Repository · ccantynz
Strong

Gluecron itself — self-hosted on Gluecron.

main216 branches48 files · 18 dirsUpdated 14h ago
CodeIssuesPull RequestsActionsSecurityInsights
✨ AI
More
Settings
chore/design-wave0chore/estate-hygienechore/heartbeat-off-githubchore/onfailure-unitsclaude/adoring-hopper-5x74bqclaude/affectionate-feynman-ykrf1hclaude/architecture-audit-design-wxprenclaude/build-status-update-3MXsfclaude/charming-meitner-mllb5rclaude/compare-gate-gluecron-s4mFQclaude/confident-faraday-tikcwbclaude/continue-work-XMTlIclaude/crontech-gluecron-deploy-7MIECclaude/crontech-platform-setup-SeKfwclaude/design-2026claude/ecstatic-ptolemy-jMdigclaude/enhance-github-integration-QNHdGclaude/fix-aa-loop-issue-PonMQclaude/fix-actions-and-processclaude/fix-desktop-errors-XqoW8claude/fix-red-workflowsclaude/fix-website-access-6FKJNclaude/gatetest-integration-hardeningclaude/github-audit-improvements-bDFr9claude/gluecron-launch-status-FoMRlclaude/hopeful-lamport-olfCTclaude/issue-to-pr-and-protectionsclaude/jolly-heisenberg-2sg1Qclaude/launch-preparation-QmTb6claude/new-session-xk1l7claude/plan-platform-architecture-kkN4yclaude/platform-analysis-roadmap-1nUGLclaude/platform-launch-assessment-8dWV8claude/polish-platform-release-AeDrUclaude/resume-previous-work-KzyLwclaude/review-crontech-handoff-qYEVqclaude/review-project-completeness-lHhS2claude/review-readme-docs-ulqPKclaude/serene-edison-rj87weclaude/setup-multi-repo-dev-BCwNQclaude/ship-fixes-and-tests-Jvz1cclaude/site-audit-competitive-pctlwgclaude/site-migration-vercel-XstpKclaude/standalone-product-repos-XHFTDcopilot/feat-smart-empty-states-keyboard-first-enhancementcopilot/feat-smart-morning-digest-review-context-restorecopilot/fix-and-process-workflowscopilot/update-ai-powered-code-reviewdesign/emptiness-and-connectdocs/161-rebuild-runbookdocs/agent-briefdocs/attribution-guarantee-honestdocs/audit-2026-08-19-finaldocs/ci-run-conclusionsdocs/design-sweep-findingsdocs/mission-control-blueprintdocs/next-moves-finaldocs/slim-claude-mddocs/zero-noise-visionfeat/161-phase2-bridgefeat/admin-ai-model-tiersfeat/admin-ai-provider-healthfeat/agent-onboarding-brieffeat/ai-daily-budgetfeat/ai-outage-cachefeat/api-list-workflow-runsfeat/api-v2-merge-endpointfeat/building-itself-proof-pagefeat/ci-job-brokerfeat/ci-sidecar-runnerfeat/ci-test-gatefeat/debt-mapfeat/deploy-failure-alertsfeat/derived-activity-feedfeat/drain-repairs-commandfeat/email-estate-railfeat/enforce-branch-protectionfeat/estate-watchfeat/github-compat-shimfeat/grouped-security-findingsfeat/health-design-passfeat/health-improvement-enginefeat/health-repair-buttonfeat/hosted-sshfeat/http-push-auditfeat/infra-secrets-panelfeat/internal-repairs-on-subscriptionfeat/lfs-batch-apifeat/live-changelogfeat/live-edit-streamingfeat/manual-first-2026-08-19feat/mechanical-tier-firstfeat/medic-spine-doctorfeat/model-provider-portabilityfeat/nav-iafeat/next-moves-2026-08-19feat/no-purple-ever-gatefeat/osv-advisoriesfeat/paging-drillfeat/push-policy-codeowners-hardeningfeat/real-email-addressesfeat/rendered-fact-crosscheckfeat/repo-nav-coherencefeat/reporting-epochfeat/review-ergonomicsfeat/run-actionsfeat/