What g1t can't do yet, and an open letter to Cloudflare
- A limitations page under About: what you can't do, why, what to do instead, and whether it's planned or depends on Cloudflare. - An open letter to Cloudflare from the team building g1t: what's great, where we hit walls, what we built around them, and ten asks. - The git guide's included operations match billing (50,000); forks no longer claim storage semantics Cloudflare hasn't documented.
12 files+376−3460/12 viewed
| 124 | 124 | items: [ | |
| 125 | 125 | { label: 'API overview', slug: 'reference/api' }, | |
| 126 | 126 | { label: 'MCP tools', slug: 'reference/mcp' }, | |
| 127 | − | { label: "What g1t can't do yet", slug: 'reference/limitations' }, | |
| 128 | 127 | { label: 'Try it in the explorer', link: '/api/reference/', attrs: { target: '_self' } }, | |
| 129 | 128 | { label: 'OpenAPI document', link: 'https://api.g1t.sh/openapi.json' }, | |
| 130 | 129 | { label: 'llms.txt', link: 'https://g1t.sh/llms.txt' }, | |
| 132 | 131 | }, | |
| 133 | 132 | { | |
| 134 | 133 | label: 'About', | |
| 135 | − | items: [{ label: 'An open letter to Cloudflare', slug: 'about/open-letter-to-cloudflare' }], | |
| 134 | + | items: [ | |
| 135 | + | { label: "What g1t can't do yet", slug: 'about/limitations' }, | |
| 136 | + | { label: 'An open letter to Cloudflare', slug: 'about/open-letter-to-cloudflare' }, | |
| 137 | + | ], | |
| 136 | 138 | }, | |
| 137 | 139 | ...apiGroups, | |
| 138 | 140 | ], |
| 1 | + | --- | |
| 2 | + | title: What g1t can't do yet | |
| 3 | + | description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned. | |
| 4 | + | --- | |
| 5 | + | ||
| 6 | + | This page lists what g1t cannot do today. Each entry says what you can't | |
| 7 | + | do, why, what to do instead, and where it stands. | |
| 8 | + | ||
| 9 | + | Where it stands is one of: | |
| 10 | + | ||
| 11 | + | - **Planned**: we intend to build it. We don't give dates we can't keep. | |
| 12 | + | - **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs | |
| 13 | + | something the platform does not offer yet. | |
| 14 | + | - **Not scheduled**: no work is planned on it now. | |
| 15 | + | ||
| 16 | + | Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/). | |
| 17 | + | ||
| 18 | + | If you hit a limit that is not here, tell us at | |
| 19 | + | [g1t.sh/support](https://g1t.sh/support), and we will add it. | |
| 20 | + | ||
| 21 | + | ## Git | |
| 22 | + | ||
| 23 | + | ### No git over SSH | |
| 24 | + | ||
| 25 | + | You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does | |
| 26 | + | not work. | |
| 27 | + | ||
| 28 | + | - **Why.** SSH needs inbound TCP connections on port 22. g1t runs on | |
| 29 | + | Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta | |
| 30 | + | for inbound TCP; we have applied and are waiting. | |
| 31 | + | - **Instead.** Use the HTTPS remote with an | |
| 32 | + | [access token](/guides/git/#authentication). It does everything SSH would: | |
| 33 | + | clone, fetch and push. SSH keys you add under **Settings → SSH keys** are | |
| 34 | + | kept for when SSH arrives. | |
| 35 | + | - **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh). | |
| 36 | + | ||
| 37 | + | ### Repositories up to 1 GB, files up to 32 MB, no LFS | |
| 38 | + | ||
| 39 | + | A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is | |
| 40 | + | not supported. | |
| 41 | + | ||
| 42 | + | - **Why.** These are the limits of Cloudflare Artifacts, where every | |
| 43 | + | repository is stored. g1t does not check them before a push reaches the | |
| 44 | + | store yet, so a push that crosses them fails late, and git's message may | |
| 45 | + | not say why. | |
| 46 | + | - **Instead.** Keep large binaries out of the repository: in a release | |
| 47 | + | bucket, a package registry or object storage, fetched at build time. | |
| 48 | + | - **Status.** Checking both limits before the push, with a message git | |
| 49 | + | shows you, is planned. Large file storage is planned. Raising the limits | |
| 50 | + | themselves depends on Cloudflare. | |
| 51 | + | ||
| 52 | + | ### Pushes up to 100 MB each | |
| 53 | + | ||
| 54 | + | A single push can carry up to 100 MB. A larger one is refused with HTTP | |
| 55 | + | `413` before g1t sees it. | |
| 56 | + | ||
| 57 | + | - **Why.** Cloudflare's network limits the size of one request body on the | |
| 58 | + | plan g1t.sh is on. | |
| 59 | + | - **Instead.** Push history in steps, oldest first: | |
| 60 | + | `git push origin <older-commit>:refs/heads/main`, then a newer one, then | |
| 61 | + | `main`. Each push sends only what the last did not. | |
| 62 | + | - **Status.** Depends on Cloudflare. | |
| 63 | + | ||
| 64 | + | ### Imports and mirrors up to 40 MB | |
| 65 | + | ||
| 66 | + | Importing or mirroring a repository copies it in one piece of at most | |
| 67 | + | 40 MB, after compression. | |
| 68 | + | ||
| 69 | + | - **Why.** The copy is held in memory while it moves, and a Worker has | |
| 70 | + | 128 MB for everything it is doing at once. | |
| 71 | + | - **Instead.** Clone the repository yourself and push it to g1t, in steps if | |
| 72 | + | it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across). | |
| 73 | + | - **Status.** Streaming the copy, so size stops mattering, is planned. | |
| 74 | + | ||
| 75 | + | ### Partial clone works, but is not promised | |
| 76 | + | ||
| 77 | + | `git clone --filter=blob:none` returns a real partial clone today. We don't | |
| 78 | + | promise it will keep doing so. | |
| 79 | + | ||
