace intents and attempts56- Public and private repositories, and git over HTTPS, including creating a
57 repository by pushing to it.
Fast pages, required checks on the branch, self-hosted runners, honest incidents58- Issues with labels and comments; a description can say what done means,
59 under a Definition of done.
Pull requests from branches60- Pull requests with a diff and a recorded agent session: in a
61 copy-on-write fork, which is how agents work, or from a branch pushed to
62 the repository. Several can be made for one issue.
Fast pages, required checks on the branch, self-hosted runners, honest incidents63- Checks: the repository's workflows run on every pull request, a
64 person's or an agent's, and report a check each. The default branch
65 names the required checks a merge needs; an agent whose change fails a
66 check is sent back with the failing jobs' logs. A repository with no
67 workflows gets a starter CI workflow in one click.
Acceptance checks in sandboxes, line comments and review verdicts68- Review: comments on lines of a change, and approve or request-changes
69 verdicts, from people and from agents.
Agents as a team: lifecycle, merge queue, billing and a new shell70- Overlap: each pull request shows which others in progress change the
71 same files, while the work is still going on.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily72- Catch-up: when `main` has moved under a pull request, g1t merges it in,
73 and a g1t agent resolves any conflict.
Agents as a team: lifecycle, merge queue, billing and a new shell74- Reviews written by a g1t agent, on request: line comments, a summary and
75 a verdict.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily76- Importing a public repository from any git host by its address, and
77 public or private repositories through g1t's GitHub App, imported once,
78 mirrored, or pushed back to GitHub.
Issues and pull requests replace intents and attempts79- Merging: lands a pull request on `main`, closes its issue naming the pull
80 request that resolved it, and closes the others for that issue as
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily81 superseded. When `main` has moved, the pull request is brought up to date
82 first, or refused where the repository requires that, so no commit is
83 lost.
Issues and pull requests replace intents and attempts84- g1t agents: g1t's own agents working on an issue in sandboxes on
README says what is working today; the free allowance says what it covers85 Cloudflare Containers, seeing each pull request through checks, an
86 agent's review, revisions and catch-up.
87- Outcomes: a brief planned into issues with dependencies, which agents
88 take up as their dependencies land.
89- The merge queue: pull requests tested together with what is ahead of
90 them before they land, with failures sent back to the agent that wrote
91 them. Required approvals and checks per repository.
92- Checks in detail on every pull request, and conflicts worked out on
93 every push, before a merge is tried.
94- Agents as records: every run with its live steps, cost and session, Stop
95 and Message, and memory at two levels (project and workspace) that
96 agents write and read.
97- Projects with deployments on g1t.page: a preview for every pull request,
98 production on merge, dependencies between projects, custom domains.
99- GitHub Actions workflows from `.g1t/workflows`, secrets and variables,
100 webhooks and integrations (Sentry, Datadog, Jira, Linear).
101- Profiles, workspaces with display names, icons and renameable slugs.
102- Usage billing with no seats: what it costs g1t plus a markup, a public
103 price book, usage limits and itemised invoices.
Issues and pull requests replace intents and attempts104- A REST API, an OpenAPI document and an MCP server over the same operations.
API and MCP server, Rust identity service, registration, site redesign105- An event bus: every state change is published, logged and delivered to
106 subscribers.
107
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily108Not built yet: what the Soon pages in each project's menu describe. Git
109over SSH waits on inbound TCP on port 22, which on Cloudflare
Say why git over SSH is not on yet110means Workers inbound TCP, a beta g1t has applied for and is waiting on.
111Use HTTPS until then. See the build order in the plan.
API and MCP server, Rust identity service, registration, site redesign112
113## Try it
114
115```sh
OAuth 2.1 sign-in for MCP clients and other applications116# 1. Create an account and a workspace at https://g1t.sh/register.
API and MCP server, Rust identity service, registration, site redesign117
OAuth 2.1 sign-in for MCP clients and other applications118# 2. Connect Claude Code, then run /mcp in it to sign in through your browser.
119claude mcp add --transport http g1t https://mcp.g1t.sh
API and MCP server, Rust identity service, registration, site redesign120
Issues and pull requests replace intents and attempts121# 3. Ask it to open a pull request for an open issue.
API and MCP server, Rust identity service, registration, site redesign122```
123
Issues and pull requests replace intents and attempts124[Getting started](https://docs.g1t.sh/quickstart/) walks through this in
125full. An assistant can do it for you from <https://g1t.sh/llms.txt>.
