Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Billing accounts, terms and enterprises; g1t is no longer free | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-sudo", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 6 | "placement": { "mode": "off" }, |
| Billing accounts, terms and enterprises; g1t is no longer free | 7 | "main": "./workers/app.ts", |
| 8 | // Staff only: reachable at sudo.g1t.sh, behind Cloudflare Access, and | |
| 9 | // nowhere else. No workers.dev address and no preview URLs, so there is | |
| 10 | // no way round Access to the worker. | |
| 11 | "routes": [{ "pattern": "sudo.g1t.sh", "custom_domain": true }], | |
| 12 | "workers_dev": false, | |
| 13 | "preview_urls": false, | |
| 14 | // Even the stylesheet goes through the worker, which checks the Access | |
| 15 | // token on every request before anything is served. | |
| 16 | "assets": { "binding": "ASSETS", "run_worker_first": true }, | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 17 | // Billing's and identity's staff-only methods (admin_*). Nothing else |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 18 | // binds to identity's admin_* methods. The event log, read-only, for |
| 19 | // `abuse.flagged` (Abuse & fraud). | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 20 | "services": [ |
| 21 | { "binding": "BILLING", "service": "g1t-billing" }, | |
| Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look | 22 | { "binding": "IDENTITY", "service": "g1t-identity" }, |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 23 | { "binding": "EVENTS", "service": "g1t-events" }, |
| 24 | // The status page's staff-only entrypoint: posting incidents to | |
| 25 | // status.g1t.sh (apps/status). Only bindings reach it. | |
| 26 | { "binding": "STATUS", "service": "g1t-status", "entrypoint": "StatusAdmin" } | |
| Billing on Stripe's pages, month-end charges, warnings; sudo by workspace | 27 | ], |
| Billing accounts, terms and enterprises; g1t is no longer free | 28 | "vars": { |
| 29 | // The Zero Trust team domain, such as `g1t.cloudflareaccess.com`. | |
| sudo: Access is on, and everyone at g1t.sh is staff | 30 | "ACCESS_TEAM_DOMAIN": "syntaqx.cloudflareaccess.com", |
| Billing accounts, terms and enterprises; g1t is no longer free | 31 | // The Access application's Audience (AUD) tag. |
| sudo: Access is on, and everyone at g1t.sh is staff | 32 | "ACCESS_AUD": "5479fcf84130fc7ae68c207ae69a81b2aa17d97714443c6f1dddd058c530b8cf", |
| Billing accounts, terms and enterprises; g1t is no longer free | 33 | // Who may use sudo, comma separated. Access lets them in; this |
| 34 | // decides again, in case the Access policy is ever widened. | |
| sudo: Access is on, and everyone at g1t.sh is staff | 35 | "STAFF_EMAILS": "syntaqx@gmail.com, @g1t.sh" |
| Billing accounts, terms and enterprises; g1t is no longer free | 36 | }, |
| 37 | "observability": { "enabled": true }, | |
| 38 | "upload_source_maps": true | |
| 39 | } |