| 80 | + | - **Why.** Cloudflare's documentation says filters are not supported, but | |
| 81 | + | they work with git's protocol version 2. We have asked whether that is | |
| 82 | + | intended. | |
| 83 | + | - **Instead.** Use it, and fall back to `--depth=1` for a shallow clone, | |
| 84 | + | which is supported. | |
| 85 | + | - **Status.** Depends on Cloudflare. | |
| 86 | + | ||
| 87 | + | ### No server-side hooks of your own | |
| 88 | + | ||
| 89 | + | You can't run a script of your own on g1t when a push arrives, before or | |
| 90 | + | after its refs move. | |
| 91 | + | ||
| 92 | + | - **Why.** The git store has no hook for this. g1t's own checks run in front | |
| 93 | + | of it, in g1t's code: [protected branches](/guides/git/#protected-branches) | |
| 94 | + | and [push protection](/guides/security/#push-protection). | |
| 95 | + | - **Instead.** Protect the default branch and make your workflows | |
| 96 | + | [required checks](/guides/pull-requests/#required-status-checks). To react | |
| 97 | + | after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`. | |
| 98 | + | - **Status.** Not scheduled for your own scripts. A hook in the store, | |
| 99 | + | which would let g1t enforce more before refs move, depends on Cloudflare. | |
| 100 | + | ||
| 101 | + | ### Push protection skips very large pushes | |
| 102 | + | ||
| 103 | + | Very large pushes, by size or by number of commits, are not yet fully | |
| 104 | + | scanned for secrets. Most pushes are scanned in full; we are raising the | |
| 105 | + | limit by streaming the scan instead of reading the whole push at once. | |
| 106 | + | ||
| 107 | + | - **Why.** Scanning reads the whole push inside a Worker, which has 128 MB | |
| 108 | + | for everything it is doing at once. Past that size, scanning could fail | |
| 109 | + | the push outright. | |
| 110 | + | - **Instead.** Push large histories in steps (see above), so each push is | |
| 111 | + | scanned. Secrets already in history are listed under | |
| 112 | + | [Secrets in history](/guides/security/#secrets-in-history). | |
| 113 | + | - **Status.** Planned: scanning while the push streams, at any size. | |
| 114 | + | ||
| 115 | + | ### Deleting history does not free storage | |
| 116 | + | ||
| 117 | + | Storage is counted from what is pushed, and the count only grows. Deleting | |
| 118 | + | a branch, or force-pushing over commits, does not lower it. | |
| 119 | + | ||
| 120 | + | - **Why.** The git store does not say whether or when it reclaims space | |
| 121 | + | from objects nothing points to any more, or report how much a repository | |
| 122 | + | holds. So g1t cannot see it either. | |
| 123 | + | - **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in | |
| 124 | + | a private repository and counts against you, tell us at | |
| 125 | + | [g1t.sh/support](https://g1t.sh/support). | |
| 126 | + | - **Status.** Depends on Cloudflare. See | |
| 127 | + | [private repository storage](/guides/usage-and-billing/#private-repository-storage). | |
| 128 | + | ||
| 129 | + | ## Pull requests and forks | |
| 130 | + | ||
| 131 | + | ### Forks are only for pull requests | |
| 132 | + | ||
| 133 | + | You can't fork a repository into your own workspace. On g1t, a fork is a | |
| 134 | + | pull request's own working copy, made when the pull request is opened. | |
| 135 | + | ||
| 136 | + | - **Why.** We built forks to isolate agents' work, one per pull request. | |
| 137 | + | See [Forks and branches](/concepts/forks/). | |
| 138 | + | - **Instead.** To contribute, open a pull request: it gets its own fork. To | |
| 139 | + | start a copy of your own, clone the repository and push it to a new one | |
| 140 | + | in your workspace; pushing creates it. | |
| 141 | + | - **Status.** Not scheduled. | |
| 142 | + | ||
| 143 | + | ### Pull request forks are kept after they close | |
| 144 | + | ||
| 145 | + | A pull request's fork stays after the pull request merges or closes. | |
| 146 | + | ||
| 147 | + | - **Why.** Cloudflare has not documented whether a fork shares stored | |
| 148 | + | objects with its source or copies them, and the answer decides how and | |
| 149 | + | when forks should be cleaned up. | |
| 150 | + | - **Instead.** Nothing you need to do. | |
| 151 | + | - **Status.** Deleting forks some time after their pull request closes is | |
| 152 | + | planned. Clear fork storage rules depend on Cloudflare. | |
| 153 | + | ||
| 154 | + | ### No conflict resolution in the browser | |
| 155 | + | ||
| 156 | + | You can't resolve a merge conflict on the pull request's page. | |
| 157 | + | ||
| 158 | + | - **Instead.** Ask a g1t agent to resolve it, or fix it on the command line. | |
| 159 | + | See [Conflicts](/guides/pull-requests/#conflicts). | |
| 160 | + | - **Status.** Planned. | |
| 161 | + | ||
| 162 | + | ## Actions and runners | |
| 163 | + | ||
| 164 | + | ### No Docker in g1t's sandboxes | |
| 165 | + | ||
| 166 | + | On g1t's own machines, Docker container actions, `services:` containers and | |
| 167 | + | `container:` do not run, and a step cannot run `docker build`. | |
| 168 | + | ||
| 169 | + | - **Why.** Jobs run in Cloudflare Containers, which offer no supported way | |
| 170 | + | to run Docker or another image builder inside a container. | |
| 171 | + | - **Instead.** Run those jobs on a [self-hosted runner](/guides/self-hosted-runners/). | |
| 172 | + | A runner in Docker mode runs each job in its `container:` image. To build | |
| 173 | + | images, register a runner with `--no-docker` on a machine that has Docker, | |
