g1t/services/billing/src/storage.rs

408 lines18,873 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put1//! Usage other services meter through the month, charged once it is over:
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look2//! security scans, search embeddings, and two billing measures itself each
3//! day: private repository storage and git operations.
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put4//!
5//! Each reports what it cost g1t so far this month (`note_pending`), so the
6//! workspace's limit counts it as it happens. When the month is over,
7//! billing charges it once: at cost plus the margin, on the account's
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look8//! terms, after the plan's included usage and the trial credit (see
9//! `credits`), dated the month's last second so it falls in that month's
10//! statement and invoice.
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put11//!
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas12//! The forge is free for every workspace up to the same amounts, on the
13//! plan or not; past them, a workspace on the plan pays at cost plus the
14//! margin and is never refused or slowed, and a free workspace is never
15//! charged but is held to them.
16//!
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look17//! **Git operations.** Cloudflare Artifacts charges g1t $0.15 per 1,000
18//! operations (clones, fetches, pushes) from 2026-10-14. The repos service
19//! counts those through g1t's git endpoints. Every workspace has
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas20//! `GIT_OPERATIONS_INCLUDED` (50,000) a month free; past it, the plan pays
21//! at cost plus the margin, and a free workspace is slowed down instead
22//! (the repos service's `GIT_OPERATIONS_FREE_CAP`, the same number).
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look23//!
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put24//! **Storage.** The git store does not report a repository's size, so the
25//! repos service counts the packs pushed through g1t's git endpoints (see
26//! `g1t_contracts::repos::StorageArgs`): a lower bound. Each day billing
27//! records what each workspace's private repositories hold and what is
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas28//! free that day (`FREE_PRIVATE_STORAGE_BYTES`, 1 GB, for everyone). Like
29//! Cloudflare's own storage billing, a month's GB-months are the days'
30//! amounts past the free one, added up and divided by 30, and only the
31//! plan is charged for them. A free workspace is never charged for
32//! storage: pushes to its private repositories stop once they hold its
33//! free amount. Public repositories are never charged.
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put34
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look35use g1t_contracts::billing::PlanKind;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put36use g1t_contracts::new_id;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look37use g1t_contracts::repos::{GitOperationsArgs, StorageArgs, WorkspaceGitOperations, WorkspaceStorage};
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put38use g1t_contracts::time::rfc3339;
39use g1t_kit::now_ms;
40use serde::Deserialize;
41use worker::Result;
42
43use crate::credits::{self, Drawn, Eligible};
44use crate::{Billing, optional};
45
46/// Sources billing charges itself when the month is over.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look47pub(crate) const CHARGED_HERE: [&str; 4] = ["security", "context", "storage", "git"];
48
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas49/// What Artifacts charges g1t, when the price book cannot be read: $0.50
50/// a GB-month of storage, and $0.15 per 1,000 git operations.
51pub(crate) const STORAGE_MICROS_PER_GB_MONTH: i64 = 500_000;
52pub(crate) const GIT_MICROS_PER_THOUSAND: i64 = 150_000;
53
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look54/// When Cloudflare starts charging for Artifacts operations: none before
55/// count.
56pub(crate) const GIT_BILLING_STARTS: &str = "2026-10-14T00";
57
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas58/// What git operations past the free amount cost g1t, at
59/// `micros_per_thousand`: nothing up to it.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look60pub(crate) fn git_cost(operations: u64, included: u64, micros_per_thousand: f64) -> i64 {
61 let past = operations.saturating_sub(included);
62 (past as f64 * micros_per_thousand / 1000.0).ceil() as i64
63}
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put64
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look65/// The first hour of `month` to count git operations from.
66pub(crate) fn git_since(month: &str) -> String {
67 let start = format!("{month}-01T00");
68 if start.as_str() < GIT_BILLING_STARTS { GIT_BILLING_STARTS.to_owned() } else { start }
69}
70
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put71/// A gigabyte, as Cloudflare bills storage.
