Skip to content
373 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow1// Everything g1t deploys to Cloudflare, in one place. Read by
2// scripts/deploy.mjs (plan, deploy), deploy/self-host/configs.mjs (what a
3// self-hosted installation runs) and the tests in scripts/deploy/.
4// docs/DEPLOYING.md explains each field and how to add a unit.
5//
6// What is written here is what the Wrangler configs cannot say. The rest is
7// read from each unit's wrangler.jsonc, never copied: its D1 databases and
8// migrations, the services it binds to, its KV, R2, queues and routes. The
9// shared crates and packages a unit is built from are read from Cargo's and
10// npm's workspace metadata. `worker` and `d1` are written here too, so the
11// file reads as an inventory, and a test checks they match the configs.
12{
13 // Deployed in this order. A stage starts only when the one before it
14 // succeeded. A unit binds only to units in its own stage or an earlier
15 // one (a test checks it), so new code never calls a service that has
16 // not shipped yet. Within a stage, units go out in parallel.
17 //
18 // migrations: every pending D1 migration, before any code.
19 // core: the services, reached through service bindings.
Chat and workspace agents: channels, DMs and named agents you talk to20 // edge: public endpoints other than the site: API, MCP, g1t.page, status
21 // (models is public too, but in core: agents binds to it).
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow22 // front: the site, sudo and the docs.
23 "stages": ["migrations", "core", "edge", "front"],
24
25 // Names for the resources the configs refer to by id, for setup
26 // commands and the docs. A test checks every KV id in a config is here.
27 "resources": {
28 "kv": {
29 "16a4232cb746418db53782aa068be693": "g1t-actions-blobs",
30 "e627b571f07047e187c03e1fc2b3bbdd": "g1t-avatars",
31 "14bc5c233d4c46a5bbf23b5367cce5fd": "g1t-domains",
32 "be765052d0124c2a935b3db4dff99f1f": "g1t-repos-git-cache"
33 }
34 },
35
36 // Each deployable unit, by short name (`--only events,web`).
37 //
38 // kind: rust-worker (worker-build), ts-worker (Wrangler bundles it),
39 // react-router (vite build first), astro (astro build first).
40 // secrets: names only; set with `npx wrangler secret put NAME` in its folder.
41 // setup: one-time steps no config can say, for a first deploy.
42 // self_host: what deploy/self-host does with it: "run" (in the one
43 // workerd), "off" (bound to the off Worker), "separate" (a
44 // process of its own), or "none".
45 // inputs: files outside its folder it is built from that no workspace
46 // metadata names (a test finds such imports).
Fast pages, required checks on the branch, self-hosted runners, honest incidents47 // image: a Containers image (docs/DEPLOYING.md, "The runner's images"):
48 // dockerfile the image a deploy ships: the base plus the binary
49 // crate the crate that binary is built from (and what it uses)
50 // base { context: the base's folder, lock: the file that
51 // records the base that was pushed }; the base is
52 // rebuilt only when its folder changes
53 // repository where both are pushed in Cloudflare's registry
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow54 "units": {
55 "events": {
56 "path": "services/events",
57 "kind": "rust-worker",
58 "worker": "g1t-events",
59 "d1": { "database": "g1t-events", "migrations": "migrations" },
60 "stage": "core",
61 "secrets": [],
Merge branch 'worktree-agent-ad8a36dfcd4176015' into spend-guardrails62 "setup": [
63 "The dead-letter queue every queue consumer sends what it gave up on to, before any unit that names it deploys: npx wrangler queues create g1t-events-dlq"
64 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow65 "self_host": "run"
66 },
67 "identity": {
68 "path": "services/identity",
69 "kind": "rust-worker",
70 "worker": "g1t-identity",
71 "d1": { "database": "g1t", "migrations": "migrations" },
72 "stage": "core",
73 "secrets": ["GITHUB_APP_CLIENT_SECRET", "IDENTITY_KEY"],
74 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
75 "self_host": "run"
76 },
77 "repos": {
78 "path": "services/repos",
79 "kind": "rust-worker",
80 "worker": "g1t-repos",
81 "d1": { "database": "g1t-repos", "migrations": "migrations" },
82 "stage": "core",
83 "secrets": ["REPOS_KEY"],
Merge branch 'worktree-agent-a1b995daa94e4e1b7'84 "setup": [
85 "The Artifacts namespace `g1t` (the ARTIFACTS binding)",
