README.md
sudo
g1t's staff console, at https://sudo.g1t.sh. Staff use it to manage how accounts pay: comp a workspace, set custom terms (a discount, a ceiling on unpaid usage, an end date), create Enterprise accounts that pay for several workspaces, move workspaces on and off them, issue credits, and see where every account stands this month with its ledger and audit log.
It holds no data. Everything goes to the billing service's staff methods
(admin_*, see BillingAdminApi in packages/contracts/src/billing.ts),
and each change is recorded there with the staff member's email.
How it is locked
- Cloudflare Access sits in front of
sudo.g1t.shand signs people in. - The worker checks Access's work on every request, the stylesheet
included (
run_worker_first): it verifies theCf-Access-Jwt-AssertionJWT itself (RS256 against the team's published keys, audience, issuer, expiry), then requires its email to be inSTAFF_EMAILS. That email is who every change is recorded as. Seeapp/lib/access.ts. - It fails closed. Until
ACCESS_TEAM_DOMAIN,ACCESS_AUDandSTAFF_EMAILSare all set, every request gets a 403 saying sudo is not configured. - Changes are POSTs only, and only from sudo's own pages (
Origin, orReferer, must behttps://sudo.g1t.sh). Terms, enterprise moves and new enterprises show a confirmation step first; a credit needs the workspace's slug typed out. - The pages ship no JavaScript. The content security policy forbids
every script and inline style; responses are
no-store,noindexand cannot be framed. The worker has noworkers.devaddress or preview URLs.
Setting up Access (once, in the Cloudflare dashboard)
-
Zero Trust → Access → Applications → Add an application → Self-hosted.
- Application name:
sudo. - Session duration: short, such as 8 hours.
- Public hostname:
sudo.g1t.sh(path empty, so it covers everything).
- Application name:
-
Add a policy (
g1t staff): action Allow, include Emails → the owner's address, and Emails ending in →g1t.shfor everyone with a g1t address (the same entries asSTAFF_EMAILS, where a domain is written@g1t.sh). Add more staff here and inSTAFF_EMAILS; either one alone is not enough. -
Save, then open the application's Overview (or Basic information) and copy the Application Audience (AUD) tag.
-
Find the team domain under Zero Trust → Settings → Custom pages (or Team name and domain): it looks like
<team>.cloudflareaccess.com. -
Put both into
wrangler.jsonc:"vars": { "ACCESS_TEAM_DOMAIN": "<team>.cloudflareaccess.com", "ACCESS_AUD": "<the AUD tag>", "STAFF_EMAILS": "syntaqx@gmail.com, @g1t.sh" }jsonc -
Deploy:
scripts/deploy.sh sudo(afterbilling, whoseadmin_*methods it calls).
Visit https://sudo.g1t.sh: Access asks you to sign in, then the accounts
list opens. Anyone else gets Access's own refusal; anyone Access lets in who
is not in STAFF_EMAILS gets a 403 from the worker.
Working on it
npm run typecheck -w @g1t/sudo
npm test -w @g1t/sudo # JWT verification, forms, money
npm run build -w @g1t/sudonpm run dev serves the pages, but every request is refused without a real
Access token, by design.