72pub(crate) const GB: f64 = 1_000_000_000.0;
73
74/// GB-months from a month's daily measures, each `(private, free)` bytes:
75/// what was past the free amount each day, over 30 days.
76pub(crate) fn storage_gb_months(days: &[(i64, i64)]) -> f64 {
77 days.iter().map(|(private, free)| (private - free).max(0) as f64).sum::<f64>() / GB / 30.0
78}
79
80/// What `gb_months` cost g1t at `micros_per_gb_month`, rounded up.
81pub(crate) fn storage_cost(gb_months: f64, micros_per_gb_month: f64) -> i64 {
82 (gb_months * micros_per_gb_month).ceil() as i64
83}
84
85/// What a source is called on the statement.
86pub(crate) fn title(source: &str) -> &'static str {
87 match source {
88 "security" => "Security scans",
89 "context" => "Search embeddings",
90 "storage" => "Private repository storage past the free amount",
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas91 "git" => "Git operations past the free amount",
92 "domains" => "Custom domains",
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put93 _ => "Metered usage",
94 }
95}
96
97/// A usage entry to put on the ledger.
98pub(crate) struct UsageLine<'a> {
99 pub workspace: &'a str,
100 /// What the workspace is charged, after terms and what paid for it.
101 pub charged: i64,
102 pub description: &'a str,
103 pub repo: Option<&'a str>,
104 pub task: &'a str,
105 pub cost: i64,
106 pub reference: &'a str,
107 pub created_at: &'a str,
108 pub drawn: Drawn,
109}
110
111impl Billing {
112 /// Puts a usage entry on the ledger and takes it off the balance, as
113 /// one write.
114 pub(crate) async fn post_usage(&self, line: UsageLine<'_>) -> Result<()> {
115 self.db
116 .batch(vec![
117 self.db
118 .prepare(
119 "INSERT INTO ledger
120 (id, workspace, kind, amount_micros, description, repo, task, cost_micros, reference,
121 created_at, billed_to, credit_micros, trial_micros, oss_micros)
122 VALUES (?, ?, 'usage', ?, ?, ?, ?, ?, ?, ?, 'g1t', ?, ?, ?)",
123 )
124 .bind(&[
125 new_id("led", now_ms()).into(),
126 line.workspace.into(),
127 (-(line.charged as f64)).into(),
128 line.description.into(),
129 optional(line.repo),
130 line.task.into(),
131 (line.cost as f64).into(),
132 line.reference.into(),
133 line.created_at.into(),
134 (line.drawn.credit as f64).into(),
135 (line.drawn.trial as f64).into(),
136 (line.drawn.oss as f64).into(),
137 ])?,
138 self.db
139 .prepare(
140 "INSERT INTO accounts (workspace, balance_micros, created_at) VALUES (?1, ?2, ?3)
141 ON CONFLICT (workspace) DO UPDATE SET balance_micros = balance_micros + ?2",
142 )
143 .bind(&[line.workspace.into(), (-(line.charged as f64)).into(), rfc3339(now_ms()).into()])?,
144 ])
145 .await?;
146 Ok(())
147 }
148
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas149 /// Writes down what a source cost g1t so far in `month`, what it will
150 /// be charged, and how much of it there was (`detail`, for the Billing
151 /// page), replacing the last figure.
152 pub(crate) async fn set_pending(
153 &self,
154 workspace: &str,
155 source: &str,
156 month: &str,
157 cost_micros: i64,
158 detail: Option<&str>,
159 ) -> Result<()> {
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put160 let charge = credits::with_margin(cost_micros, self.margin_percent);
161 self.db
162 .prepare(
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas163 "INSERT INTO pending_usage (workspace, source, month, charge_micros, cost_micros, updated_at, detail)
164 VALUES (?1, ?2, ?3, ?4, ?5, ?6, ?7)
165 ON CONFLICT (workspace, source, month) DO UPDATE SET
166 charge_micros = ?4, cost_micros = ?5, updated_at = ?6, detail = COALESCE(?7, detail)",
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put167 )
168 .bind(&[
169 workspace.to_lowercase().into(),
170 source.into(),
171 month.into(),
172 (charge as f64).into(),
173 (cost_micros.max(0) as f64).into(),
174 rfc3339(now_ms()).into(),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas175 optional(detail),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put176 ])?