Merge branch 'worktree-agent-ac5b181a013e54348'86 "The R2 bucket `g1t-git-packs` (GIT_PACKS) with its lifecycle rule: `npx wrangler r2 bucket create g1t-git-packs`, then `npx wrangler r2 bucket lifecycle add g1t-git-packs expire-packs packs/ --expire-days 7 --abort-multipart-days 1`",
87 "The R2 bucket for nightly backups: npx wrangler r2 bucket create g1t-backups"
Merge branch 'worktree-agent-a1b995daa94e4e1b7'88 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow89 "self_host": "run"
90 },
91 "work": {
92 "path": "services/work",
93 "kind": "rust-worker",
94 "worker": "g1t-work",
95 "d1": { "database": "g1t-work", "migrations": "migrations" },
96 "stage": "core",
97 "secrets": [],
98 "self_host": "run"
99 },
100 "search": {
101 "path": "services/search",
102 "kind": "rust-worker",
103 "worker": "g1t-search",
104 "d1": { "database": "g1t-search", "migrations": "migrations" },
105 "stage": "core",
106 "secrets": [],
107 "self_host": "run"
108 },
109 "projects": {
110 "path": "services/projects",
111 "kind": "ts-worker",
112 "worker": "g1t-projects",
113 "d1": { "database": "g1t-projects", "migrations": "migrations" },
114 "stage": "core",
115 "secrets": [],
116 "self_host": "run"
117 },
Chat and workspace agents: channels, DMs and named agents you talk to118 "chat": {
119 "path": "services/chat",
120 "kind": "ts-worker",
121 "worker": "g1t-chat",
122 "d1": { "database": "g1t-chat", "migrations": "migrations" },
123 "stage": "core",
124 "secrets": [],
125 "setup": [
126 "The D1 database, before the first deploy: npx wrangler d1 create g1t-chat, then put its id in services/chat/wrangler.jsonc"
127 ],
128 "self_host": "run"
129 },
Docs: a workspace knowledge base people and agents write together130 // Docs mode's service. Its Worker is g1t-docs-service: g1t-docs is
131 // the documentation site (apps/docs).
132 "docs-service": {
133 "path": "services/docs",
134 "kind": "ts-worker",
135 "worker": "g1t-docs-service",
136 "d1": { "database": "g1t-docs", "migrations": "migrations" },
137 "stage": "core",
138 "secrets": [],
139 "setup": [
140 "The D1 database, before the first deploy: npx wrangler d1 create g1t-docs, then put its id in services/docs/wrangler.jsonc",
Docs know what code they describe; a project's docs folder in Docs; Docs events; files on any S3 store141 "The R2 bucket for files in pages: npx wrangler r2 bucket create g1t-docs-files",
Docs index by meaning: passages of every page and project doc, embedded on save and recalled for agents; hybrid search for people142 "The queue the events service sends it merges and pushes on (pages whose cited code changed, projects' docs): npx wrangler queues create g1t-events-docs. The service also sends its own backfill jobs to it (JOBS)",
143 "The Vectorize index agents recall Docs from: npx wrangler vectorize create g1t-docs --dimensions=768 --metric=cosine, with string metadata indexes on workspace_id and space_id (npx wrangler vectorize create-metadata-index g1t-docs --property-name=<name> --type=string)"
Docs: a workspace knowledge base people and agents write together144 ],
145 "self_host": "run"
146 },
Merge the workspace shell: navigation and phone shell, g1t as orchestrator, agents in roles with audience-checked reads, reactions and custom emoji, live notifications and browser push, the homepage tour (agents 0002, chat 0002)147 "notify": {
148 "path": "services/notify",
149 "kind": "ts-worker",
150 "worker": "g1t-notify",
151 // No D1: each person's feed keeps its own state in its Durable
152 // Object's SQLite storage.
153 "stage": "core",
154 // The private half of the VAPID key pair browser pushes are signed
155 // with; without it, notifications are live in open tabs only.
156 "secrets": ["VAPID_PRIVATE_KEY"],
157 "setup": [
158 "The VAPID key pair for browser push: `node scripts/ops/vapid-keys.mjs` prints both halves and stores nothing. Put the public half in VAPID_PUBLIC_KEY in services/notify/wrangler.jsonc, and the private half with `npx wrangler secret put VAPID_PRIVATE_KEY` in services/notify"
159 ],
160 "self_host": "run"
161 },
Chat and workspace agents: channels, DMs and named agents you talk to162 "agents": {
163 "path": "services/agents",
164 "kind": "ts-worker",
165 "worker": "g1t-agents",
166 "d1": { "database": "g1t-agents", "migrations": "migrations" },
167 "stage": "core",
168 "secrets": [],
169 "setup": [
170 "The D1 database, before the first deploy: npx wrangler d1 create g1t-agents, then put its id in services/agents/wrangler.jsonc"
171 ],
172 // Replies route and gate model work exactly as runs do, with the
173 // runner's own modules: its routing policy and who may use hosted models.
