flagon-io/g1t

public

Where people and agents ship software together. The open-source git platform for the whole job: issues, agents, checks and deploys to the edge.

Commit

What g1t can't do yet, and an open letter to Cloudflare

- A limitations page under About: what you can't do, why, what to do instead, and whether it's planned or depends on Cloudflare. - An open letter to Cloudflare from the team building g1t: what's great, where we hit walls, what we built around them, and ten asks. - The git guide's included operations match billing (50,000); forks no longer claim storage semantics Cloudflare hasn't documented.

syntaqxcommitted Parent482f7c8Browse files
12 files+376−3460/12 viewed
+4−2
124124 items: [
125125 { label: 'API overview', slug: 'reference/api' },
126126 { label: 'MCP tools', slug: 'reference/mcp' },
127− { label: "What g1t can't do yet", slug: 'reference/limitations' },
128127 { label: 'Try it in the explorer', link: '/api/reference/', attrs: { target: '_self' } },
129128 { label: 'OpenAPI document', link: 'https://api.g1t.sh/openapi.json' },
130129 { label: 'llms.txt', link: 'https://g1t.sh/llms.txt' },
132131 },
133132 {
134133 label: 'About',
135− items: [{ label: 'An open letter to Cloudflare', slug: 'about/open-letter-to-cloudflare' }],
134+ items: [
135+ { label: "What g1t can't do yet", slug: 'about/limitations' },
136+ { label: 'An open letter to Cloudflare', slug: 'about/open-letter-to-cloudflare' },
137+ ],
136138 },
137139 ...apiGroups,
138140 ],
+339−0
1+---
2+title: What g1t can't do yet
3+description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned.
4+---
5+
6+This page lists what g1t cannot do today. Each entry says what you can't
7+do, why, what to do instead, and where it stands.
8+
9+Where it stands is one of:
10+
11+- **Planned**: we intend to build it. We don't give dates we can't keep.
12+- **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs
13+ something the platform does not offer yet.
14+- **Not scheduled**: no work is planned on it now.
15+
16+Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/).
17+
18+If you hit a limit that is not here, tell us at
19+[g1t.sh/support](https://g1t.sh/support), and we will add it.
20+
21+## Git
22+
23+### No git over SSH
24+
25+You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does
26+not work.
27+
28+- **Why.** SSH needs inbound TCP connections on port 22. g1t runs on
29+ Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta
30+ for inbound TCP; we have applied and are waiting.
31+- **Instead.** Use the HTTPS remote with an
32+ [access token](/guides/git/#authentication). It does everything SSH would:
33+ clone, fetch and push. SSH keys you add under **Settings → SSH keys** are
34+ kept for when SSH arrives.
35+- **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh).
36+
37+### Repositories up to 1 GB, files up to 32 MB, no LFS
38+
39+A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is
40+not supported.
41+
42+- **Why.** These are the limits of Cloudflare Artifacts, where every
43+ repository is stored. g1t does not check them before a push reaches the
44+ store yet, so a push that crosses them fails late, and git's message may
45+ not say why.
46+- **Instead.** Keep large binaries out of the repository: in a release
47+ bucket, a package registry or object storage, fetched at build time.
48+- **Status.** Checking both limits before the push, with a message git
49+ shows you, is planned. Large file storage is planned. Raising the limits
50+ themselves depends on Cloudflare.
51+
52+### Pushes up to 100 MB each
53+
54+A single push can carry up to 100 MB. A larger one is refused with HTTP
55+`413` before g1t sees it.
56+
57+- **Why.** Cloudflare's network limits the size of one request body on the
58+ plan g1t.sh is on.
59+- **Instead.** Push history in steps, oldest first:
60+ `git push origin <older-commit>:refs/heads/main`, then a newer one, then
61+ `main`. Each push sends only what the last did not.
62+- **Status.** Depends on Cloudflare.
63+
64+### Imports and mirrors up to 40 MB
65+
66+Importing or mirroring a repository copies it in one piece of at most
67+40 MB, after compression.
68+
69+- **Why.** The copy is held in memory while it moves, and a Worker has
70+ 128 MB for everything it is doing at once.
71+- **Instead.** Clone the repository yourself and push it to g1t, in steps if
72+ it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across).
73+- **Status.** Streaming the copy, so size stops mattering, is planned.