runner-concurrencyfeat/runner-load-guardfeat/ship-path-ai-independencefeat/signal-precisionfeat/smart-digest-contextfeat/spec-failure-queuefeat/spine-alert-fanoutfeat/spine-health-systemfeat/spine-heartbeatsfeat/spine-peer-watchfeat/stage-impactfeat/synthetic-journeysfeat/t1-secret-migrationfeat/truth-ledgerfeat/u-polishfeat/w-self-hostfeat/w2-claude-configfix/admin-quota-exemptionfix/agent-journey-orphan-sweepfix/api-v2-state-allfix/archaeology-stops-leaking-provider-errorsfix/audit-sweep-2026-07-26fix/billing-aware-anthropic-probefix/broker-socket-accessfix/caddy-cotenant-inertfix/ci-gate-fails-openfix/ci-healer-diagnosisfix/ci-no-steps-executedfix/ci-oom-ceilingfix/ci-workdir-permissionsfix/ci-workspace-leakfix/clone-url-and-content-encodingfix/close-signup-during-buildoutfix/deploy-script-2026-08-19fix/digest-palette-and-design-auditfix/emergency-pat-selfhostfix/empty-repo-ctafix/estate-scoped-statusfix/explore-discovery-opt-infix/feed-dedupe-integration-rowsfix/first-pr-dead-endsfix/gate-diff-was-the-seventh-unvalidated-git-reffix/greeting-local-timefix/healer-defer-transientfix/honest-ai-liveness-copyfix/honest-ai-review-gatefix/honest-merge-conflict-promisesfix/import-bulk-user-accountsfix/import-default-branchfix/import-onconflict-partial-indexfix/journey-freshness-watchedfix/landing-rebuildfix/login-500-on-malformed-hashfix/merge-fires-push-workflowsfix/merged-pr-empty-difffix/mirror-sync-cannot-report-ok-while-deadfix/mirror-sync-would-destroy-local-only-historyfix/nav-audit-flagged-any-number-400-to-499fix/oauth-consent-shows-destinationfix/onboarding-honestyfix/outage-must-not-block-mergefix/override-caddy-under-servicesfix/post-receive-repaired-repos-it-could-not-identifyfix/precision-publication-gatefix/proof-page-polishfix/quota-exemption-canonical-adminfix/rate-limit-htmlfix/readiness-no-browserfix/readiness-wave-2fix/reinstate-raw-sql-scannerfix/repair-queue-owner-onlyfix/repo-freshness-corroborationfix/requeue-runs-orphaned-by-restartfix/run-branch-filterfix/runner-concurrency-defaultfix/runner-readinessfix/security-scan-and-ci-honestyfix/selfcheck-critical-was-permanent-and-benignfix/ssh-hostkey-formatfix/state-filter-parityfix/status-heartbeat-honestyfix/status-page-stops-fabricating-service-healthfix/theme-toggle-digest-collisionfix/trust-critical-pagesfix/untimed-spawn-and-stale-deploy-docfix/verify-deploy-supersededfix/verify-deploy-wgetfix/website-honesty-2026-08-19fix/workflow-runner-block-scalarsgatetest/auto-fix-1776586424172gatetest/auto-fix-1776586534814gatetest/auto-fix-1776590685143gatetest/auto-fix-1776590808199honest-contributor-identitymainops/redeploy-retriggerperf/history-page-cachingpr-ledger-truthrecover/github-forkrestore-drill-ownershiprestore/sweep-consolidationstyle/dxt-cta-themesweep/billing-bannersweep/dashboardsweep/docs-admin-themesweep/issues-surfacessweep/notificationssweep/pr-detailworktree-agent-a3377aad30d55da26worktree-agent-a7ef607b7ee1d6c74
.claudefix(billing): the subscription repair queue is operator-only; customers meter on their quota24 days ago
.githubdocs(heartbeat): the workflow described a watchdog nobody built4 days ago
