flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

g1t/services/security/wrangler.jsonc

44 lines1,723 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API1{
2 "$schema": "../../node_modules/wrangler/config-schema.json",
3 "name": "g1t-security",
4 "account_id": "1e6f2cffa3f445920836e8ebe446bb58",
5 "compatibility_date": "2026-09-26",
6 // Runs next to its database: a request makes several queries in turn,
7 // and each would otherwise cross the distance to it.
Fast pages, required checks on the branch, self-hosted runners, honest incidents8 "placement": { "mode": "off" },
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API9 "main": "build/index.js",
Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow10 "build": { "command": "node ../../scripts/build-rust-worker.mjs" },
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API11 // Reached only through service bindings.
12 "workers_dev": false,
13 "d1_databases": [
14 {
15 "binding": "DB",
16 "database_name": "g1t-security",
17 // Create with `wrangler d1 create g1t-security` and put its id here.
18 "database_id": "a7febbca-768a-4828-97b8-dd69b2636e1e",
19 "migrations_dir": "migrations"
20 }
21 ],
22 "services": [
23 { "binding": "IDENTITY", "service": "g1t-identity" },
24 { "binding": "REPOS", "service": "g1t-repos" },
25 { "binding": "WORK", "service": "g1t-work" },
26 { "binding": "RUNNER", "service": "g1t-runner" },
27 { "binding": "BILLING", "service": "g1t-billing" }
28 ],
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily29 // Pushes to a default branch (dependencies are read again), pushes too
30 // large to scan first (scanned after they land), security updates'
31 // branches (their pull requests open), pull requests merged, closed or
32 // failing checks (security updates move on), new repositories (their
33 // history is scanned once) and renamed workspaces.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API34 "queues": {
35 "consumers": [{ "queue": "g1t-events-security", "max_batch_size": 10, "max_batch_timeout": 5 }]
36 },
37 // Continues history scans a page at a time, and reads every
38 // repository's dependencies again once a day.
39 "triggers": { "crons": ["*/30 * * * *"] },
40 "vars": {
41 "SITE_URL": "https://g1t.sh"
42 },
43 "observability": { "enabled": true }
44}