| 174 | + | and its steps can call `docker build` and `docker push`. Self-hosted time | |
| 175 | + | costs nothing. | |
| 176 | + | - **Status.** Image builds on g1t's machines depend on Cloudflare. | |
| 177 | + | ||
| 178 | + | ### Linux only on g1t's machines | |
| 179 | + | ||
| 180 | + | A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own | |
| 181 | + | machines. | |
| 182 | + | ||
| 183 | + | - **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux, | |
| 184 | + | macOS and Windows, on x64 and arm64. | |
| 185 | + | - **Status.** Not scheduled. | |
| 186 | + | ||
| 187 | + | ### Machine sizes, time and storage | |
| 188 | + | ||
| 189 | + | | Limit | Value | | |
| 190 | + | | --- | --- | | |
| 191 | + | | Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. | | |
| 192 | + | | One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. | | |
| 193 | + | | One cache entry | 2 GB, compressed. A larger one is not saved. | | |
| 194 | + | | A repository's caches | 10 GB together. Past it, the entries restored longest ago are removed. | | |
| 195 | + | | One artifact | 60 MB, kept for 14 days | | |
| 196 | + | ||
| 197 | + | The machine sizes are Cloudflare Containers' instance sizes. For more, use a | |
| 198 | + | [self-hosted runner](/guides/self-hosted-runners/). See | |
| 199 | + | [Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache). | |
| 200 | + | ||
| 201 | + | ### Workflow features not supported yet | |
| 202 | + | ||
| 203 | + | - Reusable workflows from another repository. Ones in the same repository | |
| 204 | + | work. | |
| 205 | + | - Actions that cache through the hosted toolkit's own cache service, such as | |
| 206 | + | `setup-node` with `cache: npm`. They run without it; use `actions/cache`. | |
| 207 | + | - Environments' protection rules: required reviewers, wait timers and branch | |
| 208 | + | limits. A job with `environment:` gets that environment's values and runs | |
| 209 | + | without waiting. | |
| 210 | + | ||
| 211 | + | See [Not yet](/guides/actions/#not-yet). **Status.** Planned. | |
| 212 | + | ||
| 213 | + | ## Deployments | |
| 214 | + | ||
| 215 | + | ### Static sites and Workers only | |
| 216 | + | ||
| 217 | + | Deployments run static sites and Workers projects. You can't deploy a | |
| 218 | + | long-running server, a container, or an app that needs a process that stays | |
| 219 | + | up. | |
| 220 | + | ||
| 221 | + | - **Why.** Apps run on Cloudflare Workers, which run only while they answer a | |
| 222 | + | request. That is why an app nobody visits costs nothing. | |
| 223 | + | - **Instead.** Deploy the server from a workflow to wherever it runs today, | |
| 224 | + | with its credentials in [secrets](/guides/secrets-and-variables/). | |
| 225 | + | - **Status.** A runtime for servers is planned. | |
| 226 | + | ||
| 227 | + | ### Some Workers bindings are not provisioned | |
| 228 | + | ||
| 229 | + | A Workers project deploys without D1, KV, R2, Durable Objects, Queues, | |
| 230 | + | service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its | |
| 231 | + | cron triggers are not scheduled. | |
| 232 | + | ||
| 233 | + | - **Why.** Each of these is a resource g1t has to create and bill per | |
| 234 | + | project, and that is not built yet. | |
| 235 | + | - **Instead.** Check that a binding exists before using it. The deployment | |
| 236 | + | lists each one it left out. | |
| 237 | + | - **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects). | |
| 238 | + | ||
| 239 | + | ### Build and size limits | |
| 240 | + | ||
| 241 | + | A build stops after 45 minutes. A static site can have up to 20,000 files | |
| 242 | + | and 25 MiB per file, which are Cloudflare's limits. See | |
| 243 | + | [Static sites](/guides/deployments/#static-sites). | |
| 244 | + | ||
| 245 | + | ## Data residency | |
| 246 | + | ||
| 247 | + | You can't choose where a workspace's data is stored. g1t's databases keep | |
| 248 | + | their primary copy in the United States, with read copies in other regions | |
| 249 | + | so pages load fast. Repositories are not pinned to a region. | |
| 250 | + | ||
| 251 | + | - **Why.** Cloudflare fixes the region of a repository store when it is | |
| 252 | + | created, and g1t has one store so far. | |
| 253 | + | - **Instead.** None today, if your data must stay in the EU. | |
| 254 | + | - **Status.** EU residency, with an EU-only repository store and databases, | |
| 255 | + | is planned. | |
| 256 | + | ||
| 257 | + | ## Billing | |
| 258 | + | ||
| 259 | + | ### Some costs are not fully defined yet | |
| 260 | + | ||
| 261 | + | Cloudflare starts billing for Artifacts, where repositories are stored, on | |
| 262 | + | October 14, 2026, and has not yet said exactly which calls count as a | |
| 263 | + | billable operation. | |
| 264 | + | ||
| 265 | + | - **What g1t does.** It counts every clone, fetch and push through its git | |
| 266 | + | endpoints. Each day it checks what Cloudflare billed it for containers and | |
| 267 | + | apps against what was used. When a cost moves, | |
| 268 | + | g1t's price moves with it, and every change is listed with its reason on | |
| 269 | + | [g1t.sh/pricing](https://g1t.sh/pricing). | |
| 270 | + | - **What this means for you.** Prices can change while Cloudflare's beta | |
| 271 | + | products settle. They follow cost. | |
| 272 | + | See [How prices are set](/guides/usage-and-billing/#how-prices-are-set) | |
| 273 | + | and [git operations](/guides/usage-and-billing/#git-operations). | |
| 274 | + | - **Status.** Depends on Cloudflare. | |
| 275 | + | ||
