Skip to content
125 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Automations: rules in .g1t/automations that act when something happens1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-runner",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 "main": "./src/index.ts",
7 "workers_dev": false,
Fast pages, required checks on the branch, self-hosted runners, honest incidents8 // One image (the base plus the runner binary), on three machine sizes.
9 // scripts/deploy.mjs deploys with each image set to the reference it
The docs folder is gone, and what it held lives where people read it: how a self-hosted g1t runs and how to deploy g1t to Cloudflare are pages on docs.g1t.sh under Run g1t yourself, and speed, rate limits and operating g1t.sh are sections of CONTRIBUTING.md; code that cited a file in docs/ now points to the page or section that covers it, or says what it means itself, and applied migrations and the runner images are left as they were.10 // built and pushed ("The runner's images" in
11 // docs.g1t.sh/guides/deploy-to-cloudflare/), so a deploy builds
12 // nothing; "./Dockerfile" here is for building by hand.
Automations: rules in .g1t/automations that act when something happens13 "containers": [
14 {
15 "class_name": "AttemptSandbox",
16 "image": "./Dockerfile",
17 "instance_type": "standard-1",
18 "max_instances": 20,
19 // A deploy replaces sandboxes. Ones that are busy are given this
20 // long, in seconds, to finish first, so shipping g1t does not
21 // kill agents in the middle of their work.
22 "rollout_active_grace_period": 7200
Fast pages, required checks on the branch, self-hosted runners, honest incidents23 },
24 {
25 // Workflow jobs with `runs-on: g1t-2core`: 2 vCPU, 8 GiB, 16 GB.
26 "class_name": "Sandbox2Core",
27 "image": "./Dockerfile",
28 "instance_type": "standard-3",
29 "max_instances": 10,
30 "rollout_active_grace_period": 7200
31 },
32 {
33 // Workflow jobs with `runs-on: g1t-4core`: 4 vCPU, 12 GiB, 20 GB.
34 "class_name": "Sandbox4Core",
35 "image": "./Dockerfile",
36 "instance_type": "standard-4",
37 "max_instances": 10,
38 "rollout_active_grace_period": 7200
Automations: rules in .g1t/automations that act when something happens39 }
40 ],
41 "durable_objects": {
Fast pages, required checks on the branch, self-hosted runners, honest incidents42 "bindings": [
43 { "name": "SANDBOX", "class_name": "AttemptSandbox" },
44 { "name": "SANDBOX_2CORE", "class_name": "Sandbox2Core" },
45 { "name": "SANDBOX_4CORE", "class_name": "Sandbox4Core" }
46 ]
Automations: rules in .g1t/automations that act when something happens47 },
Fast pages, required checks on the branch, self-hosted runners, honest incidents48 "migrations": [
49 { "tag": "v1", "new_sqlite_classes": ["AttemptSandbox"] },
50 { "tag": "v2", "new_sqlite_classes": ["Sandbox2Core", "Sandbox4Core"] }
51 ],
Automations: rules in .g1t/automations that act when something happens52 "services": [
53 { "binding": "IDENTITY", "service": "g1t-identity" },
54 { "binding": "REPOS", "service": "g1t-repos" },
55 { "binding": "WORK", "service": "g1t-work" },
56 { "binding": "BILLING", "service": "g1t-billing" },
GitHub Actions on g1t, part two: running workflows57 { "binding": "INTEGRATIONS", "service": "g1t-integrations" },
Deployments: a preview for every pull request, production on g1t.page58 { "binding": "ACTIONS", "service": "g1t-actions" },
Project dependencies: addresses, preview stacks, Affects, and agents who know59 { "binding": "DEPLOYMENTS", "service": "g1t-deployments" },
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API60 { "binding": "PROJECTS", "service": "g1t-projects" },
61 // The context hub: the Context section every agent run starts with.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look62 { "binding": "CONTEXT", "service": "g1t-context" },
63 // The event bus: abuse.flagged, when a sandbox looks like it is mining.
64 { "binding": "EVENTS", "service": "g1t-events" }
Automations: rules in .g1t/automations that act when something happens65 ],
66 // A sweep for lifecycle steps whose trigger was missed or whose sandbox
Merge branch 'worktree-agent-ac5b181a013e54348'67 // died before reporting, which also starts queued nightly backups.
Automations: rules in .g1t/automations that act when something happens68 "triggers": { "crons": ["*/5 * * * *"] },
69 // Events it reacts to: a pull request ready for review, or its head moving.
