BLUEFLY FACTORY --- MASTER RUNNING TODO, BEADS & PROOF CHAIN¶
Purpose: This is the simple execution-facing companion to the Bluefly Factory Living Plan. It answers four questions: What are we proving now? What Beads already own the work? What is blocked? What becomes eligible next?
The detailed Mountains, Convoys, blockers, strategy, and existing Bead inventory from the prior tracker are preserved below. This top section is the controlling execution order.
Architecture: ContextControl is the commercial Drupal product and governed human surface. Gas City is the backend orchestration authority. Beads/Dolt is durable work authority. Source-controlled definitions travel through the governed forge/release path. Drupal may brand Gas City concepts, but must not create a second scheduler, work graph, event system, mail system, or agent runtime.
0. THE PLAN --- SIMPLE VERSION¶
GATE ZERO
Prove Oracle Gas City is healthy enough to trust.
Resolve real Agents, service identities, Beads/Dolt, Events, Mail, Sessions,
Claudex access, and self-hosted inference connectivity.
↓ ONLY WITH WITNESS PASS + RECEIPT
TEST 1 — AUTONOMOUS GAS CITY LIFECYCLE
One real request enters Gas City.
Gas City routes it.
A real Agent claims durable work.
The Agent executes.
Delivery happens through the governed source path when required.
Witness verifies it.
A complete Operational Receipt is produced.
Thomas transports nothing between agents.
↓ ONLY WITH WITNESS PASS + RECEIPT
TEST 2 — MINIMAL CONTEXTCONTROL READ PROOF
Drupal shows exactly:
1 Objective
1 Initiative
1 Work Item
1 Agent
1 live status
1 event timeline
1 Receipt
All from real Gas City / Beads authority. No duplicate Drupal work graph.
↓
TEST 3 — LIVE EVENT PROJECTION
ContextControl updates from native Gas City Events/SSE.
No LLM polling loop. No fake event bus.
↓
TEST 4 — ONE GOVERNED WRITE
A user performs one approved action in Drupal.
Policy authorizes or denies it.
Gas City performs the real mutation.
Event + Receipt prove the result.
↓
TEST 5 — GOVERNED AI EXPLANATION
Drupal AI explains authoritative state using scoped capabilities and evidence.
The AI does not become authority.
↓
TEST 6 — COMPLETE OPERATOR LOOP
A normal operator can understand, authorize, act, verify, and prove one
operation through ContextControl without using the CLI.
↓
TEST 7 — CLEAN CONSUMER
Reproduce the proven capability from released/version-pinned artifacts in a
clean supported environment with no Thomas-local state or undocumented fixups.
↓
TEST 8 — SECOND REAL OBJECTIVE
Run materially different real work through the same system and prove reuse,
lower re-derivation, and cost per verified completed Work Item.
↓
TEST 9 — CUSTOMER / OPERATOR PROOF
A real non-Gas-City expert can use the product language, understand state,
identify what needs attention, take one safe action, and understand the
evidence without Thomas or CLI knowledge.
↓
LATER NATIVE GAS CITY PRODUCT PROOFS
Mail → Automations/Orders → Procedures/Formulas → Sessions → Pools/Polecats →
Deacon/Dogs/health → connected-client Chat → Pack lifecycle → Commands/Doctor →
Patches → resource governance.
Hard Chain Law¶
TEST_N+1_ELIGIBLE = TEST_N_PROVEN
REQUIRED_TO_ADVANCE:
RESULT=PASS
EXPECTED_EVIDENCE=OBSERVED
FALSIFICATION_CONDITION=NOT_TRIGGERED
WITNESS_VERIFICATION=PASS
OPERATIONAL_RECEIPT=COMPLETE
RUNTIME_EVIDENCE=VALID
ADVANCEMENT_GATE=PASS
UNLOCKS_NEXT_TEST=YES
PROHIBITED:
PASS_BY_ASSERTION
PASS_BY_REPOSITORY_STATE
PASS_BY_SIMULATION
PASS_BY_STUB
SKIP_TEST
PARALLEL_FUTURE_TEST_EXECUTION
If a test is FAIL, PARTIAL, DEGRADED, or UNVERIFIED, the next
test stays blocked. Repair work attaches to the failed test, evidence is
preserved, and the same test is rerun.
1. WHAT WE DO NOW¶
NOW --- Gate Zero only¶
- [ ]
mba-9l1--- Oracle Gate Zero: finish the existing 15-step recovery and verification sequence. - [ ] Repair native Beads compatibility: eliminate the observed
schema/client skew instead of relying on
BD_IGNORE_SCHEMA_SKEW=1. - [ ] Restore trustworthy
gchealth: partial/unknown/unavailable state is degraded even if a command exits0. - [ ] Resolve Oracle saturation/root runtime defects: use the
existing P0 Beads, especially
bc-lm6m, rather than opening duplicate work. - [ ] Resolve the actual runtime Agent roster: for every doctrine
role record
ROLE,RESOLVED_AGENT,AGENT_SOURCE, andSERVICE_IDENTITY. - [ ] Prove non-human identity: no Thomas credential may be required for unattended execution.
- [ ] Prove Oracle is the sole Factory runtime authority: no workstation City and no NAS City.
- [ ] Prove Claudex can operate against Oracle while using approved self-hosted model endpoints. Oracle runs Gas City; the model host is an inference dependency, not a second City.
- [ ] Reconcile stale model-routing work:
bc-yjyrcurrently describes moving Claudex profiles to NAS. Re-scope or supersede only after Bead search/evidence; do not move Gas City authority to NAS. - [ ] Witness Gate Zero: one independent PASS receipt before Test 1 is eligible.
DO NOT START YET¶
- [ ] Test 1 implementation is BLOCKED by Gate Zero.
- [ ] Tests 2--9 are BLOCKED by the immediately prior proof.
- [ ] Later Mail/Orders/Formulas/Sessions/Pools/Deacon/Dog/connected-client/Pack proofs are recorded, not authorized.
- [ ] Graphics and architecture diagrams may document the intended architecture, but they do not count as runtime proof and must not drive premature implementation.
2. PROOF CHAIN --- TODO + BEAD OWNERSHIP¶
Do not invent duplicate Beads just to mirror this list. For each proof, search the canonical Dolt store first. Reuse or refine the existing Bead when one already owns the effect. Create a new canonical Bead only when the gap is proven.
Stage Status Existing Beads / authority to Primary role Required evidence to unlock next reconcile
Gate Zero ACTIVE mba-9l1, bc-lm6m, MAYOR + DEACON + Oracle/City/Beads/Agents/identity/events
bc-g2nl, PHANTOM:hq-zfuf, SENTINEL trustworthy; Witness PASS receipt
PHANTOM:hq-zhg4, identity/security
P0s
Test 1 --- BLOCKED Search first; reuse existing BLU routes; MAYOR One real end-to-end lifecycle; Thomas
Autonomous factory-loop / first-operation dispatches; transport = 0; receipt complete
lifecycle work where scope matches POLECAT executes;
HARBORMASTER
delivers
Test 2 --- Minimal BLOCKED bc-jbsa, mba-dtn, DRUPAL 1 Objective + 1 Initiative + 1 Work Item +
ContextControl read PHANTOM:bl-08nift and existing 1 Agent + status + events + receipt from
API-normalization work as real authority
applicable
Test 3 --- Live BLOCKED telemetry-event-stream only DRUPAL + DEACON Native event-driven update;
Events where it does not replace replay/reconnect proven; polling daemon =
native Gas City Events/SSE 0
Test 4 --- Governed BLOCKED Convoy B identity/policy work + DRUPAL + BLU + One authorized/denied real action; Gas write ContextControl operation work SENTINEL City mutation; event + receipt
Test 5 --- AI BLOCKED bc-nfnp, bc-13pv, DRUPAL Evidence-linked explanation over
explanation ContextCard / Drupal AI authoritative state; AI is not authority
capability work
Test 6 --- Operator BLOCKED mba-z5y and proven pieces DRUPAL + BLU Operator completes DETECT → UNDERSTAND →
loop from Tests 2--5 AUTHORIZE → ACT → VERIFY → PROVE without
CLI
Test 7 --- Clean BLOCKED package-clean-consumer-test FORGE Fresh supported environment reproduces
consumer plus released/versioned capability with no local magic
dependencies
Test 8 --- Second BLOCKED Reuse the proven path; no BLU Second real objective; reuse measured; objective bespoke architecture Bead cost/re-derivation measured
Test 9 --- BLOCKED Product usability proof; search PRODUCT/DRUPAL + Non-expert user succeeds without Gas City Customer/operator before creating canonical Bead BLU jargon, CLI, or Thomas
Later native LOCKED Create/reconcile only when Narrow owner per Native Gas City capability proven without proofs prior accepted proof unlocks capability rebuilding it them
3. PRODUCT LANGUAGE --- UI BRANDING WITHOUT CHANGING AUTHORITY¶
ContextControl product term Native authority
Objective Mountain Initiative Convoy Work Item Bead Workspace Rig Procedure Formula Automation Order Signal Event Capability Pack Pack Agent Agent Mail Gas City Mail Run Session / disposable execution Receipt Operational Receipt / evidence
The UI may use the product term. Receipts, API contracts, debugging surfaces, and evidence preserve the native identifier underneath.