| 276 | + | ### Payments are in test mode | |
| 277 | + | ||
| 278 | + | While payments are in test mode, no real card is charged, and g1t's hosted | |
| 279 | + | models are open only to g1t's own workspaces. | |
| 280 | + | ||
| 281 | + | - **Instead.** Connect your own [model provider](/guides/models/). Your | |
| 282 | + | agents then run on your keys, and the provider bills you directly. | |
| 283 | + | - **Status.** Planned: hosted models for every workspace once payments go | |
| 284 | + | live. | |
| 285 | + | ||
| 286 | + | ## Agents | |
| 287 | + | ||
| 288 | + | ### Confidence is a judgement, not a guarantee | |
| 289 | + | ||
| 290 | + | The confidence g1t gives an agent's change, high, medium or low, is | |
| 291 | + | worked out from what g1t can observe: checks, reviews, revisions, the size | |
| 292 | + | and reach of the change. It cannot tell whether the change is correct. | |
| 293 | + | ||
| 294 | + | - **Instead.** Keep **Ask a person before merging low-confidence changes** | |
| 295 | + | on, and make your workflows required checks. A high rating on a | |
| 296 | + | repository with weak tests means less. See | |
| 297 | + | [How sure the agent is](/guides/g1t-agents/#how-sure-the-agent-is). | |
| 298 | + | - **Status.** The signals and their weights may change as we learn from | |
| 299 | + | real changes. | |
| 300 | + | ||
| 301 | + | ### Agents' model calls go through g1t | |
| 302 | + | ||
| 303 | + | An agent's model requests always pass through g1t's model proxy, | |
| 304 | + | `models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox | |
| 305 | + | straight at a provider. | |
| 306 | + | ||
| 307 | + | - **Why.** So that no key is ever inside a sandbox, and so budgets, caps and | |
| 308 | + | the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox). | |
| 309 | + | - **Status.** Not planned. This is by design. | |
| 310 | + | ||
| 311 | + | ## Accounts, status and self-hosting | |
| 312 | + | ||
| 313 | + | ### Sign-up needs an invite | |
| 314 | + | ||
| 315 | + | g1t is invite-only for now. See [Invites](/guides/authentication/#invites). | |
| 316 | + | **Status.** Opening sign-up is planned. | |
| 317 | + | ||
| 318 | + | ### No uptime commitment during the beta | |
| 319 | + | ||
| 320 | + | g1t does not promise a particular uptime or offer a service level agreement | |
| 321 | + | unless you have a written agreement with us. Several of the Cloudflare | |
| 322 | + | products g1t is built on are in beta and have none either. | |
| 323 | + | [status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing, | |
| 324 | + | and every incident. Sandboxes are not checked there yet. See | |
| 325 | + | [Status and incidents](/guides/status/). **Status.** Not scheduled during | |
| 326 | + | the beta. | |
| 327 | + | ||
| 328 | + | ### Self-hosting is early | |
| 329 | + | ||
| 330 | + | [Running g1t yourself](/guides/self-hosting/) gives you the core forge: | |
| 331 | + | accounts, repositories over HTTP, issues and pull requests. g1t agents, | |
| 332 | + | Actions, deployments, git over SSH, the REST API and MCP are off, and it is | |
| 333 | + | not ready for the open internet. **Status.** Planned, in phases. | |
| 334 | + | ||
| 335 | + | ### Not built yet | |
| 336 | + | ||
| 337 | + | - **Milestones.** Planned. | |
| 338 | + | - **Releases and package registries.** Planned. | |
| 339 | + | - **Wikis.** Not scheduled. Keep docs in the repository. |
| 50 | 50 | ||
| 51 | 51 | ### Forks are cheap here | |
| 52 | 52 | ||
| 53 | − | A fork on g1t is copy-on-write. Creating one does not copy the repository's | |
| 54 | − | history; the fork shares it and stores only what changes. A fork of a large | |
| 55 | − | repository is ready in about the time a branch would be. | |
| 53 | + | Creating a fork on g1t takes one call and is ready in about the time a | |
| 54 | + | branch would be, even for a large repository. Forks don't count toward | |
| 55 | + | your workspace's storage. | |
| 56 | 56 | ||
| 57 | 57 | ### Anyone's agent can contribute | |
| 58 | 58 |
| 226 | 226 | ||
| 227 | 227 | ## What is not built yet | |
| 228 | 228 | ||
| 229 | − | g1t is under active development. These are designed but not available yet: | |
| 229 | + | g1t is under active development. These are designed but not available yet | |
| 230 | + | (every current limit, and why, is on | |
| 231 | + | [What g1t can't do yet](/about/limitations/)): | |
| 230 | 232 | ||
| 231 | 233 | - **Milestones.** | |
| 232 | 234 | - **g1t agents for everyone.** g1t can put its own agents on an issue, each |
| 65 | 65 | [values](/guides/secrets-and-variables/#a-value-per-environment), and runs | |
| 66 | 66 | without waiting. | |
| 67 | 67 | ||
| 68 | + | Why each of these is missing, and what to use instead, is on | |
| 69 | + | [What g1t can't do yet](/about/limitations/#actions-and-runners). | |
| 70 | + | ||
| 68 | 71 | ## The runner | |
| 69 | 72 | ||
| 70 | 73 | Jobs run in a fresh sandbox each: Debian with Node 24, Python 3, Go, Rust, |
| 106 | 106 | lists each one it left out. Code that needs them should check that the | |
| 107 | 107 | binding is there. | |
| 108 | 108 | ||
| 109 | + | What Deployments cannot run yet, such as long-running servers, is on | |
| 110 | + | [What g1t can't do yet](/about/limitations/#deployments). | |
| 111 | + | ||
| 109 | 112 | ## Addresses of other projects | |
| 110 | 113 | ||
| 111 | 114 | A project that [depends on another](/guides/projects/#dependencies) with |
| 122 | 122 | Repositories are stored in Cloudflare Artifacts, which limits a repository to | |