70 "queues": {
Merge branch 'worktree-agent-ad8a36dfcd4176015' into spend-guardrails71 "consumers": [{ "queue": "g1t-events-runner", "max_batch_size": 20, "max_batch_timeout": 1, "max_retries": 3, "dead_letter_queue": "g1t-events-dlq" }]
Automations: rules in .g1t/automations that act when something happens72 },
73 "vars": {
74 // Each workspace chooses where its agents' model spend goes: its own
75 // provider (under Integrations) or g1t's hosted models, paid from its
76 // credit. While billing takes no real money, hosted models are open
77 // only to these workspaces; once it does, to every workspace.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look78 "HOSTED_AGENT_WORKSPACES": "flagon-io",
Merge branch 'model-routing'79 // How g1t routes agent work: "Auto" (AgentRouting and route in
80 // src/model-env.ts). Nobody assigning an agent has to choose; a workspace
Merge branch 'main' into actions-toolkit-oidc-artifacts81 // can still choose a tier per kind of work under Integrations. Staff
82 // choose each tier's model, the background model and each job's tier and
83 // effort in sudo (Agents & models; billing's model_defaults), which the
84 // runner reads once a minute and puts on top of this. So "tiers", "tasks"
85 // and "effort" here apply only while billing cannot be read; the labels,
86 // change sizes, "frontierAfter" and "learning" always do. "tiers": the
Merge branch 'model-routing'87 // catalogue, the model behind small (fast), large (standard) and frontier
88 // (most capable); "modelName" is shown to people, "model" is sent to the
89 // provider, "price" (dollars per million tokens) is for estimates only.
90 // "tasks": the tier each kind of job starts on, or "change" to size the
91 // change a review reads ("smallChange" or less and nothing sensitive: small;
92 // more than "largeChange": frontier). "frontierLabels", "largeLabels" and
93 // "smallLabels" move work by its issue's labels. A failed attempt goes one
94 // tier up and "frontierAfter" failures in a row to frontier; "learning"
95 // steps work down or up by the repository's own recent runs of the kind.
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9796 "AGENT_ROUTING": "{\"tiers\":{\"small\":{\"modelName\":\"Claude Haiku 5.5\",\"model\":\"claude-haiku-5-5\",\"price\":{\"input\":0.1,\"output\":0.5,\"cacheRead\":0.01,\"cacheWrite\":0.125}},\"large\":{\"modelName\":\"Claude Sonnet 5.5\",\"model\":\"claude-sonnet-5-5\",\"price\":{\"input\":2,\"output\":10,\"cacheRead\":0.1,\"cacheWrite\":2.5}},\"frontier\":{\"modelName\":\"Claude Opus 5.5\",\"model\":\"claude-opus-5-5\",\"price\":{\"input\":4,\"output\":20,\"cacheRead\":0.2,\"cacheWrite\":5}}},\"tasks\":{\"implement\":\"large\",\"revise\":\"large\",\"answer\":\"small\",\"review\":\"change\",\"update\":\"small\",\"plan\":\"small\"},\"effort\":{\"plan\":\"high\",\"answer\":\"medium\",\"update\":\"low\"},\"smallChange\":{\"files\":10,\"lines\":200},\"largeChange\":{\"files\":60,\"lines\":3000},\"largeLabels\":[\"security\"],\"frontierLabels\":[\"architecture\"],\"smallLabels\":[\"documentation\",\"docs\",\"typo\"],\"frontierAfter\":2,\"learning\":{\"window\":20,\"minRuns\":5,\"stepDownAt\":0.9,\"stepUpAt\":0.5}}",
Automations: rules in .g1t/automations that act when something happens97 // Where sandboxes send model requests, with a token for their run.
98 // The proxy holds the keys: g1t's gateway's, or the workspace's own.
99 "MODELS_URL": "https://models.g1t.sh",
100 // Set to a Cloudflare AI Gateway id to route model traffic through it.
101 // Used only when MODELS_URL is unset.
102 "AI_GATEWAY_ID": "g1t",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API103 "CLOUDFLARE_ACCOUNT_ID": "1e6f2cffa3f445920836e8ebe446bb58",
104 // Guardrails' network list is enforced by starting sandboxes without
105 // internet and passing their HTTP(S) through this Worker. "off" opens
106 // every sandbox's network again, whatever its guardrails say.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look107 "EGRESS": "enforce",
108 // Sandboxes stop themselves when they look like they are mining
109 // (crates/runner abuse.rs). "off" turns the CPU watch off; miners
110 // named in commands are refused either way.
Merge branch 'worktree-agent-ac5b181a013e54348'111 "ABUSE_WATCH": "on",
Merge branch 'main' into actions-toolkit-oidc-artifacts112 // Each workflow job gets a Docker Engine of its own, inside its
113 // sandbox, started the first time a step uses Docker or the job has
114 // `services:` or `container:` (crates/runner docker/). "off" gives
115 // jobs none.
116 "DOCKER": "on",
Merge branch 'worktree-agent-ac5b181a013e54348'117 // Nightly backups (src/backup.ts): each sweep starts this many of the
118 // backups the repos service queued, with at most BACKUPS_RUNNING at
119 // once. "0" starts none.
120 "BACKUPS_PER_SWEEP": "4",
121 "BACKUPS_RUNNING": "6"
Automations: rules in .g1t/automations that act when something happens122 },
Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails123 // Every log kept: few requests, and a failed run must be traceable.
124 "observability": { "enabled": true, "head_sampling_rate": 1 }
Automations: rules in .g1t/automations that act when something happens125}

This file's history is long; its oldest lines are credited to the oldest commit read.