4. CONTEXTCONTROL END STATE --- PRODUCT TODO, NOT CURRENT AUTHORIZATION¶
The commercial end state is ordinary product CRUD in Drupal while preserving native authority.
- [ ] Objectives: list/view/manage the product representation of strategic work without inventing a second durable work authority.
- [ ] Initiatives: list/view/create/manage Convoys through the native contract.
- [ ] Work Items: list/view/create/update Beads through Beads/Gas City authority.
- [ ] Agents: list configured Agents separately from live Sessions.
- [ ] Procedures: manage Formula definitions through their native versioned representation.
- [ ] Automations: manage Order triggers/actions through native Gas City semantics.
- [ ] Signals: consume native Events/SSE with replay cursors.
- [ ] Mail: Inbox/Sent/thread UX over Gas City Mail, including human and Agent destinations under policy.
- [ ] Runs: observe Sessions, provider/runtime health, logs/peek/nudge where authorized.
- [ ] Capability Packs: expose native Pack composition without creating Bluefly-only pack primitives.
- [ ] Receipts: show evidence, policy decision, source revisions, runtime outcome, model/provider economics, Witness result, and next action.
- [ ] Chat: use Gas City connected-client/extmsg semantics when proven so Drupal participates in a real Gas City session rather than becoming a parallel chat authority.
- [ ] Source-controlled edits: when Procedures, Automations, Packs, or Agent definitions are source authority, Drupal produces the governed native representation and uses the governed forge/release path. Do not make the Drupal database the hidden source of truth.
5. PRODUCTION / SCIENCE RULES FOR EVERY BEAD¶
Every proof Bead must declare before execution:
HYPOTHESIS=
FALSIFICATION_CONDITION=
CURRENT_AUTHORITY=
BASELINE=
ROLE=
RESOLVED_AGENT=
AGENT_SOURCE=
SERVICE_IDENTITY=
UPSTREAM_OWNER=
CAPABILITY_MATCH=
MINIMUM_CHANGE=
TEST_INPUT=
EXPECTED_OBSERVATION=
ACCEPTANCE=
VERIFICATION=
DELIVERY_PATH=
EVIDENCE_PATH=
And finish with:
ACTUAL_OBSERVATION=
RESULT=PASS|FAIL|PARTIAL
WITNESS_VERIFICATION=
OPERATIONAL_RECEIPT=
UNLOCKS_NEXT_TEST=YES|NO
DEFECT_OR_NEXT_BEAD=
CUSTOM_LOC_ADDED=
CUSTOM_LOC_REMOVED=
DUPLICATE_CAPABILITIES_REMOVED=
OBSOLETE_FILES_REMOVED=
NEW_LONG_TERM_OWNER_SURFACES=
NET_OWNERSHIP_DELTA=
WHAT_WILL_THE_NEXT_AGENT_REUSE=
WHAT_WOULD_STILL_HAVE_TO_BE_RE_DERIVED=
Zero prototype debt¶
FAKE_DATA=NO
MOCK_GAS_CITY=NO
STUB_API=NO
SIMULATED_SUCCESS=NO
SECOND_WORK_GRAPH=NO
CUSTOM_SCHEDULER=NO
CUSTOM_AGENT_LOOP=NO
LLM_POLLING=NO
THOMAS_CREDENTIALS=NO
UNVERSIONED_PACK=NO
GENERIC_OPENAPI_TO_AI_TOOL_EXPLOSION=NO
A temporary compatibility workaround is allowed only for a proven upstream defect and must have an owner, test, removal condition, and tracked defect.
6. UPSTREAM-FIRST BUILD ORDER¶
Before source mutation, prove whether the capability already belongs to Gas City, Drupal core/contrib, Drupal AI, Tool API/MCP, ECA/FlowDrop, Canvas/SDC, AgenticTools, BluCity-Packs, Cedar/ContractPlane, the forge, or another accepted upstream component.
UPSTREAM_EXISTS
→ CONFIGURE / COMPOSE / PROJECT
EXISTING_BLUEFLY_CAPABILITY
→ WIRE / REPAIR / VERIFY
REAL_GAP
→ THIN ADAPTER ONLY
CUSTOM_CODE
→ LAST RESORT
For Drupal specifically:
Core
→ Contrib
→ Contrib configuration
→ Recipe / config action
→ Canvas / SDC
→ ECA / FlowDrop
→ Drupal AI
→ Tool API / MCP
→ Existing Bluefly extension
→ Custom code
api_normalization is a contract-normalization capability, not
permission to turn every imported OpenAPI endpoint into an unrestricted
AI tool.
7. LATER GAS CITY CAPABILITY HORIZON --- REMEMBER, DO NOT BUILD EARLY¶
These are explicitly retained so we do not discover them late and rebuild them badly:
- [ ] Mail console proof --- native Gas City Mail projected into ContextControl.
- [ ] Automation proof --- Orders with cooldown/cron/condition/event/manual triggers.
- [ ] Procedure graph proof --- Formula execution and evidence.
- [ ] Session operator proof --- tmux/provider-backed Sessions; attach/peek/logs/nudge without treating tmux as durable authority.
- [ ] Elastic worker proof --- native pools /
scale_check/ Polecat-style bounded workers. - [ ] Health patrol proof --- native deterministic health/recovery; Deacon judgment only where judgment is actually needed.
- [ ] Dog proof --- pack utility-agent patterns only where deterministic Orders/exec do not already own the job.
- [ ] Connected-client Chat proof --- ContextControl Chat as a native external Gas City participant.
- [ ] Pack lifecycle proof --- Agents, Formulas, Orders, Events, commands, patches, assets, overlays as the native Pack contract supports.
- [ ] Commands/Doctor proof --- project native deterministic command and doctor results rather than rebuilding checks.
- [ ] Patch-without-fork proof --- Agent/provider/Rig patching rather than copied Pack forks.
- [ ] Resource-governance proof --- provider/model/session capacity and economics exposed without inventing another scheduler.
8. VISUAL / DATA / ARCHITECTURE TODO¶
These can be produced in parallel as documentation, but they do not unlock implementation stages.
- [ ] Product architecture map: ContextControl → Gas City → Beads/Dolt → forge → evidence.
- [ ] Chain-of-proof diagram: Gate Zero through Test 9 with hard advancement gates.
- [ ] Primitive map: Agent / Bead / Formula / Rig / Pack / Event, plus Sessions, Mail, Orders, Pools, Commands and connected clients as mechanisms rather than extra primitives.
- [ ] Authority map: what Drupal owns vs Gas City vs Beads/Dolt vs source control vs policy/evidence.
- [ ] Mail + Chat sequence: human/Drupal → extmsg/Mail → Gas City → Agent Session → Work Item → reply/event/receipt.
- [ ] CRUD contract map: product term ↔ native object ↔ read API ↔ write API ↔ source/runtime authority ↔ evidence.
- [ ] Event lifecycle diagram: request → request_id/cursor → native Events/SSE → terminal event → Drupal projection.
