Concepts · Repositories & Git truth

Real Git, hosted in Cloudflare Artifacts.

Switchyard does not copy your repository into an application database. The repository itself lives in Cloudflare Artifacts; ordinary Git is what clones, fetches, commits and pushes it.

Git

The tool and protocol.

git clone, git fetch, git commit, merge and git push remain ordinary Git operations.

Cloudflare Artifacts

The remote Git server.

Repositories, objects, refs, branches, tags and canonical history live in Artifacts. It is Switchyard's authoritative Git truth.

Switchyard

The collaboration layer.

Switchyard adds Work, Attempts, reviews, durable workflows, policy, provenance and deterministic integration around that real Git repository.

Clone, work and push with Git

Open a repository in Switchyard and choose Code. The HTTPS URL shown there is the repository's Cloudflare Artifacts Git remote.

# Clone the Artifacts-hosted repository
git clone <https-clone-url-from-switchyard>
cd <repo>

# Work normally
git switch -c my-change
# edit files
git add .
git commit -m "Implement my change"

# Push the branch back to the same Artifacts remote
git push -u origin my-change

# Later, fetch everybody else's Git state normally
git fetch origin
Nothing proprietary in the Git loopThe commands above are normal Git. Artifacts is simply the remote server on the other end. Switchyard supplies scoped credentials and observes the resulting ref movement so its coordination state stays in sync.

Authentication

Switchyard obtains short-lived, repository-scoped Artifacts credentials for Git access. The clone URL shown in the Code menu contains no secret. Read credentials can clone/fetch; write credentials can push only where Switchyard policy allows them to.

Direct Git is first-class

A human or external CI system can push directly to an allowed branch with Git. That branch is still in Artifacts. Switchyard observes external ref movement through its event path and reconciliation safety net, then reflects it in the product UI and provenance model.

Attempts are real branches too

When Switchyard creates an Attempt, it creates isolated Git state against the same Artifacts repository. Agent work is not held in a special model-only store: its resulting commits and branch state are ordinary Git. Agents are prevented from writing canonical directly; the Integration Queue is the controlled path that eventually moves the canonical ref.

Compare-and-swap comes from Git

Update(repo, ref, expected_sha, change)
  read current ref from Artifacts
  build an ordinary Git commit
  git push --force=false

  if another writer moved the ref first:
      Git rejects the push as stale
      Switchyard reconciles or re-queues

Switchyard therefore does not pretend Trestle owns repository refs. Git and Artifacts remain authoritative for repository state.