| 123 | 123 | 1 GB and a single file to 32 MB. A single push is limited to 100 MB. | |
| 124 | 124 | ||
| 125 | − | Each clone, fetch and push is a git operation. Every workspace has 10,000 | |
| 125 | + | Each clone, fetch and push is a git operation. Every workspace has 50,000 | |
| 126 | 126 | a month included. Past that, a workspace on the g1t plan pays $0.18 per | |
| 127 | 127 | 1,000, and a free workspace is never charged: past 50,000 in a month, its | |
| 128 | 128 | git requests past 60 in an hour are answered `429` with when to try again, | |
| 129 | 129 | until the month turns. Counting starts on 2026-10-14. See | |
| 130 | 130 | [git operations](/guides/usage-and-billing/#git-operations). | |
| 131 | 131 | ||
| 132 | + | What these limits mean in practice, and what to do instead, is on | |
| 133 | + | [What g1t can't do yet](/about/limitations/#git). | |
| 134 | + | ||
| 132 | 135 | ## Where a slow request's time went | |
| 133 | 136 | ||
| 134 | 137 | Every answer g1t gives git carries a `Server-Timing` header: how many |
| 30 | 30 | | Git over SSH, the REST API, MCP and the `g1t` CLI | Not available yet | | |
| 31 | 31 | | Scheduled jobs (webhook retries, Actions schedules) | Not run yet | | |
| 32 | 32 | ||
| 33 | + | What hosted g1t cannot do yet either is on | |
| 34 | + | [What g1t can't do yet](/about/limitations/). | |
| 35 | + | ||
| 33 | 36 | ## Before you start | |
| 34 | 37 | ||
| 35 | 38 | - Docker with Compose v2 (`docker compose version`). |
| 253 | 253 | measurement far from the current cost is not adopted, only logged, so | |
| 254 | 254 | one odd day cannot reprice anything. | |
| 255 | 255 | ||
| 256 | + | Some of the Cloudflare products g1t pays for are in beta and do not yet | |
| 257 | + | define exactly what they bill; see | |
| 258 | + | [What g1t can't do yet](/about/limitations/#billing). | |
| 259 | + | ||
| 256 | 260 | ### Sandbox time | |
| 257 | 261 | ||
| 258 | 262 | Every sandbox g1t starts runs on Cloudflare Containers, and Cloudflare |
| 97 | 97 | /> | |
| 98 | 98 | </CardGrid> | |
| 99 | 99 | ||
| 100 | + | ## Know the limits | |
| 101 | + | ||
| 102 | + | [What g1t can't do yet](/about/limitations/) lists every limit you can | |
| 103 | + | hit today, why it exists, what to do instead, and whether it is planned. | |
| 104 | + | ||
| 100 | 105 | ## Using an AI assistant? | |
| 101 | 106 | ||
| 102 | 107 | Give it [g1t.sh/llms.txt](https://g1t.sh/llms.txt), which describes g1t for |
| 1 | − | --- | |
| 2 | − | title: What g1t can't do yet | |
| 3 | − | description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned. | |
| 4 | − | --- | |
| 5 | − | ||
| 6 | − | This page lists what g1t cannot do today. Each entry says what you can't | |
| 7 | − | do, why, what to do instead, and where it stands. | |
| 8 | − | ||
| 9 | − | Where it stands is one of: | |
| 10 | − | ||
| 11 | − | - **Planned**: we intend to build it. We don't give dates we can't keep. | |
| 12 | − | - **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs | |
| 13 | − | something the platform does not offer yet. | |
| 14 | − | - **Not scheduled**: no work is planned on it now. | |
| 15 | − | ||
| 16 | − | Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/). | |
| 17 | − | ||
| 18 | − | If you hit a limit that is not here, tell us at | |
| 19 | − | [g1t.sh/support](https://g1t.sh/support), and we will add it. | |
| 20 | − | ||
| 21 | − | ## Git | |
| 22 | − | ||
| 23 | − | ### No git over SSH | |
| 24 | − | ||
| 25 | − | You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does | |
| 26 | − | not work. | |
| 27 | − | ||
| 28 | − | - **Why.** SSH needs inbound TCP connections on port 22. g1t runs on | |
| 29 | − | Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta | |
| 30 | − | for inbound TCP; we have applied and are waiting. | |
| 31 | − | - **Instead.** Use the HTTPS remote with an | |
| 32 | − | [access token](/guides/git/#authentication). It does everything SSH would: | |
| 33 | − | clone, fetch and push. SSH keys you add under **Settings → SSH keys** are | |
| 34 | − | kept for when SSH arrives. | |
| 35 | − | - **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh). | |
| 36 | − | ||
| 37 | − | ### Repositories up to 1 GB, files up to 32 MB, no LFS | |
| 38 | − | ||
| 39 | − | A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is | |
| 40 | − | not supported. | |
| 41 | − | ||
| 42 | − | - **Why.** These are the limits of Cloudflare Artifacts, where every | |
| 43 | − | repository is stored. g1t does not check them before a push reaches the | |
| 44 | − | store yet, so a push that crosses them fails late, and git's message may | |
| 45 | − | not say why. | |
| 46 | − | - **Instead.** Keep large binaries out of the repository: in a release | |
| 47 | − | bucket, a package registry or object storage, fetched at build time. | |
| 48 | − | - **Status.** Checking both limits before the push, with a message git | |
| 49 | − | shows you, is planned. Large file storage is planned. Raising the limits | |
| 50 | − | themselves depends on Cloudflare. | |
| 51 | − | ||
| 52 | − | ### Pushes up to 100 MB each | |
| 53 | − | ||
| 54 | − | A single push can carry up to 100 MB. A larger one is refused with HTTP | |
| 55 | − | `413` before g1t sees it. | |
| 56 | − | ||
| 57 | − | - **Why.** Cloudflare's network limits the size of one request body on the | |
| 58 | − | plan g1t.sh is on. | |
| 59 | − | - **Instead.** Push history in steps, oldest first: | |
| 60 | − | `git push origin <older-commit>:refs/heads/main`, then a newer one, then | |
| 61 | − | `main`. Each push sends only what the last did not. | |
| 62 | − | - **Status.** Depends on Cloudflare. | |
| 63 | − | ||
| 64 | − | ### Imports and mirrors up to 40 MB | |
| 65 | − | ||
| 66 | − | Importing or mirroring a repository copies it in one piece of at most | |
| 67 | − | 40 MB, after compression. | |
| 68 | − | ||
| 69 | − | - **Why.** The copy is held in memory while it moves, and a Worker has | |
| 70 | − | 128 MB for everything it is doing at once. | |
| 71 | − | - **Instead.** Clone the repository yourself and push it to g1t, in steps if | |
| 72 | − | it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across). | |
| 73 | − | - **Status.** Streaming the copy, so size stops mattering, is planned. | |
| 74 | − | ||
| 75 | − | ### Partial clone works, but is not promised | |
| 76 | − | ||
| 77 | − | `git clone --filter=blob:none` returns a real partial clone today. We don't | |
| 78 | − | promise it will keep doing so. | |
| 79 | − | ||
| 80 | − | - **Why.** Cloudflare's documentation says filters are not supported, but | |
| 81 | − | they work with git's protocol version 2. We have asked whether that is | |
| 82 | − | intended. | |
| 83 | − | - **Instead.** Use it, and fall back to `--depth=1` for a shallow clone, | |
| 84 | − | which is supported. | |
| 85 | − | - **Status.** Depends on Cloudflare. | |
| 86 | − | ||
| 87 | − | ### No server-side hooks of your own | |
| 88 | − | ||
| 89 | − | You can't run a script of your own on g1t when a push arrives, before or | |
| 90 | − | after its refs move. | |
| 91 | − | ||
| 92 | − | - **Why.** The git store has no hook for this. g1t's own checks run in front | |
| 93 | − | of it, in g1t's code: [protected branches](/guides/git/#protected-branches) | |
| 94 | − | and [push protection](/guides/security/#push-protection). | |
| 95 | − | - **Instead.** Protect the default branch and make your workflows | |
| 96 | − | [required checks](/guides/pull-requests/#required-status-checks). To react | |
| 97 | − | after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`. | |
| 98 | − | - **Status.** Not scheduled for your own scripts. A hook in the store, | |
| 99 | − | which would let g1t enforce more before refs move, depends on Cloudflare. | |
| 100 | − | ||
| 101 | − | ### Push protection skips very large pushes | |
| 102 | − | ||
| 103 | − | A push larger than about 24 MB is not scanned for secrets. In a push of more | |
| 104 | − | than 300 commits, only the first 300 are scanned. | |
| 105 | − | ||
| 106 | − | - **Why.** Scanning reads the whole push inside a Worker, which has 128 MB | |
| 107 | − | for everything it is doing at once. Past that size, scanning could fail | |
| 108 | − | the push outright. | |
| 109 | − | - **Instead.** Push large histories in steps (see above), so each push is | |
| 110 | − | scanned. Secrets already in history are listed under | |
| 111 | − | [Secrets in history](/guides/security/#secrets-in-history). | |
| 112 | − | - **Status.** Planned: scanning while the push streams, at any size. | |
| 113 | − | ||
| 114 | − | ### Deleting history does not free storage | |
| 115 | − | ||
| 116 | − | Storage is counted from what is pushed, and the count only grows. Deleting | |
| 117 | − | a branch, or force-pushing over commits, does not lower it. | |
| 118 | − | ||
| 119 | − | - **Why.** The git store does not say whether or when it reclaims space | |
| 120 | − | from objects nothing points to any more, or report how much a repository | |
| 121 | − | holds. So g1t cannot see it either. | |
| 122 | − | - **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in | |
| 123 | − | a private repository and counts against you, tell us at | |
| 124 | − | [g1t.sh/support](https://g1t.sh/support). | |
| 125 | − | - **Status.** Depends on Cloudflare. See | |
| 126 | − | [private repository storage](/guides/usage-and-billing/#private-repository-storage). | |
| 127 | − | ||
| 128 | − | ## Pull requests and forks | |
| 129 | − | ||
| 130 | − | ### Forks are only for pull requests | |
| 131 | − | ||
| 132 | − | You can't fork a repository into your own workspace. On g1t, a fork is a | |
| 133 | − | pull request's own working copy, made when the pull request is opened. | |
| 134 | − | ||
| 135 | − | - **Why.** We built forks to isolate agents' work, one per pull request. | |
| 136 | − | See [Forks and branches](/concepts/forks/). | |
| 137 | − | - **Instead.** To contribute, open a pull request: it gets its own fork. To | |
| 138 | − | start a copy of your own, clone the repository and push it to a new one | |
| 139 | − | in your workspace; pushing creates it. | |
| 140 | − | - **Status.** Not scheduled. | |
| 141 | − | ||
| 142 | − | ### Pull request forks are kept after they close | |
| 143 | − | ||
| 144 | − | A pull request's fork stays after the pull request merges or closes. | |
| 145 | − | ||
| 146 | − | - **Why.** Cloudflare has not documented whether a fork shares stored | |
| 147 | − | objects with its source or copies them, and the answer decides how and | |
| 148 | − | when forks should be cleaned up. | |
| 149 | − | - **Instead.** Nothing you need to do. | |
| 150 | − | - **Status.** Deleting forks some time after their pull request closes is | |
| 151 | − | planned. Clear fork storage rules depend on Cloudflare. | |
| 152 | − | ||
| 153 | − | ### No conflict resolution in the browser | |
| 154 | − | ||
| 155 | − | You can't resolve a merge conflict on the pull request's page. | |
| 156 | − | ||
| 157 | − | - **Instead.** Ask a g1t agent to resolve it, or fix it on the command line. | |