- [ ] Agent/session/runtime map: configured Agent vs disposable Session vs provider vs tmux vs pool.
- [ ] Factory economics dashboard spec: cost per verified completed Work Item, human interventions, retries, custom LOC delta, reuse, latency, paid vs self-hosted model use.
- [ ] Customer journey map: operator sees attention → understands why → authorizes → watches progress → receives proof.
9. CURATION NOTES / KNOWN TRACKER RECONCILIATION¶
- The prior tracker says "15 Canonical Cross-Mountain Convoys" but contains Convoys A through P. Preserve all Convoys for now; reconcile the count and canonical status through the governing docs rather than deleting one here.
- Existing Bead IDs below are retained as historical/current execution references. Before acting on any one, verify it still exists, is not closed/superseded, and still owns the described effect in canonical Dolt.
- Existing tracker language that implies NAS-hosted inference or model routing must be reconciled with the current architecture before execution. Oracle remains Factory runtime authority. NAS remains durability/artifact infrastructure unless an accepted architecture decision explicitly changes that.
- The detailed tracker below remains useful for Mountains, Convoys, P0s, package/release work, migration strategy, documentation integrity, and the GitLab/Forgejo transition. The proof chain above controls what may execute next.
PRESERVED DETAILED TRACKER¶
The content below is the prior RunningTodo retained intact so we do
not lose Beads, Convoys, Mountains, blockers, or strategic work while
moving to the proof-chain execution model.
BLUEFLY FACTORY --- MASTER RUNNING TODO & CROSS-MOUNTAIN CONVOY TRACKER¶
Purpose: This document is the living execution tracker for the Bluefly Factory. It bridges the 40 Strategic Mountains into 15 Canonical Cross-Mountain Convoys, binding high-level durable missions to actionable, dependency-aware Beads in the canonical Dolt store (
:3308/hq).Policy & Architecture Authorities (Do Not Restate Here): - Authority Precedence & Light Factory:
Engineering-Standard/standards/core/STD-AUTH-001-authority-precedence-and-light-factory-model.md- Pre-Execution Gate:Engineering-Standard/operating-model/STD-GATE-001-factory-execution-gate.md- Economic Completion Gate:Engineering-Standard/standards/core/STD-ECON-001-factory-economic-gate.md- Team Dispatch & Role Governance:Engineering-Standard/operating-model/agent-blu-factory-directive.md- ContextControl Architecture:Engineering-Standard/architecture/contextcontrol-factory-control-plane.md- Factory Mountains Strategy (1--40):Engineering-Standard/architecture/STD-FACT-002-factory-mountains-roadmap.md- Cross-Mountain Convoys & Reconciliation:Engineering-Standard/architecture/STD-FACT-003-cross-mountain-convoys-and-reconciliation.md- Gas City Platform Authority:https://docs.gascity.com/(Agent reference:https://docs.gascity.com/llms-full.txt)
1. Operating Invariant & Team Dispatch¶
BLU_ROUTES=YES
BLU_EXECUTES=NO
MAYOR_DISPATCHES=YES
POLECAT_EXECUTES=YES
HARBORMASTER_DELIVERS=YES
REFINERY_CONVERGES=YES
DRUPAL_OWNS_DRUPAL=YES
SENTINEL_OWNS_SECURITY=YES
FORGE_PROVES_REUSE=YES
WITNESS_VERIFIES_INDEPENDENTLY=YES
FOUNDRY_BUILDS_ONLY_PROVEN_GAPS=YES
DEACON_PATROLS_DETERMINISTICALLY=YES
Team Taxonomy: Upstream vs. Bluefly-Owned¶
Category Roles Source
Upstream Gas City MAYOR, DEACON, Gas City organization
(import/configure, do WITNESS, REFINERY, pack
NOT rebuild) POLECAT
Bluefly-Owned BLU, HARBORMASTER, BluCity-Packs / OSSA
(author and maintain) DRUPAL, SENTINEL, manifests
FOUNDRY, FORGE
Implementation Strategy¶
Wire, substitute, and prove --- not build.
The Factory's main problem is not missing capability but that existing capability is unwired, unlocked, and unverified. Contrib/upstream capability must not be rebuilt unnecessarily.
Reuse Model¶
AUTHOR ONCE
→ Pack / CI Component
→ Version + Pin
→ Project through references
→ Project to each harness using upstream mechanisms
→ Verify
NOT:
copy Skill / copy Formula / copy policy / copy agent / copy CI
into every repository
Skills are projections of capabilities, not the capability itself.
Harness-specific needs are patches, not forks. packs.lock makes
composition reproducible.
Execution Wave Ordering¶
WAVE 0 — Repair the Factory runtime itself.
WAVE 1 — Execution Gate + agent/identity convergence.
WAVE 2 — Wire Mountains/Convoys to what already exists.
WAVE 3 — RUN THE PRODUCT: Drupal Security & Release on bluefly.io.
WAVE 4 — Run 2 on the same estate and measure reuse.
WAVE 5 — Second estate.
Only then: PROVEN REUSABLE CAPABILITY.
Waves 0--2 are plumbing and must not expand. Wave 3 is the product.
Upstream Substitution Ledger¶
Capability Upstream Owner Bluefly Owns
Security/update Composer audit, Drupal Integration, policy, detection release/security feeds estate fan-out
Update application Renovate Decision, verification, receipt
Custom-code analysis PHPStan, Drupal Check, Classification, Rector/Upgrade Status disposition, retirement
Migration Drupal Migrate, Recipes, estate migrate_plus, playbook, verification migrate_tools
Sovereignty Group + entity access + Tenant policy, Cedar isolation proof
Context ai_context ContextCard structure,
composition retrieval
Durability restic/borg/rclone Schedule, verification, SLA
Merge trains GitLab native Selective enablement, CI components
Observability OpenTelemetry, Wiring, dashboards, OtterMon, Gas City economic metrics events
2. Gas City Execution Hierarchy & Deduplication Law¶
The 40 Mountains are durable strategic missions, not 40 parallel task backlogs. They converge into 15 shared delivery Convoys feeding bounded Beads through native Gas City and Beads primitives:
MOUNTAIN (Durable Mission)
↓
SHARED CONVOY (Coordinated Multi-Bead Batch)
↓
BEAD GRAPH (Dolt-backed Work DAG: blocks, tracks, discovered-from)
↓
FORMULA / MOLECULE / GATE (Repeatable Method / Asynchronous Gate)
↓
AGENT (Configured Worker Role: OSSA v0.4.1)
↓
SESSION (Disposable Execution Process)
↓
EXECUTION (Smallest Verifiable Source Mutation)
↓
VERIFICATION (Independent Witness Proof & Economic Gate)
Deduplication Law¶
- Search existing Beads (
bd list,bd ready) before creating new work. - If a capability touches multiple Mountains (e.g. Identity in M1, M4, M6, M7, M21, M30) $\to$ ONE Bead under SHARED CONVOY B, not separate copies per Mountain.
- Use native dependency edges:
blocks(ordering/readiness),tracks(convoy grouping),parent-child(containment),discovered-from(emergent findings).
Native Gas City & Beads Mechanics (Tutorial 06 Best Practices)¶
- Dependency-Aware Work Pull: Use
bd ready --metadata-field gc.routed_to=<agent> --unassigned --limit=1--- work blocked by open dependencies is automatically invisible until the blocker closes. - Stranded Work Detection: Run
gc convoy strandedto find open beads in active convoys with no assigned worker. - Automated Lifecycle & Reconciliation: Convoys auto-close via
on_closehooks when all tracked beads close. Rungc convoy checkto reconcile missed hooks; usegc convoy land <id>for--ownedconvoys. - Target Branch Inheritance: Set
--target release/v0.1.xon convoys so member beads automatically inherit the governed release target branch. - Structured Metadata over Title Hacks: Set state via
--set-metadata branch=...,--set-metadata reviewer=...,--set-metadata gc.routed_to=...rather than polluting bead titles.
