Git configuration
What the worker needs for Git — identity, credentials, host tokens — and the guarantees it keeps about your repositories.
Git runs on the worker, as the worker's user, in the mapped checkout.
Worker setup
- Identity: the user's Git configuration, or Settings → Git author in the worker UI.
- Credentials: configure push credentials for the worker user as you normally would (credential manager, SSH key). Without them, commits stay local and the push step reports why.
- Host tokens: worker UI → Settings → Git hosting — a token per host (github.com, gitlab.com, GitHub Enterprise, self-managed GitLab with its API URL) for pull and merge requests. Stored in the credential store.
- GitHub App: for repositories from the organization's GitHub App, a worker without its own github.com token asks the control plane for a short-lived installation token limited to the task's repositories.
Guarantees
- Force-push,
reset --hard,clean, branch deletion and discarding changes are refused. - Pre-existing uncommitted work is never committed.
- Agents are told never to run destructive Git commands, and Aider's own auto-commits are turned off.
.agent-orchestration/is excluded through.git/info/exclude, never committed.