.gluecronfix(ci): a deploy that was overtaken is not a deploy that failed21 hours ago
.huskyfix(gate): skip prSize for batch platform releases3 months ago
clifeat(ai-commit): gluecron commit + prepare-commit-msg hook — Claude writes commit messages3 months ago
docsfeat(ci): a container per job — jobs isolated from each other, not just the app22 hours ago
drizzlefeat(protection): branch protection is enforced at push time — the checkboxes stop lying5 days ago
e2etest(e2e): add PR command center smoke test + missing-git-repo regression2 months ago
editor-extensionsfeat(jetbrains): JetBrains plugin — chat / commit / PRs / specs / voice in IntelliJ + WebStorm + GoLand + PyCharm3 months ago
extensionfeat(site): stop advertising liveness and proving deadness28 days ago
infrafeat(ops): metal-box deploy checklist + verify script + alert rules4 months ago
jetbrains-pluginAdd JetBrains plugin skeleton — IntelliJ/WebStorm/GoLand support2 months ago
legalfeat(launch-polish): audit report + backup-restore drill + DPA template3 months ago
mobilefix: break circular imports in mobile navigation by extracting types2 months ago
publicfeat(BLOCK-Q): zero-friction onboarding paths — .dxt + magic link + anonymous playground3 months ago
scriptsfix(journey): the first-run monitor carries the invite code1 day ago
srcfix(ci): moving checkouts to a shared volume made them leak forever22 hours ago
vscode-extensionfeat(BLOCK-G): G1 PWA + G2 GraphQL + G3 CLI + G4 VS Code extension4 months ago
.dockerignorefix(docker): stop excluding files the Dockerfile needs4 months ago596 B
.env.examplefix(ci): the broker reported healthy while unable to reach docker at all22 hours ago29.4 KB
.eslintrc.jsonfix: address GateTest and Fly Deploy workflow failures4 months ago190 B
.gatetest.jsonfix(gatetest): expand quick-suite exclusions for pre-existing findings3 months ago911 B
.gitattributestest: fix 12 false-failing tests — line endings, Windows paths, stale landing markup1 month ago481 B
.gitignorechore: ignore root-level scratch scripts1 month ago1.1 KB
.mcp.jsonfix: declare Gluecron MCP server in .mcp.json so sessions actually load it2 months ago190 B
AUDIT_REPORT.mdaudit: full-platform audit 2026-06-10 — green suite restored, docs reconciled2 months ago6.8 KB
AUDIT-2026-06-10.mddocs: consolidate status tracking into STATUS.md1 month ago287 B
AUDIT-2026-07-07-CHECKLIST.mddocs: consolidate status tracking into STATUS.md1 month ago297 B
AUDIT-2026-07-09.mddocs: consolidate status tracking into STATUS.md1 month ago287 B
AUDIT-2026-07-14.mddocs: consolidate status tracking into STATUS.md1 month ago360 B
AUDIT-v2.mdaudit: full-platform audit 2026-06-10 — green suite restored, docs reconciled2 months ago9.3 KB
AUDIT.mdaudit: full-platform audit 2026-06-10 — green suite restored, docs reconciled2 months ago6.8 KB
BUILD_BIBLE.mdfix(docs): CLAUDE.md described a deploy path that does not run1 month ago157.9 KB
bun.lockfeat(selfcheck): static self-diagnosis of the platform's own source1 month ago37.7 KB
bunfig.tomltest: stop the suite failing intermittently on git-heavy integration tests1 month ago950 B
Caddyfilefeat(deploy): one-command metal-box deploy via Caddy + compose4 months ago576 B
