Commit

Plan: a repository that maintains itself, and deployments on g1t.page

Upkeep agents in place of Dependabot and GitHub Advanced Security, each problem fixed by an agent through the queue; previews and production on g1t.page through Workers for Platforms, scaled to zero, on by default and off in one click. The large run builds both on g1t itself.

syntaqxcommitted Parentd609937Browse files
1 file+71−40/1 viewed
+71−4
492492 Agents can also reach integrations directly: an agent definition lists MCP
493493 servers (Sentry, Linear and so on) it may use while working.
494494
495+## A repository that maintains itself
496+
497+> **2026-10-04:** the user asked for Dependabot, GitHub Advanced Security and
498+> Vercel-style deployments, "so you're not having to maintain shit and you're
499+> just pushing up agents that are delivering work consistently".
500+
501+GitHub reports problems and leaves the fix to you. In g1t, an agent opens an
502+issue for each problem, writes the fix, runs its checks, links a preview and
503+lands it through the queue. People only decide.
504+
505+### Upkeep agents
506+
507+- **Dependency updates.** A scheduled scan reads the lockfiles (npm, Cargo,
508+ Go, pip), finds outdated and vulnerable packages and opens one issue per
509+ update or group, assigned to g1t-agent. The agent upgrades the package,
510+ fixes what the upgrade broke and lands it through the queue. A repository
511+ sets how often it scans, which packages it groups and what lands without
512+ review (`.g1t/upkeep.yml`, shaped like `dependabot.yml`).
513+- **Secret scanning.** Pushes are scanned for known token formats. A push
514+ that adds a secret is refused with the file and line; one already in
515+ history opens an issue to rotate it and remove it.
516+- **Vulnerability alerts.** Dependencies are matched against the OSV
517+ database. Every alert links to the issue and pull request fixing it.
518+- **Code scanning.** A reviewer agent reads each pull request's diff for
519+ security problems and leaves findings as review comments with a
520+ suggested fix. Findings on `main` open issues.
521+- **A security page per repository** lists alerts, secrets and findings,
522+ with the agent work on each, like GitHub's Security tab.
523+
524+All of these are event sources for the existing issue → agent → checks →
525+queue pipeline; they need no new kind of work.
526+
527+### Deployments
528+
529+- **A preview for every pull request**, at
530+ `<pr>--<repo>--<owner>.g1t.page`, linked on the pull request and updated
531+ on each push. `main` deploys to `<repo>--<owner>.g1t.page`, and a
532+ repository can add its own domain.
533+- **On g1t.page, not g1t.sh,** so customer code never shares cookies or an
534+ origin with the site people sign in to.
535+- **Built on Workers for Platforms.** Each deployment is a user Worker in a
536+ dispatch namespace; one dispatch Worker on `*.g1t.page` routes to it. The
537+ build runs in the same runners as Actions. Static sites and Workers apps
538+ first; container apps and databases later.
539+- **Agents use the preview.** The reviewer agent opens the preview in a
540+ browser, takes screenshots of what changed and attaches them to its
541+ review, so an approver sees the result without reading the diff.
542+- **Environments.** Preview, production and their secrets; deploy history
543+ and one-click rollback.
544+- **Scale to zero.** An idle branch costs neither g1t nor the customer
545+ anything: a Worker runs, and is billed, only while it answers a request.
546+ A preview is deleted when its pull request closes or merges, and after
547+ a set number of idle days. Container apps, later, sleep when idle.
548+- **On by default, off in one click.** Deployments are recommended, not
549+ required: a repository can turn them off, keep only production, or
550+ deploy somewhere else from its own workflows. Apps built for Cloudflare
551+ (Workers, static assets, D1, KV, R2) deploy without configuration.
552+
553+Later, toward GitLab's DevOps breadth: environment protection rules,
554+package and container registries, releases, container hosting.
555+
495556 ## Agents and models
496557
497558 ### Defining an agent
736797 | --- | --- |
737798 | Repositories; a fork per pull request; data residency per workspace | Artifacts (forks, jurisdictions) |
738799 | Reacting to pushes | Artifacts event subscriptions on Queues |
739−| Preview URL per pull request; deploy on merge | Workers Builds and previews |
800+| Preview URL per pull request; deploy on merge | Workers for Platforms on `g1t.page` |
740801 | Site, API, MCP, git front end | Workers |
741802 | Per-repo coordination, live updates | Durable Objects |
742803 | Pull request lifecycles, automations | Workflows, Cron Triggers |
789850 page.~~ Done: questions and handoffs show as waiting, read, answered,
790851 taken on or declined; since 2026-10-03 an agent asked while it is not at
791852 work is woken to answer, where before the question waited forever.
792−2. **The large run.** Dozens of agents on a real repository, end to end, for
793− the video; g1t hosted on g1t.
794−3. **Polish for judges trying it in a minute:** a seeded demo workspace, the
853+2. **Upkeep agents** (above): dependency updates, secret scanning,
854+ vulnerability alerts, code scanning, the security page. No new
855+ infrastructure.
856+3. **Deployments on `g1t.page`** (above): previews per pull request,
857+ production on merge, the reviewer agent checking the preview.
858+4. **The large run, building 2 and 3.** About 20–30 issues on g1t itself,
859+ built by agents and landed through the queue, for the video: g1t built
860+ on g1t.
861+5. **Polish for judges trying it in a minute:** a seeded demo workspace, the
795862 empty states, and the first-run path from sign-up to an outcome landing.
796863
797864 Earlier items still open, after those: