Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Deploy scripts live in the repository | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-api", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 6 | "placement": { "mode": "off" }, |
| Deploy scripts live in the repository | 7 | "main": "build/index.js", |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 8 | "build": { "command": "node ../../scripts/build-rust-worker.mjs" }, |
| Deploy scripts live in the repository | 9 | "workers_dev": false, |
| 10 | // One Worker, two hostnames: REST on api, MCP on mcp. Both are thin | |
| 11 | // adapters over the same operations. | |
| 12 | "routes": [ | |
| 13 | { "pattern": "api.g1t.sh", "custom_domain": true }, | |
| 14 | { "pattern": "mcp.g1t.sh", "custom_domain": true } | |
| 15 | ], | |
| 16 | "services": [ | |
| 17 | { "binding": "IDENTITY", "service": "g1t-identity" }, | |
| 18 | { "binding": "REPOS", "service": "g1t-repos" }, | |
| 19 | { "binding": "WORK", "service": "g1t-work" }, | |
| 20 | { "binding": "EVENTS", "service": "g1t-events" }, | |
| 21 | { "binding": "RUNNER", "service": "g1t-runner" }, | |
| 22 | { "binding": "BILLING", "service": "g1t-billing" }, | |
| 23 | { "binding": "INTEGRATIONS", "service": "g1t-integrations" }, | |
| 24 | { "binding": "WEBHOOKS", "service": "g1t-webhooks" }, | |
| 25 | { "binding": "ACTIONS", "service": "g1t-actions" }, | |
| 26 | // Builds of deployments report through here. | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 27 | { "binding": "DEPLOYMENTS", "service": "g1t-deployments" }, |
| 28 | // The context hub: search_context and get_entity. | |
| Search across all of g1t, Explore, and a command palette | 29 | { "binding": "CONTEXT", "service": "g1t-context" }, |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 30 | { "binding": "SEARCH", "service": "g1t-search" }, |
| 31 | // Secret and dependency alerts: list_security_alerts and dismissing them. | |
| API: pinned projects over REST and MCP | 32 | { "binding": "SECURITY", "service": "g1t-security" }, |
| 33 | // A person's pinned projects: list_pinned_projects and changing them. | |
| Merge packages: roles, Actions access, source label, soft delete, API | 34 | { "binding": "PROJECTS", "service": "g1t-projects" }, |
| 35 | // Packages: list_packages, their settings, deleting and restoring them. | |
| Merge main into Artifacts Phase 2 | 36 | { "binding": "PACKAGES", "service": "g1t-packages" }, |
| 37 | // Artifacts (folios): the artifact tool and /workspaces/{ws}/artifacts. | |
| Every agent can have its own computer. A session that needs one wakes it: a home of its own on g1t cloud, one per agent and never shared, where it runs commands, reads and writes files and keeps what it made, with each session working in its own folder under a shared home; after ten idle minutes it sleeps, its home kept as a snapshot and restored when it wakes, and Reset wipes the home while memory and artifacts stay. Its shell and files are abilities with the usual choices, Alone, Alone when asked, Ask first or Never, offered only inside sessions and never to a chat reply; every command shows on the session with its output, and the agent's new Computer tab shows the state, the disk used of the five gigabytes included, the recent commands, and Wake, Put to sleep and Reset. Machine time counts only while it is awake, on the sandbox lines of the ledger that name the agent and who asked, held to the same spend caps as the session; the disk itself costs nothing in this version. The runner gained a long-lived supervisor that answers the computer's requests inside the container, and the runner service a computer per agent that keeps its snapshot in the agent homes bucket when one is attached, and says so when none is. The REST API and the agent tool can read a computer, wake it, put it to sleep and reset it. The agents, abilities, sessions, runners, billing and deploy guides say how it works and what an operator sets up; pinning a computer to your own runner, its browser and take-over come next. | 38 | { "binding": "ARTIFACTS", "service": "g1t-artifacts" }, |
| 39 | // Workspace agents' own computers: /workspaces/{ws}/agents/{agent}/computer. | |
| 40 | { "binding": "AGENTS", "service": "g1t-agents" } | |
| Deploy scripts live in the repository | 41 | ], |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 42 | // GitHub Actions artifacts older runners kept, in chunks, with KV's own |
| 43 | // expiry, read until it passes (and cache | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 44 | // entries saved before the cache moved to R2, until they expire). |
| Deploy scripts live in the repository | 45 | "kv_namespaces": [{ "binding": "BLOBS", "id": "16a4232cb746418db53782aa068be693" }], |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 46 | // actions/cache entries (`c/`) and artifacts (`a/`), uploaded in parts. The actions |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 47 | // service lists them and decides what is kept (services/actions/src/cache.rs). |
| 48 | "r2_buckets": [{ "binding": "ACTIONS_CACHE", "bucket_name": "g1t-actions-cache" }], | |
| Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails | 49 | // REST and MCP requests (src/limits.rs): per token, or per address |
| 50 | // without one. Ids and limits: RATE_LIMITS in packages/contracts. | |
| 51 | "ratelimits": [ | |
| 52 | { "name": "API_ANONYMOUS_LIMIT", "namespace_id": "4401", "simple": { "limit": 60, "period": 60 } }, | |
| 53 | { "name": "API_TOKEN_LIMIT", "namespace_id": "4402", "simple": { "limit": 1000, "period": 60 } } | |
| 54 | ], | |
| 55 | // Logs of a tenth of requests: agents call it constantly. | |
| 56 | "observability": { "enabled": true, "head_sampling_rate": 0.1 } | |
| Deploy scripts live in the repository | 57 | } |
This file's history is long; its oldest lines are credited to the oldest commit read.