177 .run()
178 .await?;
179 Ok(())
180 }
181
182 /// Charges every month that is over for the usage billing charges
183 /// itself, once each.
184 pub(crate) async fn charge_pending(&self) -> Result<()> {
185 if self.stripe.is_none() {
186 return Ok(());
187 }
188 let now = rfc3339(now_ms());
189 let current = credits::month_of(&now);
190 #[derive(Deserialize)]
191 struct Row {
192 workspace: String,
193 source: String,
194 month: String,
195 cost_micros: Option<i64>,
196 }
197 let marks = CHARGED_HERE.iter().map(|s| format!("'{s}'")).collect::<Vec<_>>().join(", ");
198 let due = self
199 .db
200 .prepare(format!(
201 "SELECT workspace, source, month, cost_micros FROM pending_usage
202 WHERE month < ? AND charged_at IS NULL AND source IN ({marks}) ORDER BY month LIMIT 50"
203 ))
204 .bind(&[current.as_str().into()])?
205 .all()
206 .await?
207 .results::<Row>()?;
208 for row in due {
209 // Claimed first, so two crons never charge it twice.
210 let claimed = self
211 .db
212 .prepare(
213 "UPDATE pending_usage SET charged_at = ?1
214 WHERE workspace = ?2 AND source = ?3 AND month = ?4 AND charged_at IS NULL RETURNING workspace",
215 )
216 .bind(&[now.as_str().into(), row.workspace.as_str().into(), row.source.as_str().into(), row.month.as_str().into()])?
217 .first::<serde_json::Value>(None)
218 .await?;
219 let cost = row.cost_micros.unwrap_or(0);
220 if claimed.is_none() || cost <= 0 {
221 continue;
222 }
223 let base = credits::with_margin(cost, self.margin_percent);
224 let (charge, terms_note) = self.charged(&row.workspace, base).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look225 let drawn = self.draw(&row.workspace, charge, &row.month, &Eligible { trial: true, repo: None, cover_rest: false }).await?;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put226 let detail = if row.source == "storage" {
227 let gb_months = self.gb_months(&row.workspace, &row.month).await?;
228 format!(": {gb_months:.2} GB-months")
229 } else {
230 String::new()
231 };
232 let description = format!("{} in {}{detail}{terms_note}{}", title(&row.source), row.month, drawn.note());
233 let reference = format!("{}/{}/{}", row.source, row.workspace, row.month);
234 let created_at = credits::month_end(&row.month);
235 self.post_usage(UsageLine {
236 workspace: &row.workspace,
237 charged: charge - drawn.total(),
238 description: &description,
239 repo: None,
240 task: &row.source,
241 cost,
242 reference: &reference,
243 created_at: &created_at,
244 drawn,
245 })
246 .await?;
247 }
248 Ok(())
249 }
250
251 /// A workspace's private storage past the free amount in `month`.
252 async fn gb_months(&self, workspace: &str, month: &str) -> Result<f64> {
253 #[derive(Deserialize)]
254 struct Day {
255 private_bytes: i64,
256 free_bytes: i64,
257 }
258 let days = self
259 .db
260 .prepare("SELECT private_bytes, free_bytes FROM storage_days WHERE workspace = ? AND substr(day, 1, 7) = ?")
261 .bind(&[workspace.into(), month.into()])?
262 .all()
263 .await?
264 .results::<Day>()?;
265 Ok(storage_gb_months(&days.iter().map(|d| (d.private_bytes, d.free_bytes)).collect::<Vec<_>>()))
266 }
267
268 /// Once a day: what each workspace's private repositories hold, and
269 /// what this month's storage past the free amount comes to so far.
270 pub(crate) async fn measure_storage(&self) -> Result<()> {
271 let Some(repos) = &self.repos else { return Ok(()) };
272 let list: Vec<WorkspaceStorage> = g1t_kit::call(repos, "storage", &StorageArgs {}).await?;
273 let now = rfc3339(now_ms());
274 let (day, month) = (&now[..10], credits::month_of(&now));
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas275 let price = self.price("private_storage").await?.map_or(STORAGE_MICROS_PER_GB_MONTH as f64, |(cost, _)| cost);
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put276 for workspace in list {
277 let slug = workspace.namespace.to_lowercase();
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look278 let plan = self.has_plan(&slug).await?;
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas279 // The same free amount for everyone: the plan pays past it.
280 let free = self.plans.free_storage_bytes;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put281 self.db
282 .prepare(
283 "INSERT INTO storage_days (workspace, day, private_bytes, free_bytes) VALUES (?1, ?2, ?3, ?4)
284 ON CONFLICT (workspace, day) DO UPDATE SET private_bytes = ?3, free_bytes = ?4",
285 )
286 .bind(&[slug.as_str().into(), day.into(), (workspace.private_bytes as f64).into(), (free as f64).into()])?
287 .run()
288 .await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look289 // Only the plan pays for storage past its amount. A free
290 // workspace is never charged: the repos service stops its pushes
291 // to private repositories once it is full (see git_ops.rs there).
292 let gb_months = if plan { self.gb_months(&slug, &month).await? } else { 0.0 };
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put293 if gb_months > 0.0 {
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas294 let detail = format!("{gb_months:.2} GB-months past the free {}", crate::features::bytes(free));
295 self.set_pending(&slug, "storage", &month, storage_cost(gb_months, price), Some(&detail)).await?;
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put296 }
297 }
298 Ok(())
299 }
300
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look301 /// Git operations this month for each workspace, from the repos
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas302 /// service: what is past the free amount goes to the month's pending
303 /// usage for workspaces on the plan, which are never slowed or refused
304 /// for them. Free workspaces are never charged for them.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look305 pub(crate) async fn measure_git(&self) -> Result<()> {
306 let Some(repos) = &self.repos else { return Ok(()) };
307 let month = credits::month_of(&rfc3339(now_ms()));
308 let list: Vec<WorkspaceGitOperations> =
309 g1t_kit::call(repos, "git_operations", &GitOperationsArgs { since: Some(git_since(&month)), month: month.clone(), namespace: None }).await?;
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas310 let price = self.price("git_operations").await?.map_or(GIT_MICROS_PER_THOUSAND as f64, |(cost, _)| cost);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look311 for workspace in list {
312 let slug = workspace.namespace.to_lowercase();
313 if self.plan_kind(&slug).await? == PlanKind::Free {
314 continue;
315 }
316 let cost = git_cost(workspace.operations, self.plans.git_included, price);
317 if cost > 0 {
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas318 let detail = format!(
319 "{} operations, {} of them free",
320 crate::features::thousands(workspace.operations),
321 crate::features::thousands(self.plans.git_included)
322 );
323 self.set_pending(&slug, "git", &month, cost, Some(&detail)).await?;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look324 }
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put325 }
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look326 Ok(())
327 }
328
329 /// The workspace's git operations this month, as last measured.
330 pub(crate) async fn git_operations_this_month(&self, workspace: &str) -> Result<u64> {
331 let Some(repos) = &self.repos else { return Ok(0) };
332 let month = credits::month_of(&rfc3339(now_ms()));
333 let list: Result<Vec<WorkspaceGitOperations>> =
334 g1t_kit::call(repos, "git_operations", &GitOperationsArgs { since: Some(format!("{month}-01T00")), month, namespace: Some(workspace.to_lowercase()) }).await;
335 Ok(list
336 .ok()
337 .and_then(|list| list.into_iter().find(|w| w.namespace.eq_ignore_ascii_case(workspace)))
338 .map_or(0, |w| w.operations))
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put339 }
340}
341
342#[cfg(test)]
343mod tests {
344 use super::*;
345
346 #[test]
347 fn storage_past_the_free_amount_is_counted_by_the_day() {
348 // 3 GB private with 1 GB free, every day of a 30-day month: 2 GB-months.
349 let month = vec![(3_000_000_000, 1_000_000_000); 30];
350 assert!((storage_gb_months(&month) - 2.0).abs() < 1e-9);
351 // Under the free amount: nothing.
352 assert_eq!(storage_gb_months(&[(500_000_000, 1_000_000_000); 30]), 0.0);
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas353 // The plan has the same 1 GB free: 11 GB on it all month is 10
354 // GB-months, $5.00 to g1t, $6.00 charged, from its included usage.
355 let days = vec![(11_000_000_000, 1_000_000_000); 30];
356 assert!((storage_gb_months(&days) - 10.0).abs() < 1e-9);
357 assert_eq!(credits::with_margin(storage_cost(storage_gb_months(&days), STORAGE_MICROS_PER_GB_MONTH as f64), 20), 6_000_000);
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put358 // Ten days of 4 GB past it: a third of 4 GB-months.
359 let days = vec![(5_000_000_000, 1_000_000_000); 10];
360 assert!((storage_gb_months(&days) - 4.0 / 3.0).abs() < 1e-9);
361 }
362
363 #[test]
364 fn storage_is_priced_at_cloudflares_rate_plus_the_margin() {
365 // $0.50 a GB-month to g1t: 2 GB-months cost $1.00, charged $1.20.
366 let cost = storage_cost(2.0, 500_000.0);
367 assert_eq!(cost, 1_000_000);
368 assert_eq!(credits::with_margin(cost, 20), 1_200_000);
369 // A fraction of a millionth rounds up.
370 assert_eq!(storage_cost(0.000_000_001, 500_000.0), 1);
371 }
372
373 #[test]
374 fn embeddings_and_scans_are_charged_at_cost_plus_the_margin() {
375 // 10 million tokens at $0.067 a million: $0.67, charged $0.804.
376 assert_eq!(credits::with_margin(670_000, 20), 804_000);
377 assert_eq!(title("context"), "Search embeddings");
378 assert_eq!(title("security"), "Security scans");
379 assert!(CHARGED_HERE.contains(&"storage") && !CHARGED_HERE.contains(&"deployments"));
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look380 assert!(CHARGED_HERE.contains(&"git"));
381 }
382
383 #[test]
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas384 fn git_operations_are_charged_past_the_free_amount_at_cloudflares_price() {
385 // $0.15 per 1,000 to g1t; 50,000 a month free for everyone.
386 let per_thousand = GIT_MICROS_PER_THOUSAND as f64;
387 let free = crate::credits::Config::default().git_included;
388 assert_eq!(free, 50_000);
389 assert_eq!(git_cost(49_000, free, per_thousand), 0);
390 assert_eq!(git_cost(50_000, free, per_thousand), 0);
391 // A workspace on the plan pushes on past it, and pays: 70,000
392 // operations are 20,000 past it, $3.00 to g1t, $3.60 charged.
393 assert_eq!(git_cost(70_000, free, per_thousand), 3_000_000);
394 assert_eq!(credits::with_margin(git_cost(70_000, free, per_thousand), 20), 3_600_000);
395 // A million in a month: no cap, $142.50 to g1t.
396 assert_eq!(git_cost(1_000_000, free, per_thousand), 142_500_000);
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look397 // One past it: a fraction of a cent, rounded up to a millionth.
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas398 assert_eq!(git_cost(50_001, free, per_thousand), 150);
399 assert_eq!(title("git"), "Git operations past the free amount");
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look400 }
401
402 #[test]
403 fn git_operations_count_from_when_cloudflare_starts_charging() {
404 assert_eq!(git_since("2026-10"), "2026-10-14T00");
405 assert_eq!(git_since("2026-11"), "2026-11-01T00");
406 assert_eq!(git_since("2026-09"), "2026-10-14T00");
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put407 }
408}