3. Critical Path & Blocker Registry (Dolt :3308/hq)¶
P0 Active Blockers (Must Clear First)¶
Blocker Bead Priority Domain Blocker Impact & Scope Owning Agent Blocked Dependents
bc-ggku / P0 DrupalWorks Consolidation push rejected due to sentinel / Blocks
bc-6fxp Authority service-account push credentials harbormaster DrupalWorks
pack
distribution &
bc-a7fd
bc-4w9a / P0 Security Live Google API keys & blu_fleet sentinel Blocks all
bc-0pqi Exposure tokens in bluefly.io / public package
contextcontrol-ai release publishing &
history MR merges
du-tjp P0 Security Static API key in tmux argv + 31 sentinel Blocks
Exposure sessions with unattended
--dangerously-skip-permissions multi-agent
autonomy
bc-g2nl P0 Oracle Traefik dead on Oracle deacon / Blocks remote
Gateway (claw.copaw.us & tunneled mayor webhook
services unreachable) ingress &
mobile
monitoring
bc-lm6m P0 Oracle gastown-gateway crash-loops 48k deacon Blocks City
Saturation times (MODULE_NOT_FOUND), supervisory
starving gc controller loop
bc-w56f / P0 Event / GitLab group webhook 500 loop foundry / Blocks
bc-uld Webhooks caused by broken bd city import forge event-driven
pipeline
triggers
across 20
repos
bc-8mla P0 CI Quality gitlab_components refinery Blocks
Gate pre-merge-validation.yml never verified merge
included; 5 guard jobs inert train
activation
bc-escm P0 GitLab Exit GitLab subscription A-S00141074 harbormaster Blocks source
⚠️ --- Dec 15 expires 2026-12-15 (84 days). sovereignty,
Hard Cutoff Convoy P starts 2026-10-01. ON webhook
HOLD until Oct 1 --- see CONVOY reliability,
P. and factory
autonomy
Blocked Beads (Awaiting Upstream Resolution)¶
Blocked Bead Priority Reason Blocked Required Action Before Work
bc-fyyl P0 source_connector Fixed in branch;
InputDefinition blocked on
arity fatal republish
(bc-ez0l), do
NOT re-code
bc-inx7 P0 source_connector Fixed in branch;
ComplianceToolBase blocked on
logger fatal republish
(bc-ez0l), do
NOT re-code
bc-6ilk P1 agentic_canvas Fixed upstream;
Twig & node_classes cannot reach
defects bluefly.io
until registry
ships > 0.1.7
bc-uy73 P1 HarborMaster named Needs city-scoped
session alignment agent aligned
with always-on
Gas City session
bc-f6y P1 Durable Agent Blocked on
Identity Phase 0 machine identity
service account
provisioning
bc-3c4 P1 Post-deployment Blocked on
agent governance governed
deployment
verification
4. The 15 Canonical Cross-Mountain Convoys¶
CONVOY A --- City Foundation¶
- Supports: Mountains 1, 2, 3, 6, 16, 17, 37, 38, 40
- Goal: One Gas City running reliably on Oracle as the sole
Factory orchestration runtime (
ONE_CITY=YES,SECOND_CITY=NO). - Assigned:
MAYOR(Dispatch),DEACON(Patrol),WITNESS(Verification) - Active Dolt Beads:
- [ ]
bc-g2nl(P0): Recover Traefik gateway and tunnel endpoints on Oracle [DEACON] - [ ]
bc-lm6m(P0): Remediategastown-gatewaycrash loop and CPU starvation [DEACON] - [ ]
bc-uld(P0): Fix brokenbd importon missing remote to restore city start [FOUNDRY] - [ ]
PHANTOM:hq-zfuf(P0): Recover dispatcher supervisor process (mol-dog-reaper) [MAYOR] - [ ]
PHANTOM:hq-zhg4(P0): Relocate shadow ledger beads into canonical:3308/hq[MAYOR] - [ ]
PHANTOM:bl-38cejv(P0): Wire automated estate hygiene (blu audit estate) into Witness patrol [WITNESS] - [ ]
PHANTOM:bl-ws9obz(P0): Pin Oracle detached HEAD checkouts with bind-mount protection [DEACON] - [ ]
bc-d3k(P1): Classify and retire accidental per-rig databases created during recovery [DEACON] - [ ]
city-backup-restore-proof: Execute cold-start Dolt database restoration proof from NAS snapshot [WITNESS]
- [ ]
- Acceptance:
ONE_CITY=PASS,DOLT_HEALTH=PASS,SESSIONS_DISPOSABLE=PASS,EVENTS_EMITTING=PASS.
CONVOY B --- Identity, Authority, and Policy¶
- Supports: Mountains 1, 4, 6, 7, 21, 22, 30, 32, 33
- Goal: Every action has an explicit machine identity, bounded authority, Cedar policy decision, and customer scope.
- Assigned:
SENTINEL(Security/Cedar),FOUNDRY(OSSA/DUADP),BLU(Contract Plane) - Active Dolt Beads:
- [ ]
bc-4w9a(P0): Coordinated BFG/git-filter-repo purge of live Google API key frombluefly.iohistory [SENTINEL] - [ ]
bc-0pqi(P0): Rotate and purgeblu_fleet.settingsapi_token fromcontextcontrol-ai[SENTINEL] - [ ]
bc-ype1(P0): Revoke and rotate GitLab PAT confirmed exposed in session transcript [SENTINEL] - [ ]
du-tjp(P0): Purge static API keys from tmux arguments and enforce Cedar authorization on agent invocations [SENTINEL] - [ ]
bc-ypy2(P0): Complete canonical@bluand 8 specialist agent OSSA v0.4.1 manifests inagentictools/agents[FOUNDRY] - [ ]
bc-fyna(P1): Implement 1Password Credential Broker architecture converging with Drupal authority model [SENTINEL] - [ ]
bc-t3b(P1): Splitcedar_policyscope creep --- remove custom SAML/LDAP/MFA, adopt standard contrib [DRUPAL] - [ ]
identity-machine-git-config: Standardize machine identity commit author across all agent sessions [HARBORMASTER]
- [ ]
- Acceptance:
PERSONAL_CREDENTIALS_IN_AGENT_PATHS=0,SERVICE_IDENTITIES=PASS,CEDAR_DENIAL_PROVEN=PASS.
CONVOY C --- Source, CI, Merge, and Release Fabric¶
- Supports: Mountains 4, 18, 19, 20, 21, 25, 39, 40
- Goal: Source travels through one predictable automated path from branch to verified release artifact.
- Assigned:
HARBORMASTER(Delivery/MRs),REFINERY(CI Components),WITNESS(Proof) - Active Dolt Beads:
- [ ]
bc-8mla(P0): Fixgitlab_componentspre-merge-validation.ymlinclusion to activate 5 inert guard jobs [REFINERY] - [x]
bc-ccdv(P1): Correct 5 undeclared-input sites ingitlab_components(MERGED MR !1218) [REFINERY] - [ ]
PHANTOM:bl-sd98nf(P1): Remove manual approval rules onfeature -> release/v0.1.xacross 18 delivery repos [MAYOR] - [ ]
PHANTOM:bl-iybdig(P1): Remediate review comments and clean up 9 closed MRs (!504, !191, etc.) [REFINERY] - [ ]
PHANTOM:hq-pm1a(P0): Repair merge request pipeline configuration forstudio-ui[HARBORMASTER] - [ ]
ci-merge-trains-selective: Enable GitLab merge trains on high-concurrency repos (BluCity,DrupalWorks,bluefly.io,contextcontrol-ai) [HARBORMASTER] - [ ]
ci-shared-components-adopt: Convert leaf.gitlab-ci.ymlfiles to consume versioned GitLab components [REFINERY]
- [ ]
- Acceptance:
MERGED_RESULTS=PASS,MERGE_TRAINS_SELECTIVE=PASS,CI_FALSE_GREENS=0.
CONVOY D --- Package and Registry Publication¶
- Supports: Mountains 5, 18, 19, 25, 39
- Goal: Every reusable artifact has one canonical package identity and intentional registry distribution strategy.