CHANGELOG.mddocs: consolidate status tracking into STATUS.md1 month ago261 B
CLAUDE.mdfix(merge-queue,docs): an untimed spawnSync on the request path, and a deploy doc its own test called stale20 days ago4.9 KB
DEPLOY_CHECKLIST.mdfix(docs): CLAUDE.md described a deploy path that does not run1 month ago4.2 KB
DEPLOY_METAL.mdfix(deploy): repoint docs from obsolete Vultr 45.76.171.37 to Hetzner Gluecron-1 178.104.208.2523 months ago2.8 KB
DEPLOY_VULTR.mddeploy: app-only Vultr config behind existing Bun proxy3 months ago2.2 KB
DEPLOY.mdfix(errors): the beacon covered 164 routes and missed the four that matter29 days ago15.1 KB
DO_THIS_NOW.mdfix(deploy): repoint docs from obsolete Vultr 45.76.171.37 to Hetzner Gluecron-1 178.104.208.2523 months ago2.9 KB
docker-compose.override.ymldeploy: app-only Vultr config behind existing Bun proxy3 months ago801 B
docker-compose.standalone.ymlfix(ci): the broker reported healthy while unable to reach docker at all22 hours ago15.9 KB
docker-compose.ymldeploy(standalone): wire Google OAuth env + add wget so healthcheck works2 months ago1.7 KB
Dockerfilefix(ci): an unwritable checkout dir must not take CI down platform-wide23 hours ago4.8 KB
drizzle.config.tsfix(drizzle): explicit error when DATABASE_URL is unset3 months ago470 B
eslint.config.cjsfeat(pr): code suggestions + admin task catalog3 months ago363 B
fly.tomlfix(auth): self-healing Google OAuth callback; drop Fly APP_BASE_URL dependency2 months ago574 B
GATETEST_HOOK.mdfeat: inbound GateTest callback hook + PAT-authed backup API4 months ago4.2 KB
gatetest.config.jsonfeat: /stage PR preview command + merge impact analysis — instant previews and "what breaks?" panel2 months ago3.8 KB
INCIDENT-2026-07-13-deploy-blip.mddocs(incident): 2026-07-13 deploy-window blip — root cause + follow-ups1 month ago2.8 KB
LAUNCH_TODAY.mdfeat: permissions, SSE foundation, preflight CLI, launch docs, DPA4 months ago5.9 KB
LICENSEfeat: Legal framework + legal pages served from website4 months ago1.0 KB
LICENSE-CHANGE-NOTICE.mdfeat: AGPL license-change notice + Anthropic outreach deck3 months ago3.4 KB
MIGRATE_TO_GLUECRON.mdfeat(phase-b): gluecron-on-gluecron migration tooling4 months ago3.4 KB
package.jsonfeat(readiness): a gate that never ran is not a gate that passed2 days ago1.7 KB
railway.tomlfeat: add Railway and Fly.io deployment configs4 months ago154 B
README.mdfeat(BLOCK-R): zero-terminal deploy loop — /admin/ops + SSE log streaming + fast-lane auto-merge + docs3 months ago8.4 KB
ROADMAP.mddocs: consolidate status tracking into STATUS.md1 month ago264 B
SECURITY.mdfeat(email): the role addresses are real — security.txt published, placeholders removed, From default fixed5 days ago1.1 KB
server.jsonchore(registry): trim description to registry 100-char limit — published as com.gluecron/gluecron v1.0.01 month ago437 B
STATUS.mdInitial commit1 month ago6.6 KB
TODO.mdchore: tick off JetBrains plugin as done2 months ago17.1 KB
tsconfig.jsonfix: typecheck green, 698/881 tests passing (was 0/881)4 months ago584 B
0 AI merges this week·Saved ~63.0 hrs·0 open security alerts
README.md