74+
75+### Partial clone works, but is not promised
76+
77+`git clone --filter=blob:none` returns a real partial clone today. We don't
78+promise it will keep doing so.
79+
80+- **Why.** Cloudflare's documentation says filters are not supported, but
81+ they work with git's protocol version 2. We have asked whether that is
82+ intended.
83+- **Instead.** Use it, and fall back to `--depth=1` for a shallow clone,
84+ which is supported.
85+- **Status.** Depends on Cloudflare.
86+
87+### No server-side hooks of your own
88+
89+You can't run a script of your own on g1t when a push arrives, before or
90+after its refs move.
91+
92+- **Why.** The git store has no hook for this. g1t's own checks run in front
93+ of it, in g1t's code: [protected branches](/guides/git/#protected-branches)
94+ and [push protection](/guides/security/#push-protection).
95+- **Instead.** Protect the default branch and make your workflows
96+ [required checks](/guides/pull-requests/#required-status-checks). To react
97+ after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`.
98+- **Status.** Not scheduled for your own scripts. A hook in the store,
99+ which would let g1t enforce more before refs move, depends on Cloudflare.
100+
101+### Push protection skips very large pushes
102+
103+Very large pushes, by size or by number of commits, are not yet fully
104+scanned for secrets. Most pushes are scanned in full; we are raising the
105+limit by streaming the scan instead of reading the whole push at once.
106+
107+- **Why.** Scanning reads the whole push inside a Worker, which has 128 MB
108+ for everything it is doing at once. Past that size, scanning could fail
109+ the push outright.
110+- **Instead.** Push large histories in steps (see above), so each push is
111+ scanned. Secrets already in history are listed under
112+ [Secrets in history](/guides/security/#secrets-in-history).
113+- **Status.** Planned: scanning while the push streams, at any size.
114+
115+### Deleting history does not free storage
116+
117+Storage is counted from what is pushed, and the count only grows. Deleting
118+a branch, or force-pushing over commits, does not lower it.
119+
120+- **Why.** The git store does not say whether or when it reclaims space
121+ from objects nothing points to any more, or report how much a repository
122+ holds. So g1t cannot see it either.
123+- **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in
124+ a private repository and counts against you, tell us at
125+ [g1t.sh/support](https://g1t.sh/support).
126+- **Status.** Depends on Cloudflare. See
127+ [private repository storage](/guides/usage-and-billing/#private-repository-storage).
128+
129+## Pull requests and forks
130+
131+### Forks are only for pull requests
132+
133+You can't fork a repository into your own workspace. On g1t, a fork is a
134+pull request's own working copy, made when the pull request is opened.
135+
136+- **Why.** We built forks to isolate agents' work, one per pull request.
137+ See [Forks and branches](/concepts/forks/).
138+- **Instead.** To contribute, open a pull request: it gets its own fork. To
139+ start a copy of your own, clone the repository and push it to a new one
140+ in your workspace; pushing creates it.
141+- **Status.** Not scheduled.
142+
143+### Pull request forks are kept after they close
144+
145+A pull request's fork stays after the pull request merges or closes.
146+
147+- **Why.** Cloudflare has not documented whether a fork shares stored
148+ objects with its source or copies them, and the answer decides how and
149+ when forks should be cleaned up.
150+- **Instead.** Nothing you need to do.
151+- **Status.** Deleting forks some time after their pull request closes is
152+ planned. Clear fork storage rules depend on Cloudflare.
153+
154+### No conflict resolution in the browser
155+
156+You can't resolve a merge conflict on the pull request's page.
157+
158+- **Instead.** Ask a g1t agent to resolve it, or fix it on the command line.
159+ See [Conflicts](/guides/pull-requests/#conflicts).
160+- **Status.** Planned.
161+
162+## Actions and runners
163+
164+### No Docker in g1t's sandboxes
165+
166+On g1t's own machines, Docker container actions, `services:` containers and
167+`container:` do not run, and a step cannot run `docker build`.
168+
169+- **Why.** Jobs run in Cloudflare Containers, which offer no supported way
170+ to run Docker or another image builder inside a container.
171+- **Instead.** Run those jobs on a [self-hosted runner](/guides/self-hosted-runners/).
172+ A runner in Docker mode runs each job in its `container:` image. To build
173+ images, register a runner with `--no-docker` on a machine that has Docker,
174+ and its steps can call `docker build` and `docker push`. Self-hosted time
175+ costs nothing.