- Assigned:
FOUNDRY(Packaging),REFINERY(Publishing),FORGE(Clean Consumer Proof) - Active Dolt Beads:
- [ ]
bc-ftdk(P1): Converge Drupal estate release: 42/47 projects never reach main, 20 have no stable package [DRUPAL+REFINERY] - [ ]
bc-yrw4(P1): Fix workflow block in 6 Drupal package repos omittingCI_COMMIT_TAG[REFINERY] - [ ]
bc-ubjf(P1): Fixagentic_canvasrelease pipeline omittingCI_COMMIT_TAG[REFINERY] - [ ]
package-duadp-npm: Publish verified DUADP JS client to npmjs registry [REFINERY] - [ ]
package-ossa-npm: Publish vetted@bluefly/ossato npmjs registry [REFINERY] - [ ]
package-clean-consumer-test: Verify clean consumer installation in empty project without local path magic [FORGE]
- [ ]
- Acceptance:
NPM_PUBLISHED=PASS,COMPOSER_REGISTRY=PASS,CLEAN_CONSUMER_PROOF=PASS.
CONVOY E --- Pack Architecture¶
- Supports: Mountains 3, 5, 6, 8, 26, 27, 28, 29, 38
- Goal: Reusable Factory capability lives in versioned Packs and Formulas rather than giant session prompts.
- Assigned:
FOUNDRY(Pack Builder),BLU(Architecture/Portability) - Active Dolt Beads:
- [ ]
bc-9vir(P0): DrupalWorks Architecture Directive --- Formula v2 engine, evidence-governed lifecycle [FOUNDRY] - [ ]
bc-oay5(P2): Evidence and learning pack --- author remaining 6 formulas, 4 orders, 5 events [FOUNDRY] - [ ]
mba-0y4(P1): Gas City audit --- DrupalWorks cartesian explosion (66 phantom agents on non-Drupal rigs), 46 config-ref issues, 66 formula-requirement warnings, gc sling not adopted, scripts→commands layout [WITNESS→FOUNDRY] - [ ]
pack-public-private-boundary: Lock strict boundary: publicDrupalWorksvs. privateBluCity-Packs[BLU] - [ ]
pack-schema-validation: Validate pack manifests against Gas City v2 schema [FOUNDRY] - [ ]
formula-single-purpose-gate: Enforce single-purpose I/O contracts on all newly materialized formulas [FOUNDRY]
- [ ]
- Acceptance:
PUBLIC_PRIVATE_BOUNDARY=PASS,FORMULA_V2_COMPLIANT=PASS,ZERO_INTERNAL_SECRETS_IN_PACKS=PASS,ZERO_PHANTOM_AGENTS=PASS.
CONVOY F --- Drupal Quality and Upstream Convergence¶
- Supports: Mountains 5, 7, 8, 24, 25, 26, 27, 28, 29
- Goal: Upstream-first Drupal engineering
(
core → contrib → config → recipe → Canvas → custom code last). - Assigned:
DRUPAL(DrupalWorks),FORGE(Packaging Proof),WITNESS(QA Verification) - Active Dolt Beads:
- [ ]
bc-hadp(P0): Fix undefined logger channel inai_search_block_log_tagbreaking container compilation [DRUPAL] - [ ]
bc-4zb2(P0):bluefly.ioconfig recovery --- reconcile entity-display, Canvas, MCP, and Views drift [DRUPAL] - [ ]
bc-g4rm(P0):contextcontrol-aiconfig recovery --- reconcile 139-module gap between DB and config/sync [DRUPAL] - [ ]
bc-6fj7(P0): Upgradewebonyx/graphql-phpto 15.32.2+ to resolve 3 critical security advisories [DRUPAL] - [x]
bc-w0ue(P1): Fixdragonfly_clientPostDragonflyRunToGkglogger type fatal (MERGED MR !23) [DRUPAL] - [ ]
PHANTOM:bl-s06j5b(P1): Implement 5 reusable verification checks from STD-VERIFY-001 in DrupalWorks [DRUPAL] - [ ]
PHANTOM:bl-08nift(P1): Refactorapi_normalizationcustom module to core JSON:API [DRUPAL] - [ ]
PHANTOM:bl-oqev8j(P1): Splitbluefly_themeinto core Recipes + Canvas SDC starterkit [DRUPAL] - [ ]
kb-cache-governance: Standardizekb_cacheworktree lifecycle; resolveai_contextboundary [DRUPAL]
- [ ]
- Acceptance:
PHPCS_CLEAN=PASS,PHPSTAN_L8=PASS,NET_CUSTOM_LOC_REDUCED=PASS.
BEFORE CREATING A NEW G* BEAD: 1. search existing Beads 2. reuse or rename existing work 3. reconcile stale closed Beads against evidence 4. update RunningTodo from Bead state 5. never create a duplicate because a session lost context
CONVOY G — Governed Human Control Plane (ContextControl)¶
STATUS: ACTIVE / RECONCILE AGAINST CURRENT BEADS
ContextControl is the governed human/customer control surface.
Gas City = orchestration Beads = durable work ContractPlane / Cedar = authorization OtterMon = checks / evidence / reverification GitLab = source / MR / CI / release ContextControl = review / approval / governed context / operator UX
ContextControl MUST NOT become a scheduler or second work authority.
G1 — contextcontrol-tenancy-model¶
OWNER=DRUPAL
- Prove current Group tenancy model.
- Prefer Group contrib configuration.
- Verify Organization → Team → Project → Estate only where product semantics require each level.
- Remove custom tenancy code where upstream/config already owns behavior.
ACCEPTANCE: GROUP_MODEL_PROVEN=YES CROSS_TENANT_ACCESS_DENIED=YES CUSTOM_TENANCY_FRAMEWORK=NO
G2 — contextcontrol-registration-provisioning¶
EXISTING_BEAD=mba-d61o OWNER=DRUPAL STATUS=RECONCILE
- Re-evaluate current implementation.
- Prefer Group + ECA + Recipe/Config Action.
- Remove procedural custom hook glue if upstream/config/ECA can replace it.
- Custom plugin allowed only after proven upstream gap.
ACCEPTANCE: ECA_FIRST=YES CUSTOM_HOOK_GLUE=0 CLEAN_IMPORT=PASS REGISTRATION_PROVISIONING=PASS RUNTIME_VERIFIED=YES
G3 — contextcontrol-tenant-access-isolation¶
OWNER=DRUPAL AUDIT=SENTINEL VERIFY=WITNESS
- Prove entity access isolation.
- Prove ai_context isolation.
- Prove Search API/vector isolation.
- Prove JSON:API and Tool/MCP access isolation.
ACCEPTANCE: CROSS_TENANT_ENTITY_READ=DENIED CROSS_TENANT_ENTITY_WRITE=DENIED CROSS_TENANT_CONTEXT_RETRIEVAL=DENIED CROSS_TENANT_VECTOR_RETRIEVAL=DENIED
G4 — contextcontrol-ai-asset-group-binding¶
OWNER=DRUPAL
- Determine native Group relation support for:
- ai_context_item
- OSSA agents
- API normalization entities
- governed capability entities
- Use upstream relation plugins/config first.
- If upstream gap is real, route the smallest reusable producer fix.
ACCEPTANCE: UPSTREAM_GAP_PROVEN= CUSTOM_RELATION_PLUGIN_REQUIRED= TENANT_BINDING_PROVEN=YES
G5 — contextcontrol-zero-scheduler¶
OWNER=WITNESS
Verify that ContextControl only: - displays - reviews - approves - authorizes - requests execution - displays receipts
It must not: - own Beads - schedule agents - maintain work queues - implement retries - become another orchestrator
ACCEPTANCE: PARALLEL_SCHEDULER=NO PARALLEL_WORK_DB=NO GAS_CITY_EXECUTION_BOUNDARY=PROVEN
G6 — contextcontrol-api-catalog¶
OWNER=DRUPAL
Use api_normalization as the Drupal-native API catalog.
Flow:
OpenAPI → api_normalization → Drupal entities → Views / Canvas → Tool API → MCP → ECA
Import only approved estate APIs with explicit owners.
ACCEPTANCE: NORMALIZED_ENTITIES_CREATED=YES SOURCE_IDENTIFIER_PRESERVED=YES SECRETS_IN_ENTITIES=NO HARDCODED_ENV_ENDPOINTS=0
G7 — contextcontrol-api-tool-exposure¶
OWNER=DRUPAL / FOUNDRY
- Expose approved normalized API operations through Tool API.