| 158 | − | See [Conflicts](/guides/pull-requests/#conflicts). | |
| 159 | − | - **Status.** Planned. | |
| 160 | − | ||
| 161 | − | ## Actions and runners | |
| 162 | − | ||
| 163 | − | ### No Docker in g1t's sandboxes | |
| 164 | − | ||
| 165 | − | On g1t's own machines, Docker container actions, `services:` containers and | |
| 166 | − | `container:` do not run, and a step cannot run `docker build`. | |
| 167 | − | ||
| 168 | − | - **Why.** Jobs run in Cloudflare Containers, which offer no supported way | |
| 169 | − | to run Docker or another image builder inside a container. | |
| 170 | − | - **Instead.** Run those jobs on a [self-hosted runner](/guides/self-hosted-runners/). | |
| 171 | − | A runner in Docker mode runs each job in its `container:` image. To build | |
| 172 | − | images, register a runner with `--no-docker` on a machine that has Docker, | |
| 173 | − | and its steps can call `docker build` and `docker push`. Self-hosted time | |
| 174 | − | costs nothing. | |
| 175 | − | - **Status.** Image builds on g1t's machines depend on Cloudflare. | |
| 176 | − | ||
| 177 | − | ### Linux only on g1t's machines | |
| 178 | − | ||
| 179 | − | A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own | |
| 180 | − | machines. | |
| 181 | − | ||
| 182 | − | - **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux, | |
| 183 | − | macOS and Windows, on x64 and arm64. | |
| 184 | − | - **Status.** Not scheduled. | |
| 185 | − | ||
| 186 | − | ### Machine sizes, time and storage | |
| 187 | − | ||
| 188 | − | | Limit | Value | | |
| 189 | − | | --- | --- | | |
| 190 | − | | Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. | | |
| 191 | − | | One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. | | |
| 192 | − | | One cache entry | 2 GB, compressed. A larger one is not saved. | | |
| 193 | − | | A repository's caches | 10 GB together. Past it, the entries restored longest ago are removed. | | |
| 194 | − | | One artifact | 60 MB, kept for 14 days | | |
| 195 | − | ||
| 196 | − | The machine sizes are Cloudflare Containers' instance sizes. For more, use a | |
| 197 | − | [self-hosted runner](/guides/self-hosted-runners/). See | |
| 198 | − | [Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache). | |
| 199 | − | ||
| 200 | − | ### Workflow features not supported yet | |
| 201 | − | ||
| 202 | − | - Reusable workflows from another repository. Ones in the same repository | |
| 203 | − | work. | |
| 204 | − | - Actions that cache through the hosted toolkit's own cache service, such as | |
| 205 | − | `setup-node` with `cache: npm`. They run without it; use `actions/cache`. | |
| 206 | − | - Environments' protection rules: required reviewers, wait timers and branch | |
| 207 | − | limits. A job with `environment:` gets that environment's values and runs | |
| 208 | − | without waiting. | |
| 209 | − | ||
| 210 | − | See [Not yet](/guides/actions/#not-yet). **Status.** Planned. | |
| 211 | − | ||
| 212 | − | ## Deployments | |
| 213 | − | ||
| 214 | − | ### Static sites and Workers only | |
| 215 | − | ||
| 216 | − | Deployments run static sites and Workers projects. You can't deploy a | |
| 217 | − | long-running server, a container, or an app that needs a process that stays | |
| 218 | − | up. | |
| 219 | − | ||
| 220 | − | - **Why.** Apps run on Cloudflare Workers, which run only while they answer a | |
| 221 | − | request. That is why an app nobody visits costs nothing. | |
| 222 | − | - **Instead.** Deploy the server from a workflow to wherever it runs today, | |
| 223 | − | with its credentials in [secrets](/guides/secrets-and-variables/). | |
| 224 | − | - **Status.** A runtime for servers is planned. | |
| 225 | − | ||
| 226 | − | ### Some Workers bindings are not provisioned | |
| 227 | − | ||
| 228 | − | A Workers project deploys without D1, KV, R2, Durable Objects, Queues, | |
| 229 | − | service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its | |
| 230 | − | cron triggers are not scheduled. | |
| 231 | − | ||
| 232 | − | - **Why.** Each of these is a resource g1t has to create and bill per | |
| 233 | − | project, and that is not built yet. | |
| 234 | − | - **Instead.** Check that a binding exists before using it. The deployment | |
| 235 | − | lists each one it left out. | |
| 236 | − | - **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects). | |
| 237 | − | ||
| 238 | − | ### Build and size limits | |
| 239 | − | ||
| 240 | − | A build stops after 45 minutes. A static site can have up to 20,000 files | |
| 241 | − | and 25 MiB per file, which are Cloudflare's limits. See | |
| 242 | − | [Static sites](/guides/deployments/#static-sites). | |
| 243 | − | ||
| 244 | − | ## Data residency | |
| 245 | − | ||
| 246 | − | You can't choose where a workspace's data is stored. g1t's databases keep | |
| 247 | − | their primary copy in the United States, with read copies in other regions | |
| 248 | − | so pages load fast. Repositories are not pinned to a region. | |
| 249 | − | ||
| 250 | − | - **Why.** Cloudflare fixes the region of a repository store when it is | |
| 251 | − | created, and g1t has one store so far. | |
| 252 | − | - **Instead.** None today, if your data must stay in the EU. | |
| 253 | − | - **Status.** EU residency, with an EU-only repository store and databases, | |
| 254 | − | is planned. | |
| 255 | − | ||
| 256 | − | ## Billing | |
| 257 | − | ||
| 258 | − | ### Some costs are not fully defined yet | |
| 259 | − | ||
| 260 | − | Cloudflare starts billing for Artifacts, where repositories are stored, on | |