176+- **Status.** Image builds on g1t's machines depend on Cloudflare.
177+
178+### Linux only on g1t's machines
179+
180+A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own
181+machines.
182+
183+- **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux,
184+ macOS and Windows, on x64 and arm64.
185+- **Status.** Not scheduled.
186+
187+### Machine sizes, time and storage
188+
189+| Limit | Value |
190+| --- | --- |
191+| Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. |
192+| One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. |
193+| One cache entry | 2 GB, compressed. A larger one is not saved. |
194+| A repository's caches | 10 GB together. Past it, the entries restored longest ago are removed. |
195+| One artifact | 60 MB, kept for 14 days |
196+
197+The machine sizes are Cloudflare Containers' instance sizes. For more, use a
198+[self-hosted runner](/guides/self-hosted-runners/). See
199+[Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache).
200+
201+### Workflow features not supported yet
202+
203+- Reusable workflows from another repository. Ones in the same repository
204+ work.
205+- Actions that cache through the hosted toolkit's own cache service, such as
206+ `setup-node` with `cache: npm`. They run without it; use `actions/cache`.
207+- Environments' protection rules: required reviewers, wait timers and branch
208+ limits. A job with `environment:` gets that environment's values and runs
209+ without waiting.
210+
211+See [Not yet](/guides/actions/#not-yet). **Status.** Planned.
212+
213+## Deployments
214+
215+### Static sites and Workers only
216+
217+Deployments run static sites and Workers projects. You can't deploy a
218+long-running server, a container, or an app that needs a process that stays
219+up.
220+
221+- **Why.** Apps run on Cloudflare Workers, which run only while they answer a
222+ request. That is why an app nobody visits costs nothing.
223+- **Instead.** Deploy the server from a workflow to wherever it runs today,
224+ with its credentials in [secrets](/guides/secrets-and-variables/).
225+- **Status.** A runtime for servers is planned.
226+
227+### Some Workers bindings are not provisioned
228+
229+A Workers project deploys without D1, KV, R2, Durable Objects, Queues,
230+service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its
231+cron triggers are not scheduled.
232+
233+- **Why.** Each of these is a resource g1t has to create and bill per
234+ project, and that is not built yet.
235+- **Instead.** Check that a binding exists before using it. The deployment
236+ lists each one it left out.
237+- **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects).
238+
239+### Build and size limits
240+
241+A build stops after 45 minutes. A static site can have up to 20,000 files
242+and 25 MiB per file, which are Cloudflare's limits. See
243+[Static sites](/guides/deployments/#static-sites).
244+
245+## Data residency
246+
247+You can't choose where a workspace's data is stored. g1t's databases keep
248+their primary copy in the United States, with read copies in other regions
249+so pages load fast. Repositories are not pinned to a region.
250+
251+- **Why.** Cloudflare fixes the region of a repository store when it is
252+ created, and g1t has one store so far.
253+- **Instead.** None today, if your data must stay in the EU.
254+- **Status.** EU residency, with an EU-only repository store and databases,
255+ is planned.
256+
257+## Billing
258+
259+### Some costs are not fully defined yet
260+
261+Cloudflare starts billing for Artifacts, where repositories are stored, on
262+October 14, 2026, and has not yet said exactly which calls count as a
263+billable operation.
264+
265+- **What g1t does.** It counts every clone, fetch and push through its git
266+ endpoints. Each day it checks what Cloudflare billed it for containers and
267+ apps against what was used. When a cost moves,
268+ g1t's price moves with it, and every change is listed with its reason on
269+ [g1t.sh/pricing](https://g1t.sh/pricing).
270+- **What this means for you.** Prices can change while Cloudflare's beta
271+ products settle. They follow cost.
272+ See [How prices are set](/guides/usage-and-billing/#how-prices-are-set)
273+ and [git operations](/guides/usage-and-billing/#git-operations).
274+- **Status.** Depends on Cloudflare.
275+
276+### Payments are in test mode
277+
278+While payments are in test mode, no real card is charged, and g1t's hosted
279+models are open only to g1t's own workspaces.
280+
281+- **Instead.** Connect your own [model provider](/guides/models/). Your
282+ agents then run on your keys, and the provider bills you directly.
283+- **Status.** Planned: hosted models for every workspace once payments go
284+ live.
285+
286+## Agents
287+
288+### Confidence is a judgement, not a guarantee
289+
290+The confidence g1t gives an agent's change, high, medium or low, is
291+worked out from what g1t can observe: checks, reviews, revisions, the size
292+and reach of the change. It cannot tell whether the change is correct.
293+
294+- **Instead.** Keep **Ask a person before merging low-confidence changes**
295+ on, and make your workflows required checks. A high rating on a
296+ repository with weak tests means less. See
297+ [How sure the agent is](/guides/g1t-agents/#how-sure-the-agent-is).
298+- **Status.** The signals and their weights may change as we learn from
299+ real changes.
300+
301+### Agents' model calls go through g1t
302+
303+An agent's model requests always pass through g1t's model proxy,
304+`models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox
305+straight at a provider.
306+
307+- **Why.** So that no key is ever inside a sandbox, and so budgets, caps and
308+ the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox).
309+- **Status.** Not planned. This is by design.
310+
311+## Accounts, status and self-hosting
312+
313+### Sign-up needs an invite
314+
315+g1t is invite-only for now. See [Invites](/guides/authentication/#invites).
316+**Status.** Opening sign-up is planned.
317+
318+### No uptime commitment during the beta
319+
320+g1t does not promise a particular uptime or offer a service level agreement
321+unless you have a written agreement with us. Several of the Cloudflare
322+products g1t is built on are in beta and have none either.
323+[status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing,
324+and every incident. Sandboxes are not checked there yet. See
325+[Status and incidents](/guides/status/). **Status.** Not scheduled during
326+the beta.
327+
328+### Self-hosting is early
329+
330+[Running g1t yourself](/guides/self-hosting/) gives you the core forge:
331+accounts, repositories over HTTP, issues and pull requests. g1t agents,
332+Actions, deployments, git over SSH, the REST API and MCP are off, and it is
333+not ready for the open internet. **Status.** Planned, in phases.
334+
335+### Not built yet
336+
337+- **Milestones.** Planned.
338+- **Releases and package registries.** Planned.
339+- **Wikis.** Not scheduled. Keep docs in the repository.
+3−3
5050
5151 ### Forks are cheap here
5252
53−A fork on g1t is copy-on-write. Creating one does not copy the repository's
54−history; the fork shares it and stores only what changes. A fork of a large
55−repository is ready in about the time a branch would be.
53+Creating a fork on g1t takes one call and is ready in about the time a
54+branch would be, even for a large repository. Forks don't count toward
55+your workspace's storage.
5656
5757 ### Anyone's agent can contribute
5858
+3−1
226226
227227 ## What is not built yet
228228
229−g1t is under active development. These are designed but not available yet:
229+g1t is under active development. These are designed but not available yet
230+(every current limit, and why, is on
231+[What g1t can't do yet](/about/limitations/)):
230232
231233 - **Milestones.**
232234 - **g1t agents for everyone.** g1t can put its own agents on an issue, each
+3−0
6565 [values](/guides/secrets-and-variables/#a-value-per-environment), and runs
6666 without waiting.
6767
68+Why each of these is missing, and what to use instead, is on
69+[What g1t can't do yet](/about/limitations/#actions-and-runners).
70+
6871 ## The runner
6972
7073 Jobs run in a fresh sandbox each: Debian with Node 24, Python 3, Go, Rust,
+3−0
106106 lists each one it left out. Code that needs them should check that the
107107 binding is there.
108108
109+What Deployments cannot run yet, such as long-running servers, is on
110+[What g1t can't do yet](/about/limitations/#deployments).
111+
109112 ## Addresses of other projects
110113
111114 A project that [depends on another](/guides/projects/#dependencies) with
+4−1
122122 Repositories are stored in Cloudflare Artifacts, which limits a repository to
123123 1 GB and a single file to 32 MB. A single push is limited to 100 MB.
124124
125−Each clone, fetch and push is a git operation. Every workspace has 10,000
125+Each clone, fetch and push is a git operation. Every workspace has 50,000
126126 a month included. Past that, a workspace on the g1t plan pays $0.18 per
127127 1,000, and a free workspace is never charged: past 50,000 in a month, its
128128 git requests past 60 in an hour are answered `429` with when to try again,
129129 until the month turns. Counting starts on 2026-10-14. See
130130 [git operations](/guides/usage-and-billing/#git-operations).
131131
132+What these limits mean in practice, and what to do instead, is on
133+[What g1t can't do yet](/about/limitations/#git).
134+
132135 ## Where a slow request's time went
133136
134137 Every answer g1t gives git carries a `Server-Timing` header: how many
+3−0
3030 | Git over SSH, the REST API, MCP and the `g1t` CLI | Not available yet |
3131 | Scheduled jobs (webhook retries, Actions schedules) | Not run yet |
3232
33+What hosted g1t cannot do yet either is on
34+[What g1t can't do yet](/about/limitations/).
35+
3336 ## Before you start
3437
3538 - Docker with Compose v2 (`docker compose version`).
+4−0
253253 measurement far from the current cost is not adopted, only logged, so
254254 one odd day cannot reprice anything.
255255
256+Some of the Cloudflare products g1t pays for are in beta and do not yet
257+define exactly what they bill; see
258+[What g1t can't do yet](/about/limitations/#billing).
259+
256260 ### Sandbox time
257261
258262 Every sandbox g1t starts runs on Cloudflare Containers, and Cloudflare
+5−0
9797 />
9898 </CardGrid>
9999
100+## Know the limits
101+
102+[What g1t can't do yet](/about/limitations/) lists every limit you can
103+hit today, why it exists, what to do instead, and whether it is planned.
104+
100105 ## Using an AI assistant?
101106
102107 Give it [g1t.sh/llms.txt](https://g1t.sh/llms.txt), which describes g1t for
+0−338
1−---
2−title: What g1t can't do yet
3−description: The limits you can hit on g1t today, why each one exists, what to do instead, and whether it is planned.
4−---
5−
6−This page lists what g1t cannot do today. Each entry says what you can't
7−do, why, what to do instead, and where it stands.
8−
9−Where it stands is one of:
10−
11−- **Planned**: we intend to build it. We don't give dates we can't keep.
12−- **Depends on Cloudflare**: g1t runs on Cloudflare, and this needs
13− something the platform does not offer yet.
14−- **Not scheduled**: no work is planned on it now.
15−
16−Several of these depend on Cloudflare; [we wrote to them about it](/about/open-letter-to-cloudflare/).
17−
18−If you hit a limit that is not here, tell us at
19−[g1t.sh/support](https://g1t.sh/support), and we will add it.
20−
21−## Git
22−
23−### No git over SSH
24−
25−You can reach repositories only over HTTPS. A `git@g1t.sh:…` remote does
26−not work.
27−
28−- **Why.** SSH needs inbound TCP connections on port 22. g1t runs on
29− Cloudflare Workers, which accept HTTP, not raw TCP. Cloudflare has a beta
30− for inbound TCP; we have applied and are waiting.
31−- **Instead.** Use the HTTPS remote with an
32− [access token](/guides/git/#authentication). It does everything SSH would:
33− clone, fetch and push. SSH keys you add under **Settings → SSH keys** are
34− kept for when SSH arrives.
35−- **Status.** Depends on Cloudflare. See [Git](/guides/git/#ssh).
36−
37−### Repositories up to 1 GB, files up to 32 MB, no LFS
38−
39−A repository can hold up to 1 GB and a single file up to 32 MB. Git LFS is
40−not supported.
41−
42−- **Why.** These are the limits of Cloudflare Artifacts, where every
43− repository is stored. g1t does not check them before a push reaches the
44− store yet, so a push that crosses them fails late, and git's message may
45− not say why.
46−- **Instead.** Keep large binaries out of the repository: in a release
47− bucket, a package registry or object storage, fetched at build time.
48−- **Status.** Checking both limits before the push, with a message git
49− shows you, is planned. Large file storage is planned. Raising the limits
50− themselves depends on Cloudflare.
51−
52−### Pushes up to 100 MB each
53−
54−A single push can carry up to 100 MB. A larger one is refused with HTTP
55−`413` before g1t sees it.
56−
57−- **Why.** Cloudflare's network limits the size of one request body on the
58− plan g1t.sh is on.
59−- **Instead.** Push history in steps, oldest first:
60− `git push origin <older-commit>:refs/heads/main`, then a newer one, then
61− `main`. Each push sends only what the last did not.
62−- **Status.** Depends on Cloudflare.
63−
64−### Imports and mirrors up to 40 MB
65−
66−Importing or mirroring a repository copies it in one piece of at most
67−40 MB, after compression.
68−
69−- **Why.** The copy is held in memory while it moves, and a Worker has
70− 128 MB for everything it is doing at once.
71−- **Instead.** Clone the repository yourself and push it to g1t, in steps if
72− it is over 100 MB. See [Import, mirror or move a repository](/guides/github/#what-comes-across).
73−- **Status.** Streaming the copy, so size stops mattering, is planned.
74−
75−### Partial clone works, but is not promised
76−
77−`git clone --filter=blob:none` returns a real partial clone today. We don't
78−promise it will keep doing so.
79−
80−- **Why.** Cloudflare's documentation says filters are not supported, but
81− they work with git's protocol version 2. We have asked whether that is
82− intended.
83−- **Instead.** Use it, and fall back to `--depth=1` for a shallow clone,
84− which is supported.
85−- **Status.** Depends on Cloudflare.
86−
87−### No server-side hooks of your own
88−
89−You can't run a script of your own on g1t when a push arrives, before or
90−after its refs move.
91−
92−- **Why.** The git store has no hook for this. g1t's own checks run in front
93− of it, in g1t's code: [protected branches](/guides/git/#protected-branches)
94− and [push protection](/guides/security/#push-protection).
95−- **Instead.** Protect the default branch and make your workflows
96− [required checks](/guides/pull-requests/#required-status-checks). To react
97− after a push, use a [webhook](/guides/webhooks/) or a workflow on `push`.
98−- **Status.** Not scheduled for your own scripts. A hook in the store,
99− which would let g1t enforce more before refs move, depends on Cloudflare.
100−
101−### Push protection skips very large pushes
102−
103−A push larger than about 24 MB is not scanned for secrets. In a push of more
104−than 300 commits, only the first 300 are scanned.
105−
106−- **Why.** Scanning reads the whole push inside a Worker, which has 128 MB
107− for everything it is doing at once. Past that size, scanning could fail
108− the push outright.
109−- **Instead.** Push large histories in steps (see above), so each push is
110− scanned. Secrets already in history are listed under
111− [Secrets in history](/guides/security/#secrets-in-history).
112−- **Status.** Planned: scanning while the push streams, at any size.
113−
114−### Deleting history does not free storage
115−
116−Storage is counted from what is pushed, and the count only grows. Deleting
117−a branch, or force-pushing over commits, does not lower it.
118−
119−- **Why.** The git store does not say whether or when it reclaims space
120− from objects nothing points to any more, or report how much a repository
121− holds. So g1t cannot see it either.
122−- **Instead.** Keep large mistakes out with a `.gitignore`. If one landed in
123− a private repository and counts against you, tell us at
124− [g1t.sh/support](https://g1t.sh/support).
125−- **Status.** Depends on Cloudflare. See
126− [private repository storage](/guides/usage-and-billing/#private-repository-storage).
127−
128−## Pull requests and forks
129−
130−### Forks are only for pull requests
131−
132−You can't fork a repository into your own workspace. On g1t, a fork is a
133−pull request's own working copy, made when the pull request is opened.
134−
135−- **Why.** We built forks to isolate agents' work, one per pull request.
136− See [Forks and branches](/concepts/forks/).
137−- **Instead.** To contribute, open a pull request: it gets its own fork. To
138− start a copy of your own, clone the repository and push it to a new one
139− in your workspace; pushing creates it.
140−- **Status.** Not scheduled.
141−
142−### Pull request forks are kept after they close
143−
144−A pull request's fork stays after the pull request merges or closes.
145−
146−- **Why.** Cloudflare has not documented whether a fork shares stored
147− objects with its source or copies them, and the answer decides how and
148− when forks should be cleaned up.
149−- **Instead.** Nothing you need to do.
150−- **Status.** Deleting forks some time after their pull request closes is
151− planned. Clear fork storage rules depend on Cloudflare.
152−
153−### No conflict resolution in the browser
154−
155−You can't resolve a merge conflict on the pull request's page.
156−
157−- **Instead.** Ask a g1t agent to resolve it, or fix it on the command line.
158− See [Conflicts](/guides/pull-requests/#conflicts).
159−- **Status.** Planned.
160−
161−## Actions and runners
162−
163−### No Docker in g1t's sandboxes
164−
165−On g1t's own machines, Docker container actions, `services:` containers and
166−`container:` do not run, and a step cannot run `docker build`.