gluecron

A GitHub replacement. AI-native code intelligence, git hosting, automated CI, and a self-hostable platform built to keep every push production-ready. Every repo ships with gates, branch protection, CODEOWNERS sync, and an AI reviewer on by default — opt out per feature, never by default. Deploy anywhere Bun runs — fly.toml is in-repo, Dockerfile for any container host. Backed by Neon Postgres.

Features

Code hosting

  • Git Smart HTTP (clone / push / fetch) — subprocess-backed
  • SSH keys, personal access tokens, OAuth 2.0 provider
  • Public / private repos, forks, stars, topics, archive, transfer, template repos
  • Pull-style repository mirroring (upstream git URL, periodic fetch + audit log)
  • Releases, tags, protected tags
  • Repository rulesets — push policy engine covering commit/branch/tag patterns, blocked paths, file-size caps, force-push forbiddance

Code browsing

  • File tree, syntax highlighting (40+ languages), commit log, unified diffs, blame, raw
  • Branch + tag switcher, contributor list, commit activity graph
  • Code search (ILIKE) — per-repo and global
  • Semantic code search — Voyage voyage-code-3 when VOYAGE_API_KEY is set, deterministic hashing fallback otherwise
  • Symbol / xref navigation across ts/js/py/rs/go/rb/java/kt/swift
  • Dependency graph — npm / pip / poetry / go / cargo / rubygems / composer
  • Commit signature verification — GPG + SSH "Verified" badges

Collaboration

  • Issues, labels, milestones, issue templates, saved replies
  • Pull requests: inline review, draft PRs, AI triage on create, merge queues, required-checks matrix
  • Discussions (forum threads, q-and-a, pinned/locked)
  • Wikis (DB-backed, revision history + revert)
  • Projects / kanban boards
  • Gists (multi-file, per-revision snapshots, stars, secret)
  • Reactions (8 canonical emoji) on issues, PRs, and comments
  • Mentions, notifications, personalised activity feed, user follows, profile READMEs
  • Closing keywords auto-close issues on PR merge

AI-native

  • AI code review blocks merges on fail (requireAiApproval branch protection)
  • AI security review (Sonnet 4) + 15-pattern secret scanner on every push
  • AI commit messages, PR summaries, changelogs (per-range viewer + on release)
  • AI merge-conflict resolver, AI incident responder (auto-issue on deploy fail)
  • AI explain-this-codebase (per-commit cached Markdown)
  • AI-generated failing test stubs
  • AI dependency updater (opens a PR with a bump table)
  • Copilot-style completion endpoint (POST /api/copilot/completions, Haiku, LRU-cached)
  • AI chat — global and repo-scoped

Automation

  • Workflow runner — .gluecron/workflows/*.yml auto-discovered on push, Bun subprocess executor, per-step timeouts, size-capped logs
  • Outbound webhooks (HMAC-signed) on push / issue / PR / star
  • Inbound GateTest callback (bearer or HMAC)
  • Commit status API — external CI POSTs per-commit statuses, combined rollup
  • Auto-repair engine (rewrites broken commits when ANTHROPIC_API_KEY is set)
  • Autopilot background ticker — mirror sync, merge-queue processing, weekly email digests, advisory rescans (opt out via AUTOPILOT_DISABLED=1)
  • Dependabot-equivalent dep bumper + security advisories scanner
  • CODEOWNERS auto-sync with team-based resolution (@org/team)

Platform

  • Organizations + teams (owner / admin / member roles, team-based CODEOWNERS)
  • 2FA / TOTP with recovery codes
  • WebAuthn / passkeys
  • Enterprise SSO via OIDC (Okta, Azure AD, Auth0, Google Workspace)
  • App marketplace + GitHub-Apps-equivalent bot identities (ghi_ install tokens, scoped permissions)
  • Package registry (npm protocol — packument / tarball / publish / yank)
  • Pages / static hosting (serves from gh-pages branch)
  • Environments with protected approvals (reviewer-gated deploys, branch-glob restrictions)
  • Sponsors (tier management — payment rails deferred)
  • Personal dashboard, explore, global search, insights, releases
  • REST + GraphQL APIs (queries only on GraphQL)
  • Official CLI (cli/gluecron.ts) — single-file Bun binary
  • VS Code extension (vscode-extension/) — explain / open-on-web / semantic search / test generation
  • Mobile PWA (manifest + offline-capable service worker). Native iOS/Android apps are not built.
  • Command palette (Cmd+K), keyboard shortcuts, dark + light themes