- Use MCP for external tool transport.
- Do not build custom REST/MCP bridges unless upstream gap is proven.
ACCEPTANCE: CUSTOM_REST_BRIDGE=0 CUSTOM_MCP_PROTOCOL=0 TOOL_SCHEMA_DEFINED=YES AUTH_REFERENCE_ONLY=YES
G8 — contextcontrol-eca-api-automation¶
OWNER=DRUPAL
Use ECA for: - normalized API lifecycle - event-driven state updates - approval triggers - integrity findings - human review routing
No polling framework. No custom workflow engine.
ACCEPTANCE: ECA_FIRST=YES CUSTOM_POLLING=0 CUSTOM_WORKFLOW_ENGINE=0
G9 — contextcontrol-knowledge-authority-assurance¶
OWNER=DRUPAL POLICY=CONTRACTPLANE AUDIT=SENTINEL VERIFY=WITNESS
- Surface deterministic
docs.integrity_findingevents. - ContextControl presents findings and approvals.
- ContractPlane evaluates policy.
- Gas City routes remediation.
- ContextControl does not become evidence or execution authority.
G10 — contextcontrol-human-approval-surface¶
OWNER=DRUPAL
Model approvals for: - tools - policy exceptions - knowledge conflicts - API capability approval - sensitive operations - release/deploy requests
Prefer Drupal entities + moderation/workflow + ECA + Views/Canvas.
G11 — contextcontrol-receipt-and-evidence-ui¶
OWNER=DRUPAL VERIFY=WITNESS
Render authoritative lifecycle state:
REQUESTED AUTHORIZED DISPATCHED RUNNING SOURCE_DELIVERED CI_VERIFIED DEPLOYED RUNTIME_ACCEPTED INDEPENDENTLY_VERIFIED FAILED BLOCKED
ContextControl displays evidence. It does not independently declare execution success.
CONVOY H --- Verified Security & Release Operation¶
- Supports: Mountains 8, 25, 26, 34, 35, 36, 40
- Goal: Complete the first commercially meaningful Factory
operation end-to-end (
ESTATE=bluefly.io,OPERATION=Security Update). - Assigned:
DRUPAL(Implementation),SENTINEL(Security Gate),WITNESS(Independent Signing) - Active Dolt Beads:
- [ ]
PHANTOM:bl-m2a9un(P0): Cryptographic revocation proof for compromised credentials [SENTINEL] - [ ]
security-detector-coverage: Standardize upstream security advisory detection via GitLab native component [SENTINEL] - [ ]
security-first-operation-run1: Execute Run 1 end-to-end (DETECT → UNDERSTAND → AUTHORIZE → ACT → VERIFY → PROVE) [DRUPAL+WITNESS] - [ ]
security-operational-receipt: Emit signed operational receipt conforming toSTD-ECON-001andSTD-GATE-001[WITNESS] - [ ]
security-second-run-rehearsal: Execute Run 2 to prove compounding economic cost reduction [FORGE+WITNESS]
- [ ]
- Acceptance:
OPERATION_VERIFIED=PASS,RECEIPT_SIGNED=PASS,NEXT_RUN_CHEAPER=YES.
CONVOY I --- Custom Module Assurance¶
- Supports: Mountains 8, 27, 35
- Goal: Audit, classify, and shrink custom Drupal module footprint across the estate.
- Assigned:
DRUPAL(Module Auditor/Engineer),WITNESS(Verification) - Active Dolt Beads:
- [ ]
bc-tw16(P2): Module surface audit --- audit 250 contrib modules, retire 25 leaf modules with no config [DRUPAL] - [ ]
custom-module-disposition-register: Classify 60+ custom modules (KEEP,REPLACE,RETIRE,CONSOLIDATE) [DRUPAL] - [ ]
custom-module-contrib-substitution: Replace custom glue code with top-100 vetted contrib equivalents [DRUPAL] - [ ]
custom-module-test-coverage: Establish automated unit and kernel test baselines for retained modules [DRUPAL]
- [ ]
- Acceptance:
CUSTOM_LOC_REDUCED>30%,ZERO_UNAUDITED_MODULES=PASS.
CONVOY J --- Upgrade and Migration¶
- Supports: Mountains 28, 29
- Goal: Productize automated Drupal core/contrib major upgrades and migration recipes without custom rework.
- Assigned:
DRUPAL(Migration Specialist),FORGE(Consumer Verification) - Active Dolt Beads:
- [ ]
ubuntu-z2g8(P2): Renamerecipe_blucityand migrate all consumer sites [DRUPAL] - [ ]
upgrade-core-automation: Build automated Composer core/contrib update pipeline with visual regression [DRUPAL] - [ ]
migration-recipes-catalog: Author reusable Drupal migration recipes for D7/D9/D10 $\to$ D11 [DRUPAL] - [ ]
migration-clean-environment-proof: Verify migration recipes execute cleanly on fresh target environments [FORGE]
- [ ]
- Acceptance:
MIGRATION_RECIPES_REUSABLE=PASS,REGRESSION_TESTS_PASS=PASS.
CONVOY K --- Factory Observability, Evidence, and Economics¶
- Supports: Mountains 2, 34, 35, 36, 37
- Goal: Make factory execution measurable without turning agents into monitoring daemons.
- Assigned:
WITNESS(Proof Signing),BLU(Economic Metrics),FOUNDRY(Telemetry) - Active Dolt Beads:
- [ ]
PHANTOM:bl-ssf49r(P1): Model Cost & Context Optimization Epic (7 children:PHANTOM:bl-k9x12a..PHANTOM:bl-x5y91k) [BLU] - [ ]
ubuntu-qay(P2): Converge LiteLLM runtime routing and tier pricing catalog [FOUNDRY] - [ ]
bc-yjyr(P1): Repoint Claudex profiles from workstation to NAS for durable overnight inference [FOUNDRY] - [ ]
telemetry-event-stream: Normalize Gas City events with OpenTelemetry traces [FOUNDRY] - [ ]
factory-economic-scorecard: Automated calculation ofCUSTOM_LOC_REMOVED,MODEL_COST,HUMAN_TIME_SAVED[BLU]
- [ ]
- Acceptance:
POLLING_DAEMONS=0,STD_ECON_001_ENFORCED=PASS.
CONVOY L --- Infrastructure as Code and Execution Surfaces¶
- Supports: Mountains 14, 15, 16, 17, 21, 23, 37
- Goal: Every execution surface (Oracle, Mac, NAS, Container, DDEV) is reproducible, disposable, and governed via IaC.
- Assigned:
HARBORMASTER(Infra Delivery),DEACON(Daemon Health),SENTINEL(Network Security) - Active Dolt Beads:
- [ ]
PHANTOM:hq-kupp(P0): Cloudflare tunnel tokens incompose.lock.yamlremediation [SENTINEL] - [ ]
PHANTOM:hq-0p9q(P0): Purge 28 secret leaks incode_executorrepository history [SENTINEL] - [ ]
PHANTOM:hq-arol(P0): Purge cloudflared tunnel tokens from git history and lock 0700 permissions [SENTINEL] - [ ]
PHANTOM:hq-xe2n(P1): Restart stalled GitLab runner on Oracle and alignrunners.tflimits [DEACON+HARBORMASTER] - [ ]
infra-oracle-iac-reproducibility: Reconcile Terraform definitions with live Oracle container state [HARBORMASTER] - [ ]
infra-agent-docker-standard: Standardize agent container images and eliminate workstation host dependencies [FOUNDRY]
- [ ]
- Acceptance:
IAC_PROVEN=PASS,ZERO_MANUAL_PROD_SERVICES=PASS.
CONVOY M --- Moshi / OMO / Upstream Toolchain¶
- Supports: Mountains 14, 15, 23
- Goal: Adopt high-value upstream tools with thin configuration rather than Bluefly forks.