167−
168−- **Why.** Jobs run in Cloudflare Containers, which offer no supported way
169− to run Docker or another image builder inside a container.
170−- **Instead.** Run those jobs on a [self-hosted runner](/guides/self-hosted-runners/).
171− A runner in Docker mode runs each job in its `container:` image. To build
172− images, register a runner with `--no-docker` on a machine that has Docker,
173− and its steps can call `docker build` and `docker push`. Self-hosted time
174− costs nothing.
175−- **Status.** Image builds on g1t's machines depend on Cloudflare.
176−
177−### Linux only on g1t's machines
178−
179−A job with `runs-on: windows-latest` or `macos-latest` fails on g1t's own
180−machines.
181−
182−- **Instead.** [Self-hosted runners](/guides/self-hosted-runners/) run Linux,
183− macOS and Windows, on x64 and arm64.
184−- **Status.** Not scheduled.
185−
186−### Machine sizes, time and storage
187−
188−| Limit | Value |
189−| --- | --- |
190−| Largest machine | 4 vCPUs, 12 GiB of memory, 20 GB of disk (`g1t-4core`). No GPUs. |
191−| One job on g1t's machines | 60 minutes. On a self-hosted runner, 24 hours. |
192−| One cache entry | 2 GB, compressed. A larger one is not saved. |
193−| A repository's caches | 10 GB together. Past it, the entries restored longest ago are removed. |
194−| One artifact | 60 MB, kept for 14 days |
195−
196−The machine sizes are Cloudflare Containers' instance sizes. For more, use a
197−[self-hosted runner](/guides/self-hosted-runners/). See
198−[Machine sizes](/guides/actions/#machine-sizes) and [the cache](/guides/actions/#the-cache).
199−
200−### Workflow features not supported yet
201−
202−- Reusable workflows from another repository. Ones in the same repository
203− work.
204−- Actions that cache through the hosted toolkit's own cache service, such as
205− `setup-node` with `cache: npm`. They run without it; use `actions/cache`.
206−- Environments' protection rules: required reviewers, wait timers and branch
207− limits. A job with `environment:` gets that environment's values and runs
208− without waiting.
209−
210−See [Not yet](/guides/actions/#not-yet). **Status.** Planned.
211−
212−## Deployments
213−
214−### Static sites and Workers only
215−
216−Deployments run static sites and Workers projects. You can't deploy a
217−long-running server, a container, or an app that needs a process that stays
218−up.
219−
220−- **Why.** Apps run on Cloudflare Workers, which run only while they answer a
221− request. That is why an app nobody visits costs nothing.
222−- **Instead.** Deploy the server from a workflow to wherever it runs today,
223− with its credentials in [secrets](/guides/secrets-and-variables/).
224−- **Status.** A runtime for servers is planned.
225−
226−### Some Workers bindings are not provisioned
227−
228−A Workers project deploys without D1, KV, R2, Durable Objects, Queues,
229−service bindings, Vectorize, Hyperdrive, Workers AI or Workflows, and its
230−cron triggers are not scheduled.
231−
232−- **Why.** Each of these is a resource g1t has to create and bill per
233− project, and that is not built yet.
234−- **Instead.** Check that a binding exists before using it. The deployment
235− lists each one it left out.
236−- **Status.** Planned. See [Workers projects](/guides/deployments/#workers-projects).
237−
238−### Build and size limits
239−
240−A build stops after 45 minutes. A static site can have up to 20,000 files
241−and 25 MiB per file, which are Cloudflare's limits. See
242−[Static sites](/guides/deployments/#static-sites).
243−
244−## Data residency
245−
246−You can't choose where a workspace's data is stored. g1t's databases keep
247−their primary copy in the United States, with read copies in other regions
248−so pages load fast. Repositories are not pinned to a region.
249−
250−- **Why.** Cloudflare fixes the region of a repository store when it is
251− created, and g1t has one store so far.
252−- **Instead.** None today, if your data must stay in the EU.
253−- **Status.** EU residency, with an EU-only repository store and databases,
254− is planned.
255−
256−## Billing
257−
258−### Some costs are not fully defined yet
259−
260−Cloudflare starts billing for Artifacts, where repositories are stored, on
261−October 14, 2026, and has not yet said exactly which calls count as a
262−billable operation.