Observability

  • Rate limiting, request-ID tracing, /healthz, /readyz, /metrics
  • Audit log (personal + per-repo)
  • Traffic analytics per repo (views + clones, 7/14/30/90d windows, SHA-truncated IP uniqueness)
  • Org-wide insights dashboard (green rate, PR/issue counts, per-repo breakdown)
  • Site admin panel — user management, system flags (registration_locked, site_banner_*, read_only_mode), billing overrides
  • Billing + quotas (free / pro / team / enterprise seeded plans)
  • Email notifications (provider-pluggable: log default, Resend in prod) + opt-in weekly digest

For the full shipped-vs-missing scorecard and internal roadmap, see `BUILD_BIBLE.md`.

Install

One click: Drag `gluecron.dxt` into Claude Desktop → Extensions. Claude prompts for your Gluecron host + a personal access token (generate one at /settings/tokens with admin scope) and the 15 MCP tools (gluecron_create_pr, gluecron_merge_pr, gluecron_repo_health, …) light up.

Browser: Sign up at https://gluecron.com/register or try without signing up at https://gluecron.com/play.

Day-to-day ops: Every routine operator action lives at `/admin/ops` (enable AI auto-merge, trigger a deploy, rollback). Deploy progress streams to `/admin/deploys`. No SSH required.

Power-user options (terminal)
curl -sSL https://gluecron.com/install | bash

The installer mints a PAT, edits claude_desktop_config.json, and drops the Claude Code skill bundle into ~/.claude/skills/. See `scripts/install.sh`.

You can also wire MCP manually — edit claude_desktop_config.json and add an mcpServers.gluecron entry pointing at https://gluecron.com/mcp with an Authorization: Bearer <pat> header.

Quick start (local development)

Visit http://localhost:3000 after starting the dev server to register and create your first repository.

Local dev commands (terminal)
bun install
bun dev            # hot-reload dev server
bun run db:migrate # run database migrations
bun test           # run the test suite

You'll need at minimum a DATABASE_URL pointing at Postgres. Everything AI-flavoured gracefully degrades without ANTHROPIC_API_KEY. See `.env.example` for the full list.

Stack

  • Runtime: Bun
  • Framework: Hono (with JSX for server-rendered views)
  • Database: Drizzle ORM + Neon (PostgreSQL)
  • Git: Smart HTTP protocol via git CLI subprocesses

Architecture (top-level)

src/
  index.ts          Bun server entry
  app.tsx           Hono composition + error handlers
  db/               Drizzle schema + lazy connection + migrations
  git/              repository.ts (tree/blob/commits/diff/blame/...) + protocol.ts
  hooks/            post-receive (GateTest, outbound deploy webhook, webhooks, CODEOWNERS)
  lib/              auth, config, markdown, highlight, AI helpers, autopilot, ...
  middleware/       softAuth / requireAuth / rate-limit / request-context
  routes/           git, api, web, issues, pulls, editor, settings, webhooks, ...
  views/            layout, components, landing, reactions

Full file inventory lives in `CLAUDE.md`.

Integrations

  • GateTest — optional third-party security scanner. When GATETEST_URL is set, every git push POSTs to it; inbound results accepted at POST /api/hooks/gatetest (bearer or HMAC).
  • Webhooks — user-registered URLs receive HMAC-signed payloads on push / issue / PR / star events.
  • Outbound deploy webhook — optional. Set CRONTECH_DEPLOY_URL (or any URL) to receive a POST on pushes to the default branch. Opt out per repo via autoDeployEnabled.

Deployment

Gluecron runs anywhere Bun runs. The repo ships a fly.toml for Fly.io and a Dockerfile for any container host, with Neon Postgres as the database. See `DEPLOY.md` for step-by-step instructions, environment variables, and the post-deploy verification checklist.

License

See `LICENSE`.