Skip to content

Commit

Docs: workspace aliases, for staff (sudo README and the plan)

syntaqxcommitted Parent239f62eBrowse files
2 files+43−00/2 viewed
+23−0
7070 protected workspace. Both go in the workspace's audit log, as g1t, and in
7171 sudo's (`workspace_restored`, `workspace_purged`), naming the staff
7272 member.
73+- **Aliases** (`/aliases`, under Customers): names that lead to a
74+ workspace, set by staff only; there is no way for a customer to make
75+ one, and nothing user-facing mentions them. `g1t`, the product's name,
76+ leads to `flagon-io`, Flagon, Inc. (seeded by identity's migration
77+ `0029_workspace_aliases.sql`), so nobody mistakes the trading name for
78+ the organization. Every address under an alias leads to the workspace:
79+ pages answer with a 301 to the same page (`/g1t/g1t/issues` to
80+ `/flagon-io/g1t/issues`), git over HTTPS is answered in place as the
81+ workspace's repository (pushes do not follow redirects), the API and MCP
82+ run the call again under the workspace's slug, and the package
83+ registries answer a 301 (308 for a publish). An alias points at the
84+ workspace's id, so it follows a rename; it goes when the workspace is
85+ purged. Each row shows the workspace, why the alias exists, and who added
86+ it and when. **Add** (`admin_set_alias`) takes the alias, the
87+ workspace's slug and why: identity refuses the site's own routes
88+ (`settings`, `api`…), anyone's username, a workspace's slug (deleted, or
89+ held after a rename for another workspace) and an existing alias.
90+ Reserved names such as `g1t` can be aliases, and an alias is nobody's to
91+ register or rename a workspace to while it exists. **Remove**
92+ (`admin_remove_alias`) needs a reason. Both go in sudo's audit log
93+ (`alias_added`, `alias_removed`), naming the staff member. `@g1t` in
94+ text still means g1t's agent: it links to how the agent works, never to
95+ `/g1t`.
7396 - **Enterprises**: customers that pay for several workspaces with one
7497 bill, one limit and one set of terms. Each has its workspaces (add or
7598 remove them), combined usage, terms, credits, ledger and audit log, and
+20−0
13121312 MCP clients, the CLI (device flow) and third-party apps all use it. Access
13131313 tokens and SSH keys remain for git itself.
13141314
1315+### Workspace aliases (internal, built 2026-10-07)
1316+
1317+`g1t` is the product; `flagon-io` is Flagon, Inc., the organization that
1318+builds it. So nobody mistakes one for the other, `g1t.sh/g1t` leads to
1319+`g1t.sh/flagon-io`. That is a workspace alias: a name g1t's staff point at
1320+a workspace, kept in identity's `workspace_aliases` (migration 0029, which
1321+seeds `g1t`) by the workspace's id, so it follows renames. It is not a
1322+customer feature and is not documented for users; staff add and remove
1323+aliases on sudo's Aliases page, with a reason, in sudo's audit log. We may
1324+give other companies one for a trading name the same way.
1325+
1326+An alias is resolved wherever an old slug is (identity's `resolve_slug`),
1327+so it costs only the not-found path: site pages 301 to the same page under
1328+the workspace, the API and MCP run the call again under its slug, package
1329+registries 301, and git over HTTPS is answered in place
1330+(`resolve_alias`), because pushes do not follow redirects. An alias is
1331+never a route, a username or a workspace's slug, and nobody can register
1332+it while it exists. `@g1t` stays g1t's agent: mentions link to how the
1333+agent works, never to `/g1t`.
1334+
13151335 ## Architecture
13161336
13171337 | Component | Language | Runs on | Responsibility |