Plan: a repository that maintains itself, and deployments on g1t.page
Upkeep agents in place of Dependabot and GitHub Advanced Security, each problem fixed by an agent through the queue; previews and production on g1t.page through Workers for Platforms, scaled to zero, on by default and off in one click. The large run builds both on g1t itself.
1 file+71−40/1 viewed
| 492 | 492 | Agents can also reach integrations directly: an agent definition lists MCP | |
| 493 | 493 | servers (Sentry, Linear and so on) it may use while working. | |
| 494 | 494 | ||
| 495 | + | ## A repository that maintains itself | |
| 496 | + | ||
| 497 | + | > **2026-10-04:** the user asked for Dependabot, GitHub Advanced Security and | |
| 498 | + | > Vercel-style deployments, "so you're not having to maintain shit and you're | |
| 499 | + | > just pushing up agents that are delivering work consistently". | |
| 500 | + | ||
| 501 | + | GitHub reports problems and leaves the fix to you. In g1t, an agent opens an | |
| 502 | + | issue for each problem, writes the fix, runs its checks, links a preview and | |
| 503 | + | lands it through the queue. People only decide. | |
| 504 | + | ||
| 505 | + | ### Upkeep agents | |
| 506 | + | ||
| 507 | + | - **Dependency updates.** A scheduled scan reads the lockfiles (npm, Cargo, | |
| 508 | + | Go, pip), finds outdated and vulnerable packages and opens one issue per | |
| 509 | + | update or group, assigned to g1t-agent. The agent upgrades the package, | |
| 510 | + | fixes what the upgrade broke and lands it through the queue. A repository | |
| 511 | + | sets how often it scans, which packages it groups and what lands without | |
| 512 | + | review (`.g1t/upkeep.yml`, shaped like `dependabot.yml`). | |
| 513 | + | - **Secret scanning.** Pushes are scanned for known token formats. A push | |
| 514 | + | that adds a secret is refused with the file and line; one already in | |
| 515 | + | history opens an issue to rotate it and remove it. | |
| 516 | + | - **Vulnerability alerts.** Dependencies are matched against the OSV | |
| 517 | + | database. Every alert links to the issue and pull request fixing it. | |
| 518 | + | - **Code scanning.** A reviewer agent reads each pull request's diff for | |
| 519 | + | security problems and leaves findings as review comments with a | |
| 520 | + | suggested fix. Findings on `main` open issues. | |
| 521 | + | - **A security page per repository** lists alerts, secrets and findings, | |
| 522 | + | with the agent work on each, like GitHub's Security tab. | |
| 523 | + | ||
| 524 | + | All of these are event sources for the existing issue → agent → checks → | |
| 525 | + | queue pipeline; they need no new kind of work. | |
| 526 | + | ||
| 527 | + | ### Deployments | |
| 528 | + | ||
| 529 | + | - **A preview for every pull request**, at | |
| 530 | + | `<pr>--<repo>--<owner>.g1t.page`, linked on the pull request and updated | |
| 531 | + | on each push. `main` deploys to `<repo>--<owner>.g1t.page`, and a | |
| 532 | + | repository can add its own domain. | |
| 533 | + | - **On g1t.page, not g1t.sh,** so customer code never shares cookies or an | |
| 534 | + | origin with the site people sign in to. | |
| 535 | + | - **Built on Workers for Platforms.** Each deployment is a user Worker in a | |
| 536 | + | dispatch namespace; one dispatch Worker on `*.g1t.page` routes to it. The | |
| 537 | + | build runs in the same runners as Actions. Static sites and Workers apps | |
| 538 | + | first; container apps and databases later. | |
| 539 | + | - **Agents use the preview.** The reviewer agent opens the preview in a | |
| 540 | + | browser, takes screenshots of what changed and attaches them to its | |
| 541 | + | review, so an approver sees the result without reading the diff. | |
| 542 | + | - **Environments.** Preview, production and their secrets; deploy history | |
| 543 | + | and one-click rollback. | |
| 544 | + | - **Scale to zero.** An idle branch costs neither g1t nor the customer | |
| 545 | + | anything: a Worker runs, and is billed, only while it answers a request. | |
| 546 | + | A preview is deleted when its pull request closes or merges, and after | |
| 547 | + | a set number of idle days. Container apps, later, sleep when idle. | |
| 548 | + | - **On by default, off in one click.** Deployments are recommended, not | |
| 549 | + | required: a repository can turn them off, keep only production, or | |
| 550 | + | deploy somewhere else from its own workflows. Apps built for Cloudflare | |
| 551 | + | (Workers, static assets, D1, KV, R2) deploy without configuration. | |
| 552 | + | ||
| 553 | + | Later, toward GitLab's DevOps breadth: environment protection rules, | |
| 554 | + | package and container registries, releases, container hosting. | |
| 555 | + | ||
| 495 | 556 | ## Agents and models | |
| 496 | 557 | ||
| 497 | 558 | ### Defining an agent | |
| 736 | 797 | | --- | --- | | |
| 737 | 798 | | Repositories; a fork per pull request; data residency per workspace | Artifacts (forks, jurisdictions) | | |
| 738 | 799 | | Reacting to pushes | Artifacts event subscriptions on Queues | | |
| 739 | − | | Preview URL per pull request; deploy on merge | Workers Builds and previews | | |
| 800 | + | | Preview URL per pull request; deploy on merge | Workers for Platforms on `g1t.page` | | |
| 740 | 801 | | Site, API, MCP, git front end | Workers | | |
| 741 | 802 | | Per-repo coordination, live updates | Durable Objects | | |
| 742 | 803 | | Pull request lifecycles, automations | Workflows, Cron Triggers | | |
| 789 | 850 | page.~~ Done: questions and handoffs show as waiting, read, answered, | |
| 790 | 851 | taken on or declined; since 2026-10-03 an agent asked while it is not at | |
| 791 | 852 | work is woken to answer, where before the question waited forever. | |
| 792 | − | 2. **The large run.** Dozens of agents on a real repository, end to end, for | |
| 793 | − | the video; g1t hosted on g1t. | |
| 794 | − | 3. **Polish for judges trying it in a minute:** a seeded demo workspace, the | |
| 853 | + | 2. **Upkeep agents** (above): dependency updates, secret scanning, | |
| 854 | + | vulnerability alerts, code scanning, the security page. No new | |
| 855 | + | infrastructure. | |
| 856 | + | 3. **Deployments on `g1t.page`** (above): previews per pull request, | |
| 857 | + | production on merge, the reviewer agent checking the preview. | |
| 858 | + | 4. **The large run, building 2 and 3.** About 20–30 issues on g1t itself, | |
| 859 | + | built by agents and landed through the queue, for the video: g1t built | |
| 860 | + | on g1t. | |
| 861 | + | 5. **Polish for judges trying it in a minute:** a seeded demo workspace, the | |
| 795 | 862 | empty states, and the first-run path from sign-up to an outcome landing. | |
| 796 | 863 | ||
| 797 | 864 | Earlier items still open, after those: |