174 "inputs": ["services/runner/src/model-env.ts", "services/runner/src/hosted.ts"],
175 "self_host": "run"
176 },
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow177 "billing": {
178 "path": "services/billing",
179 "kind": "rust-worker",
180 "worker": "g1t-billing",
181 "d1": { "database": "g1t-billing", "migrations": "migrations" },
182 "stage": "core",
Stripe's webhook secret is a Worker secret, STRIPE_WEBHOOK_SECRET, from a destination made in Stripe's dashboard183 "secrets": ["STRIPE_SECRET_KEY", "STRIPE_WEBHOOK_SECRET", "CLOUDFLARE_USAGE_TOKEN"],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow184 "self_host": "run"
185 },
186 "integrations": {
187 "path": "services/integrations",
188 "kind": "rust-worker",
189 "worker": "g1t-integrations",
190 "d1": { "database": "g1t-integrations", "migrations": "migrations" },
191 "stage": "core",
192 "secrets": ["INTEGRATIONS_KEY", "GITHUB_APP_PRIVATE_KEY", "GITHUB_APP_WEBHOOK_SECRET"],
193 "self_host": "run"
194 },
195 "webhooks": {
196 "path": "services/webhooks",
197 "kind": "rust-worker",
198 "worker": "g1t-webhooks",
199 "d1": { "database": "g1t-webhooks", "migrations": "migrations" },
200 "stage": "core",
201 "secrets": ["WEBHOOKS_KEY"],
202 "self_host": "run"
203 },
204 "actions": {
205 "path": "services/actions",
206 "kind": "rust-worker",
207 "worker": "g1t-actions",
208 "d1": { "database": "g1t-actions", "migrations": "migrations" },
209 "stage": "core",
210 "secrets": ["ACTIONS_KEY"],
211 "self_host": "run"
212 },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member213 "packages": {
214 "path": "services/packages",
215 "kind": "rust-worker",
216 "worker": "g1t-packages",
217 "d1": { "database": "g1t-packages", "migrations": "migrations" },
218 "stage": "core",
219 "secrets": ["PACKAGES_TOKEN_SECRET", "R2_ACCESS_KEY_ID", "R2_SECRET_ACCESS_KEY"],
220 "setup": [
221 "The D1 database: npx wrangler d1 create g1t-packages, its id in services/packages/wrangler.jsonc",
222 "The R2 bucket for packages' files: npx wrangler r2 bucket create g1t-packages",
223 "The events queue: npx wrangler queues create g1t-events-packages",
224 "For signed downloads: an R2 API token with read access to g1t-packages, as R2_ACCESS_KEY_ID and R2_SECRET_ACCESS_KEY"
225 ],
226 "self_host": "run"
227 },
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow228 "security": {
229 "path": "services/security",
230 "kind": "rust-worker",
231 "worker": "g1t-security",
232 "d1": { "database": "g1t-security", "migrations": "migrations" },
233 "stage": "core",
234 "secrets": [],
235 "self_host": "run"
236 },
237 "deployments": {
238 "path": "services/deployments",
239 "kind": "ts-worker",
240 "worker": "g1t-deployments",
241 "d1": { "database": "g1t-deployments", "migrations": "migrations" },
242 "stage": "core",
243 "secrets": ["CLOUDFLARE_API_TOKEN"],
244 "setup": [
245 "Workers for Platforms, and the dispatch namespace: scripts/setup-deployments.sh",
246 "Custom domains (Cloudflare for SaaS on g1t.page): scripts/setup-custom-domains.sh"
247 ],
248 "self_host": "run"
249 },
250 "runner": {
251 "path": "services/runner",
252 "kind": "ts-worker",
253 "worker": "g1t-runner",
254 "stage": "core",
255 "secrets": ["AI_GATEWAY_TOKEN"],
Fast pages, required checks on the branch, self-hosted runners, honest incidents256 "setup": [
257 "Containers on the account; Docker on the machine that builds a new image",
258 "The base image, once: node scripts/deploy.mjs build-base"
259 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow260 "image": {
261 "dockerfile": "services/runner/Dockerfile",
Fast pages, required checks on the branch, self-hosted runners, honest incidents262 // The binary the image adds to its base (scripts/build-runner.mjs).