- Assigned:
FOUNDRY(Toolchain Evaluator),SENTINEL(Security Clearance) - Active Dolt Beads:
- [ ]
PHANTOM:hq-yo0h.2(P1): Moshi speech model benchmark and Oracle resource allocation assessment [FOUNDRY] - [ ]
bc-f1m2(P0): Bluefly context resolution ladder architecture: CodeGraph, QMD, Orbit, Claudex [FOUNDRY] - [ ]
bc-ck1y(P1): Orbit Local vs CodeGraph bakeoff and GitLab Orbit SDLC pilot [REFINERY] - [ ]
upstream-tool-adoption-matrix: Formalize adoption status (ADOPT,CONFIG_ONLY,DEFER,REJECT) [BLU]
- [ ]
- Acceptance:
ZERO_UNGOVERNED_FORKS=PASS.
CONVOY N --- Documentation, Schema, and Authority Convergence¶
- Supports: Mountains 1, 9, 10, 11, 12, 13
- Goal: Define doctrine once in
BluCity-Docs, reference everywhere, and enforce schema mechanically in CI. - Assigned:
REFINERY(Docs/CI Gate),FOUNDRY(Schema Authoring) - Active Dolt Beads:
- [ ]
bc-nboe(P2): CurateBluCity-Docs--- one home, one name, one authority (resolve 145 relative links) [REFINERY] - [ ]
bc-3b3i(P1): QMD Governed Documentation Indexing & Slim AGENTS.md Navigation Standard [SENTINEL+REFINERY] - [ ]
ci-doc-enforcement: Add CI checks rejecting local paths, duplicate ADRs, and stale markdown queues [REFINERY] - [ ]
schema-canonical-contracts: Maintain canonical JSON/YAML schemas for OSSA, Beads metadata, Receipts, and ContextCards [FOUNDRY]
- [ ]
- Acceptance:
SCHEMA_ENFORCED_IN_CI=PASS,ZERO_DOC_DUPLICATION=PASS.
CONVOY O --- Durability and Disaster Recovery¶
- Supports: Mountains 16, 17, 34, 37
- Goal: Critical factory state survives total loss of Oracle, workstation, or NAS.
- Assigned:
HARBORMASTER(NAS Mirroring),DEACON(Backup Automation),WITNESS(Recovery Proof) - Active Dolt Beads:
- [ ]
PHANTOM:hq-we0d(P0): Add git remote to NAS forgt/portfolio-registryto eliminate data loss hazard [HARBORMASTER] - [ ]
bc-nsh8(P0): Sync NASBluCity-Packsmirror (\~47 commits stale) [HARBORMASTER] - [ ]
bc-u2yt(P0): Inventory NASBluCity-Docsmirror (117 commits behind) [HARBORMASTER] - [ ]
dr-dolt-offhost-proof: Prove full Factory recovery from cold start using NAS persistence alone (PHANTOM:hq-xoty.3) [WITNESS] - [ ]
dr-backup-sla: Formalize backup schedule and SLA for Dolt:3308, Keycloak, and PostgreSQL [DEACON]
- [ ]
CONVOY P --- GitLab Exit & Forgejo Migration ⚠️ SCHEDULED: STARTS OCTOBER 1, 2026¶
- Supports: Mountains 4, 16, 17, 18, 19, 20, 21, 37, 38, 40
- Goal: Exit GitLab SaaS by December 15, 2026. Self-host Forgejo on private VPS, connect natively to Gas City, and retire all 32 GitLab Components by classifying each into the correct factory primitive.
- Assigned:
HARBORMASTER(Migration/Delivery),REFINERY(Component Classification),DEACON(Infrastructure),SENTINEL(Credentials),WITNESS(DR Proof) - Directive:
playbooks/directives/2026-09-23__operator__gitlab-exit-and-forgejo-migration__directive.md - Technical Plan:
playbooks/Bluefly-GitLab-Exit-Strategy-plan.md - Handoff:
.agents/context/GITLAB_EXIT_FORGEJO_MIGRATION_HANDOFF.md
⚠️ 7-DAY HOLD (Sept 23--Sept 30): Architecture frozen. No implementation until October 1, 2026.
- Phase 1 --- Foundation & Inventory (Oct 1--14):
- [ ]
bc-or8m(P0): Machine-readable GitLab estate inventory (127 projects, variables, LFS, runners) [HARBORMASTER] - [ ]
bc-45h4(P0): Subscription topology verification (A-S00141074, expiry Dec 15, 2026) [SENTINEL] - [ ]
bc-sr6q(P1): Update executive and operational playbooks with verified inventory data [HARBORMASTER]
- [ ]
- Phase 2 --- Platform POC (Oct 1--14):
- [ ]
bc-sqxb(P0): Forgejo 15 LTS on reprovisioned VPS; Host Tailscale; PostgreSQL internal;ALLOWED_HOST_LIST[DEACON] - [ ]
bc-g5jp(P0): Gas City native webhook POC (HMAC-SHA256 via Tailscale Serve;127.0.0.1:8372) [DEACON] - [ ]
bc-hcc4(P1): PILOT PROOF --- ONE Drupal repo through full Forgejo ↔ Gas City factory loop [HARBORMASTER]
- [ ]
- Phase 3 --- Classification & Delivery Contract (Oct 15--31):
- [ ]
bc-kfsv(P1): Classify all 32 GitLab components →FORGEJO_ACTION | GC_FORMULA | GC_ORDER | GC_PACK | DELETE[REFINERY] - [ ]
bc-93e7(P1): Build forge-agnostic delivery contract (delivery/core+delivery/forgejothin adapter) [REFINERY] - [ ]
bc-sttw(P1): Agent identity migration --- Phase 1: per-agent bot accounts + scoped 1Password tokens; Phase 2: JWT (v17+) [SENTINEL] - [ ]
bc-oi9p(P1): Isolated act_runner pool on Oracle/UM790 --- NO runners on Forgejo VPS [DEACON]
- [ ]
- Phase 4 --- Bulk Migration (Nov 1--25):
- [ ]
bc-7qkj(P1): Bulk import 127 projects with automated Rig admission via webhook → Order → Formula [HARBORMASTER] - [ ]
bc-fek7(P1): Backup architecture --- daily Forgejo/PG dumps to NAS + encrypted offsite [DEACON]
- [ ]
- Phase 5 --- Cutover (Nov 26--30):
- [ ]
bc-c56b(P1): Disaster recovery exercise --- restore from NAS backup on clean compute [WITNESS] - [ ]
bc-m0j6(P0): Production Cutover Day --- GitLab freeze, final delta sync, remote URL cutover [HARBORMASTER] - [ ]
bc-77rg(P0): Final factory acceptance verification (22-point checklist) [WITNESS]
- [ ]
- Phase 6 --- Decommission (Dec 1--15):
- [ ]
bc-852c(P2): GitLab decommission --- rotate credentials, archive exports, letA-S00141074expire [SENTINEL] - [ ]
bc-th5q(P1): Curate playbooks with final Gas City integration architecture [HARBORMASTER] - [ ]
bc-og39(P2): RegisterCAP-FORGEJO-001, retireCAP-GITLAB-001in capability registry [WITNESS] - [ ]
bc-0n49(P2): Port skills (gitlab-workflow→forgejo-workflow; pin Actions to SHAs) [REFINERY]
- [ ]
- Acceptance:
NO_GITLAB_REMOTES=PASS,FORGEJO_FACTORY_LOOP_PROVEN=PASS,DRUPAL_MASTER_DELETED=PASS,DR_EXERCISE_PASS=PASS,SUBSCRIPTION_COST_ZERO=PASS,READY_BEADS_UNBLOCKED=PASS.