263−
264−- **What g1t does.** It counts every clone, fetch and push through its git
265− endpoints. Each day it checks what Cloudflare billed it for containers and
266− apps against what was used. When a cost moves,
267− g1t's price moves with it, and every change is listed with its reason on
268− [g1t.sh/pricing](https://g1t.sh/pricing).
269−- **What this means for you.** Prices can change while Cloudflare's beta
270− products settle. They follow cost.
271− See [How prices are set](/guides/usage-and-billing/#how-prices-are-set)
272− and [git operations](/guides/usage-and-billing/#git-operations).
273−- **Status.** Depends on Cloudflare.
274−
275−### Payments are in test mode
276−
277−While payments are in test mode, no real card is charged, and g1t's hosted
278−models are open only to g1t's own workspaces.
279−
280−- **Instead.** Connect your own [model provider](/guides/models/). Your
281− agents then run on your keys, and the provider bills you directly.
282−- **Status.** Planned: hosted models for every workspace once payments go
283− live.
284−
285−## Agents
286−
287−### Confidence is a judgement, not a guarantee
288−
289−The confidence g1t gives an agent's change, high, medium or low, is
290−worked out from what g1t can observe: checks, reviews, revisions, the size
291−and reach of the change. It cannot tell whether the change is correct.
292−
293−- **Instead.** Keep **Ask a person before merging low-confidence changes**
294− on, and make your workflows required checks. A high rating on a
295− repository with weak tests means less. See
296− [How sure the agent is](/guides/g1t-agents/#how-sure-the-agent-is).
297−- **Status.** The signals and their weights may change as we learn from
298− real changes.
299−
300−### Agents' model calls go through g1t
301−
302−An agent's model requests always pass through g1t's model proxy,
303−`models.g1t.sh`, with your keys or g1t's. You can't point an agent's sandbox
304−straight at a provider.
305−
306−- **Why.** So that no key is ever inside a sandbox, and so budgets, caps and
307− the audit log hold. See [Your keys never reach a sandbox](/guides/models/#your-keys-never-reach-a-sandbox).
308−- **Status.** Not planned. This is by design.
309−
310−## Accounts, status and self-hosting
311−
312−### Sign-up needs an invite
313−
314−g1t is invite-only for now. See [Invites](/guides/authentication/#invites).
315−**Status.** Opening sign-up is planned.
316−
317−### No uptime commitment during the beta
318−
319−g1t does not promise a particular uptime or offer a service level agreement
320−unless you have a written agreement with us. Several of the Cloudflare
321−products g1t is built on are in beta and have none either.
322−[status.g1t.sh](https://status.g1t.sh/) shows how each part of g1t is doing,
323−and every incident. Sandboxes are not checked there yet. See
324−[Status and incidents](/guides/status/). **Status.** Not scheduled during
325−the beta.
326−
327−### Self-hosting is early
328−
329−[Running g1t yourself](/guides/self-hosting/) gives you the core forge:
330−accounts, repositories over HTTP, issues and pull requests. g1t agents,
331−Actions, deployments, git over SSH, the REST API and MCP are off, and it is
332−not ready for the open internet. **Status.** Planned, in phases.
333−
334−### Not built yet
335−
336−- **Milestones.** Planned.
337−- **Releases and package registries.** Planned.
338−- **Wikis.** Not scheduled. Keep docs in the repository.
+5−1
485485 - Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths,
486486 `{owner}` is the workspace. Pull request forks:
487487 `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available.
488−- Limits: 1 GB per repository, 32 MB per file, 100 MB per push.
488+- Limits: 1 GB per repository, 32 MB per file, 100 MB per push. Every
489+ current limit, why it exists and the workaround:
490+ https://docs.g1t.sh/about/limitations/
489491 - Forgotten password: https://g1t.sh/forgot (the person does this, in a
490492 browser).
491493 - Times are RFC 3339 in UTC.
541543 - [Git](https://docs.g1t.sh/guides/git/)
542544 - [MCP tools](https://docs.g1t.sh/reference/mcp/)
543545 - [API reference](https://docs.g1t.sh/reference/api/)
546+- [What g1t can't do yet](https://docs.g1t.sh/about/limitations/)
547+- [An open letter to Cloudflare](https://docs.g1t.sh/about/open-letter-to-cloudflare/)
544548 - [Source](https://g1t.sh/flagon-io/g1t), MIT licensed
545549
546550 ## Help, status and policies