| 261 | − | October 14, 2026, and has not yet said exactly which calls count as a | |
| 262 | − | billable operation. | |
| 263 | − | ||
| 264 | − | - **What g1t does.** It counts every clone, fetch and push through its git | |
| 265 | − | endpoints. Each day it checks what Cloudflare billed it for containers and | |
| 266 | − | apps against what was used. When a cost moves, | |
| 267 | − | g1t's price moves with it, and every change is listed with its reason on | |
| 268 | − | [g1t.sh/pricing](https://g1t.sh/pricing). | |
| 269 | − | - **What this means for you.** Prices can change while Cloudflare's beta | |
| 270 | − | products settle. They follow cost. | |
| 271 | − | See [How prices are set](/guides/usage-and-billing/#how-prices-are-set) | |
| 272 | − | and [git operations](/guides/usage-and-billing/#git-operations). | |
| 273 | − | - **Status.** Depends on Cloudflare. | |
| 274 | − | ||
| 275 | − | ### Payments are in test mode | |
| 276 | − | ||
| 277 | − | While payments are in test mode, no real card is charged, and g1t's hosted | |
| 278 | − | models are open only to g1t's own workspaces. | |
| 279 | − | ||
| 280 | − | - **Instead.** Connect your own [model provider](/guides/models/). Your | |
| 281 | − | agents then run on your keys, and the provider bills you directly. | |
| 282 | − | - **Status.** Planned: hosted models for every workspace once payments go | |
| 283 | − | live. | |
| 284 | − | ||
| 285 | − | ## Agents | |
| 286 | − | ||
| 287 | − | ### Confidence is a judgement, not a guarantee | |
| 288 | − | ||
| 289 | − | The confidence g1t gives an agent's change, high, medium or low, is | |
| 290 | − | worked out from what g1t can observe: checks, reviews, revisions, the size | |
| 291 | − | and reach of the change. It cannot tell whether the change is correct. | |
| 292 | − | ||
| 293 | − | - **Instead.** Keep **Ask a person before merging low-confidence changes** | |
| 294 | − | on, and make your workflows required checks. A high rating on a | |
| 295 | − | repository with weak tests means less. See | |
| 296 | − | [How sure the agent is](/guides/g1t-agents/#how-sure-the-agent-is). | |
| 297 | − | - **Status.** The signals and their weights may change as we learn from | |
| 298 | − | real changes. | |
| 299 | − | ||
| 300 | − | ### Agents' model calls go through g1t | |
| 301 | − | ||
| 302 | − | An agent's model requests always pass through g1t's model proxy, | |
| 303 | − | `models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox | |
| 304 | − | straight at a provider. | |
| 305 | − | ||
| 306 | − | - **Why.** So that no key is ever inside a sandbox, and so budgets, caps and | |
| 307 | − | the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox). | |
| 308 | − | - **Status.** Not planned. This is by design. | |
| 309 | − | ||
| 310 | − | ## Accounts, status and self-hosting | |
| 311 | − | ||
| 312 | − | ### Sign-up needs an invite | |
| 313 | − | ||
| 314 | − | g1t is invite-only for now. See [Invites](/guides/authentication/#invites). | |
| 315 | − | **Status.** Opening sign-up is planned. | |
| 316 | − | ||
| 317 | − | ### No uptime commitment during the beta | |
| 318 | − | ||
| 319 | − | g1t does not promise a particular uptime or offer a service level agreement | |
| 320 | − | unless you have a written agreement with us. Several of the Cloudflare | |
| 321 | − | products g1t is built on are in beta and have none either. | |
| 322 | − | [status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing, | |
| 323 | − | and every incident. Sandboxes are not checked there yet. See | |
| 324 | − | [Status and incidents](/guides/status/). **Status.** Not scheduled during | |
| 325 | − | the beta. | |
| 326 | − | ||
| 327 | − | ### Self-hosting is early | |
| 328 | − | ||
| 329 | − | [Running g1t yourself](/guides/self-hosting/) gives you the core forge: | |
| 330 | − | accounts, repositories over HTTP, issues and pull requests. g1t agents, | |
| 331 | − | Actions, deployments, git over SSH, the REST API and MCP are off, and it is | |
| 332 | − | not ready for the open internet. **Status.** Planned, in phases. | |
| 333 | − | ||
| 334 | − | ### Not built yet | |
| 335 | − | ||
| 336 | − | - **Milestones.** Planned. | |
| 337 | − | - **Releases and package registries.** Planned. | |
| 338 | − | - **Wikis.** Not scheduled. Keep docs in the repository. |
| 485 | 485 | - Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths, | |
| 486 | 486 | `{owner}` is the workspace. Pull request forks: | |
| 487 | 487 | `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available. | |
| 488 | − | - Limits: 1 GB per repository, 32 MB per file, 100 MB per push. | |
| 488 | + | - Limits: 1 GB per repository, 32 MB per file, 100 MB per push. Every | |
| 489 | + | current limit, why it exists and the workaround: | |
| 490 | + | https://docs.g1t.sh/about/limitations/ | |
| 489 | 491 | - Forgotten password: https://g1t.sh/forgot (the person does this, in a | |
| 490 | 492 | browser). | |
| 491 | 493 | - Times are RFC 3339 in UTC. | |
| 541 | 543 | - [Git](https://docs.g1t.sh/guides/git/) | |
| 542 | 544 | - [MCP tools](https://docs.g1t.sh/reference/mcp/) | |
| 543 | 545 | - [API reference](https://docs.g1t.sh/reference/api/) | |
| 546 | + | - [What g1t can't do yet](https://docs.g1t.sh/about/limitations/) | |
| 547 | + | - [An open letter to Cloudflare](https://docs.g1t.sh/about/open-letter-to-cloudflare/) | |
| 544 | 548 | - [Source](https://g1t.sh/flagon-io/g1t), MIT licensed | |
| 545 | 549 | ||
| 546 | 550 | ## Help, status and policies |