263 "crate": "g1t-runner",
264 "base": { "context": "services/runner/base", "lock": "services/runner/base.json" },
265 "repository": "g1t-runner"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow266 },
267 "self_host": "off"
268 },
269 "context": {
270 "path": "services/context",
271 "kind": "ts-worker",
272 "worker": "g1t-context",
273 "d1": { "database": "g1t-context", "migrations": "migrations" },
274 "stage": "core",
275 "secrets": [],
276 "setup": [
277 "The Vectorize index: npx wrangler vectorize create g1t-context --dimensions=768 --metric=cosine, with metadata indexes on workspace, kind, project and private"
278 ],
279 "self_host": "off"
280 },
281 "og": {
282 "path": "services/og",
283 "kind": "ts-worker",
284 "worker": "g1t-og",
285 "stage": "core",
286 "secrets": [],
287 "setup": ["Browser Rendering on the account (the BROWSER binding)"],
288 // The roadmap cards read the site's roadmap.
289 "inputs": ["apps/web/app/lib/roadmap.ts"],
290 "self_host": "none"
291 },
292 "api": {
293 "path": "apps/api",
294 "kind": "rust-worker",
295 "worker": "g1t-api",
296 "stage": "edge",
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2297 // ACTIONS_OIDC_KEY signs workflow jobs' OIDC tokens; without it the
298 // issuer answers 404 and jobs are not offered tokens.
299 // ACTIONS_OIDC_KEY_PREVIOUS only while rotating. docs/DEPLOYING.md.
300 "secrets": ["ACTIONS_OIDC_KEY"],
301 "setup": [
302 "The OIDC signing key for workflow jobs: an RSA key made with `openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048`, stored with `npx wrangler secret put ACTIONS_OIDC_KEY` (docs/DEPLOYING.md, \"OIDC tokens for workflow jobs\")",
303 "The actions cache bucket's lifecycle rule limited to `c/`, so artifacts under `a/` are kept their retention-days (docs/DEPLOYING.md)"
304 ],
Merge branch 'worktree-agent-aaf03bdceac799c89'305 "self_host": "separate"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow306 },
307 "models": {
308 "path": "services/models",
309 "kind": "ts-worker",
310 "worker": "g1t-models",
Chat and workspace agents: channels, DMs and named agents you talk to311 // Core, though it is public at models.g1t.sh: the agents service
312 // reaches it by service binding for chat replies. It binds only to
313 // core services itself.
314 "stage": "core",
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow315 "secrets": ["AI_GATEWAY_TOKEN"],
316 "setup": ["The AI Gateway `g1t`"],
Chat and workspace agents: channels, DMs and named agents you talk to317 // Not run self-hosted, but bound to the off Worker: agents binds to it.
318 "self_host": "off"
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow319 },
320 "pages": {
321 "path": "services/pages",
322 "kind": "ts-worker",
323 "worker": "g1t-pages",
324 "stage": "edge",
325 "secrets": [],
326 "setup": ["A proxied wildcard DNS record on g1t.page (`*`, AAAA 100::): scripts/setup-deployments.sh"],
327 "self_host": "none"
328 },
329 "status": {
330 "path": "apps/status",
331 "kind": "ts-worker",
332 "worker": "g1t-status",
333 "d1": { "database": "g1t-status", "migrations": "migrations" },
334 "stage": "edge",
335 "secrets": ["STATUS_SECRET"],
336 "setup": ["Email Sending on g1t.sh (the EMAIL binding)"],
337 "self_host": "separate"
338 },
339 "web": {
340 "path": "apps/web",
341 "kind": "react-router",
342 "worker": "g1t",
343 "stage": "front",
Merge g1tusercontent.com: registry answers run nothing in a browser, the site's pages run only their own scripts, repository files and avatars on their own origin, raw files rate limited per address344 // USERCONTENT_KEY signs the short-lived addresses of private
345 // repositories' files on g1tusercontent.com; without it they are
346 // served from g1t.sh instead.
347 "secrets": ["USERCONTENT_KEY"],
348 "setup": [
349 "The R2 bucket g1t-downloads, for the self-hosted runner's releases: npx wrangler r2 bucket create g1t-downloads",
350 "The zone g1tusercontent.com on the account; the Worker's custom domain on it is made by the deploy",
351 "The key for private files' addresses: `node -e \"console.log(require('crypto').randomBytes(32).toString('hex'))\" | npx wrangler secret put USERCONTENT_KEY` in apps/web"
352 ],
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow353 "self_host": "run"
354 },
355 "sudo": {
356 "path": "apps/sudo",
357 "kind": "react-router",
358 "worker": "g1t-sudo",
359 "stage": "front",
360 "secrets": [],
361 "setup": ["A Cloudflare Access application on sudo.g1t.sh; its AUD tag is ACCESS_AUD"],
362 "self_host": "none"
363 },
364 "docs": {
365 "path": "apps/docs",
366 "kind": "astro",
367 "worker": "g1t-docs",
368 "stage": "front",
369 "secrets": [],
370 "self_host": "none"
371 }
372 }
373}

This file's history is long; its oldest lines are credited to the oldest commit read.