g1t/services/security/wrangler.jsonc
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | { |
| 2 | "$schema": "../../node_modules/wrangler/config-schema.json", | |
| 3 | "name": "g1t-security", | |
| 4 | "account_id": "1e6f2cffa3f445920836e8ebe446bb58", | |
| 5 | "compatibility_date": "2026-09-26", | |
| 6 | // Runs next to its database: a request makes several queries in turn, | |
| 7 | // and each would otherwise cross the distance to it. | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 8 | "placement": { "mode": "off" }, |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 9 | "main": "build/index.js", |
| Deploys as code: a manifest of every Worker, a deploy tool that ships only what changed in parallel stages, and a g1t Actions workflow | 10 | "build": { "command": "node ../../scripts/build-rust-worker.mjs" }, |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 11 | // Reached only through service bindings. |
| 12 | "workers_dev": false, | |
| 13 | "d1_databases": [ | |
| 14 | { | |
| 15 | "binding": "DB", | |
| 16 | "database_name": "g1t-security", | |
| 17 | // Create with `wrangler d1 create g1t-security` and put its id here. | |
| 18 | "database_id": "a7febbca-768a-4828-97b8-dd69b2636e1e", | |
| 19 | "migrations_dir": "migrations" | |
| 20 | } | |
| 21 | ], | |
| 22 | "services": [ | |
| 23 | { "binding": "IDENTITY", "service": "g1t-identity" }, | |
| 24 | { "binding": "REPOS", "service": "g1t-repos" }, | |
| 25 | { "binding": "WORK", "service": "g1t-work" }, | |
| 26 | { "binding": "RUNNER", "service": "g1t-runner" }, | |
| 27 | { "binding": "BILLING", "service": "g1t-billing" } | |
| 28 | ], | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 29 | // Pushes to a default branch (dependencies are read again), pushes too |
| 30 | // large to scan first (scanned after they land), security updates' | |
| 31 | // branches (their pull requests open), pull requests merged, closed or | |
| 32 | // failing checks (security updates move on), new repositories (their | |
| 33 | // history is scanned once) and renamed workspaces. | |
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 34 | "queues": { |
| 35 | "consumers": [{ "queue": "g1t-events-security", "max_batch_size": 10, "max_batch_timeout": 5 }] | |
| 36 | }, | |
| 37 | // Continues history scans a page at a time, and reads every | |
| 38 | // repository's dependencies again once a day. | |
| 39 | "triggers": { "crons": ["*/30 * * * *"] }, | |
| 40 | "vars": { | |
| 41 | "SITE_URL": "https://g1t.sh" | |
| 42 | }, | |
| 43 | "observability": { "enabled": true } | |
| 44 | } |