API and MCP server, Rust identity service, registration, site redesign126
127## Layout
128
129| Path | What it is |
130| --- | --- |
131| `apps/web` | The site: server-rendered React on a Worker. Holds no data. |
Issues and pull requests replace intents and attempts132| `apps/docs` | The documentation site, with the API explorer. |
API and MCP server in Rust; a public index at the API root133| `apps/api` | REST API and MCP server. Rust. |
Issues and pull requests replace intents and attempts134| `services/identity` | Accounts, workspaces, sessions, keys and tokens. Rust. |
135| `services/repos` | Repository registry, contents, forks, diffs, landing, git over HTTPS. Rust. |
Acceptance checks in sandboxes, line comments and review verdicts136| `services/work` | Issues, pull requests, reviews, check runs and sessions. Rust. |
Events service in Rust, with RFC 3339 times and accurate push events137| `services/events` | The event bus and its log. Rust. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily138| `services/search` | Site-wide search and Explore. Rust. |
139| `services/billing` | Usage, the price book, limits, invoices and payments. Rust. |
140| `services/actions` | GitHub Actions workflows, runs, caches and self-hosted runners. Rust. |
141| `services/security` | Push protection findings, history scanning and dependency upkeep. Rust. |
142| `services/integrations` | Model providers, alerts, trackers and the GitHub App. Rust. |
143| `services/webhooks` | Webhook deliveries. Rust. |
144| `services/runner` | Starts sandboxes: for g1t agents, workflow jobs and the merge queue. TypeScript. |
145| `services/projects` | Projects and the dependencies between them. TypeScript. |
146| `services/deployments` | Builds, previews and production on `g1t.page`. TypeScript. |
147| `services/pages` | Serves every app deployed on `g1t.page`, and custom domains. TypeScript. |
148| `services/models` | The model proxy at `models.g1t.sh`. TypeScript. |
149| `services/context` | The context hub: catalog, search and scorecards. TypeScript. |
150| `services/og` | Social cards at `og.g1t.sh`: a PNG per page, showing only what anyone may see. TypeScript. |
151| `apps/status` | `status.g1t.sh`. TypeScript. |
152| `apps/sudo` | g1t's own staff console. |
Fast pages, required checks on the branch, self-hosted runners, honest incidents153| `crates/runner` | The program inside a sandbox: runs an agent, a workflow job or a merge queue build, and reports back. Rust. |
API and MCP server, Rust identity service, registration, site redesign154| `crates/contracts` | Types and service interfaces for the Rust services. |
155| `crates/kit` | Plumbing shared by Rust services on Workers. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily156| `crates/actions` | Reads workflows and evaluates their expressions. Rust. |
157| `crates/scan` | Secret and lockfile scanning, shared by services. Rust. |
158| `crates/secrets` | Secrets at rest and signatures. Rust. |
API and MCP server, Rust identity service, registration, site redesign159| `crates/sshd` | Git over SSH, bridged to Artifacts. Not deployed yet. |
160| `packages/contracts` | The same interfaces for TypeScript callers. |
Issues and pull requests replace intents and attempts161| `packages/theme` | Design tokens and the logo, shared by the site and the docs. |
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily162| `deploy` | `stack.jsonc`, every deployable part and its resources; `self-host`, the Docker Compose version. |
API and MCP server, Rust identity service, registration, site redesign163
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily164Each service is its own Worker, and each one that keeps data has its own
165database. They call each other through service bindings and react to each
166other through events. The core services (accounts, repositories, work,
167events, billing, Actions, security and the API) are written in Rust; the
168rest are the web apps and the Workers marked TypeScript above.
API and MCP server, Rust identity service, registration, site redesign169
170## Run your own
171
172You need a Cloudflare account on the Workers Paid plan (Artifacts requires
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily173it), Node 22.22 or newer (`engines` in `package.json`; g1t is built on
174Node 24), Rust with the `wasm32-unknown-unknown` target, and
Issues and pull requests replace intents and attempts175Docker to build the sandbox image.
API and MCP server, Rust identity service, registration, site redesign176
177```sh
178npm install
179npx wrangler login
180```
181
182Then, once:
183
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily1841. Create the resources each part needs: D1 databases, queues, KV
185 namespaces, R2 buckets and the Artifacts namespace (`npx wrangler d1
186 create <name>`, `npx wrangler queues create <name>`, and so on), and set
187 each part's secrets. `deploy/stack.jsonc` lists them all.
API and MCP server, Rust identity service, registration, site redesign1882. Put your own `account_id`, database ids and hostnames in each
189 `wrangler.jsonc`.
Deploy scripts live in the repository1903. For [Deployments](https://docs.g1t.sh/guides/deployments/), which needs
191 the Workers for Platforms add-on and a zone for apps:
192 `scripts/setup-deployments.sh`.
API and MCP server, Rust identity service, registration, site redesign193
Deploy scripts live in the repository194Deploy everything, migrations first, in dependency order:
API and MCP server, Rust identity service, registration, site redesign195
196```sh
Deploy scripts live in the repository197scripts/deploy.sh
API and MCP server, Rust identity service, registration, site redesign198```
199
Deploy scripts live in the repository200Or only what changed, still in order: `scripts/deploy.sh billing web`.
201Both use your `wrangler login`, not a token in `.env`.
202
API and MCP server, Rust identity service, registration, site redesign203Create the first account by registering on your site, or with
204`node services/identity/scripts/create-user.mjs <username>`.
205
206## License
207
208[MIT](LICENSE)