5. Reconciled 40 Strategic Mountains Scope¶
Baselined Foundational Mountains (1--16)¶
Per STD-FACT-002, Mountains 1--16 establish the architectural baseline
and are operationalized through the Convoys: - Mountain 1 (BLU
Identity & Governance): Baselined $\to$ Operational in Convoy B
(OSSA @blu, MR !276). - Mountain 2 (Gas City Execution
Discipline): Baselined $\to$ Operational in Convoy A & K (No
polling, disposable sessions). - Mountain 3 (Formula / Order / Event
Standards): Baselined $\to$ Operational in Convoy E (Formula v2
compiler, Orders). - Mountain 4 (Forge Factory Convergence):
Transitioning → Convoy C (MR pipelines, shared components) +
Convoy P ⚠️ (GitLab exit → Forgejo + Gas City; cutover by Nov 30,
2026). - Mountain 5 (DrupalWorks Public Pack): Baselined $\to$
Operational in Convoy E & F (Public portable Drupal pack). -
Mountain 6 (BluCity-Packs Private Overlay): Baselined $\to$
Operational in Convoy E (Private operational bindings). - Mountain
7 (ContextControl Console Architecture): Baselined $\to$ Operational
in Convoy G (STD-ARCH-003). - Mountain 8 (Drupal Maintenance
Factory): Baselined $\to$ Umbrella for Convoys E, F, H, I, J. -
Mountain 9 (Project .agents/ Standard): Baselined $\to$
Operational in Convoy N (Committed manifests, clean gitignores). -
Mountain 10 (Project Documentation Standard): Baselined $\to$
Operational in Convoy N (Predictable repo docs). - Mountain 11
(BluCity-Docs Governance): Baselined $\to$ Operational in Convoy N
(DOCUMENTATION_DRIFT=YES). - Mountain 12 (Product Documentation):
Baselined $\to$ Operational in Convoy N (Separate product from
session state). - Mountain 13 (Schema Enforcement): Baselined $\to$
Operational in Convoy N (CI-enforced schema contracts). - Mountain
14 (Local Workstation Environment): Baselined $\to$ Operational in
Convoy L (Disposable dev environments). - Mountain 15 (Model &
Inference Architecture): Baselined $\to$ Operational in Convoy K &
L (LiteLLM, Claudex NAS). - Mountain 16 (Oracle / Production
Convergence): Baselined $\to$ Operational in Convoy A & L
(IaC-driven Oracle).
Strategic Delivery Mountains (17--40)¶
- Mountain 17 (NAS / Durability): Active in Convoy A, O
[Beads:
PHANTOM:bl-ws9obz,PHANTOM:hq-we0d,bc-nsh8,bc-u2yt] - Mountain 18 (Public Package & Release): Active in Convoy C,
D [Beads:
PHANTOM:bl-sd98nf,PHANTOM:bl-hii14j,PHANTOM:hq-pm1a] - Mountain 19 (Multi-Registry Release Standard): Active in
Convoy C, D [Beads:
package-duadp-npm,ci-npm-release] - Mountain 20 (Merge Trains & Delivery Flow): Active in Convoy
C [Beads:
PHANTOM:bl-iybdig,PHANTOM:hq-y6t3] - Mountain 21 (GitLab Agent Delivery): Active in Convoy B, C,
L [Beads:
PHANTOM:bl-l6fhpj,PHANTOM:hq-xe2n] - Mountain 22 (GitLab Duo / MCP / Tool Governance): Active in
Convoy B, M [Beads:
du-tjp,tool-gate-cedar] - Mountain 23 (Moshi + OMO Evaluation): Active in Convoy M
[Bead:
PHANTOM:hq-yo0h.2] - Mountain 24 (KB_Cache Recovery): Active in Convoy F [Beads:
kb-cache-governance,bc-3b3i] - Mountain 25 (Drupal Package Quality Gate): Active in Convoy C,
F [Bead:
PHANTOM:bl-s06j5b] - Mountain 26 (Security & Release Factory): Active in Convoy B,
H [Beads:
PHANTOM:bl-m2a9un,PHANTOM:hq-kupp,PHANTOM:hq-0p9q,PHANTOM:hq-arol] - Mountain 27 (Custom Module Assurance): Active in Convoy F, I
[Beads:
PHANTOM:bl-08nift,bc-tw16] - Mountain 28 (Drupal Upgrade Factory): Active in Convoy F, J
[Bead:
ubuntu-z2g8] - Mountain 29 (Migration Factory Pack): Active in Convoy F, J
[Bead:
migration-recipes-catalog] - Mountain 30 (ContextControl Customer UI): Active in Convoy G
[Beads:
bc-nfnp,bc-jbsa] - Mountain 31 (AGUI Product Experience): Active in Convoy G
[Bead:
bc-13pv] - Mountain 32 (Customer Data Sovereignty): Active in Convoy B,
G [Bead:
contextcontrol-tenant-isolation] - Mountain 33 (Context Model): Active in Convoy B, G [Bead:
contextcontrol-context-cards] - Mountain 34 (Operational Receipt): Active in Convoy H, K
[Bead:
security-operational-receipt] - Mountain 35 (Capability Flywheel): Active in Convoy E, K
[Bead:
formula-promotion] - Mountain 36 (Factory Product Economics): Active in Convoy K
[Beads:
PHANTOM:bl-ssf49r,ubuntu-qay] - Mountain 37 (Factory Observability): Active in Convoy A, K
[Bead:
PHANTOM:bl-38cejv] - Mountain 38 (Factory Pack Architecture): Active in Convoy E
[Beads:
bc-ypy2,PHANTOM:bl-xzpb5f,mba-0y4] - Mountain 39 (Released Product Inventory): Active in Convoy C,
D [Bead:
bc-ftdk] - Mountain 40 (Factory Completion Program): Active in Convoy A,
H, N [Bead:
bc-t1ox]
6. Factory Completion Receipt Contract¶
Every completed operation, MR, or closed Bead must append this verified economic receipt:
REQUESTED_EFFECT=
VERIFIED=
SOURCE_DELIVERED=
RUNTIME_VERIFIED=
EVIDENCE=
CAPABILITY_CHANGE=
NONE | CANDIDATE | UPDATED | PROVEN | REMOVED | TRANSFERRED_TO_UPSTREAM
REUSE_EFFECT=
REUSED_EXISTING_UPSTREAM | REMOVED_CUSTOM_OWNERSHIP | CONSOLIDATED_DUPLICATION |
CREATED_REUSABLE_CAPABILITY | IMPROVED_DISCOVERABILITY | REDUCED_RE_DERIVATION |
REDUCED_MODEL_USAGE | REDUCED_HUMAN_INTERVENTION | REDUCED_FAILURE_RISK |
REDUCED_EXECUTION_TIME | IMPROVED_VERIFICATION | IMPROVED_RECOVERY | NONE
IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES|NO
WHY=
WHAT_WILL_THE_NEXT_AGENT_REUSE=
WHAT_WOULD_STILL_HAVE_TO_BE_RE_DERIVED=
Migration Factory --- Product Strategy & Execution¶
Full strategy document:
strategy/migration-factory-strategy.md(53 sections) Bead:mba-72p--- Migration Factory Strategy --- Team Discussion & Decisions
Core Thesis¶
Bluefly can turn repeated digital-estate migration work into an accumulating library of proven capability, allowing increasingly complex portfolios to be migrated with less rediscovery, less human effort, better verification, and lower cost per accepted outcome.
Strategic Framing¶
MIGRATION FACTORY = LAND / TRANSFORMATION OFFER (not standalone product)
DIGITAL ESTATE OPERATIONS = RECURRING PRODUCT
CONTEXTCONTROL = CUSTOMER CONTROL SURFACE
BLUEFLY FACTORY = EXECUTION + MARGIN ENGINE
Migration as Land Motion → Recurring Operations¶
MIGRATION → KNOWN ESTATE → SECURITY OPS → A11Y → UPGRADES → CUSTOM-CODE REDUCTION → DIGITAL ESTATE OPS
Key Decisions Needed (§51)¶
- [ ] Is Migration Factory a land offer or independent product?
- [ ] Which source problem first? (Drupal legacy / WP sprawl / portfolio consolidation / long-tail rescue)
- [ ] Which market first? (higher-ed / state gov / enterprise)
- [ ] Minimum estate size for Factory economics?
- [ ] Which named accounts to research immediately?
- [ ] Which existing client becomes the first proof?
DrupalWorks Pack Discovery (2026-09-23)¶
DRUPALWORKS_PACK=EXISTS (30+ production formulas, 13 orders)
FORMULAS=PRODUCTION_GRADE (real bash: composer audit, drush pm:list, jq, drupal.evidence.v1 JSON)
CRON_ORDERS=4 (config-verify, contrib-audit, estate-inventory, release-verify — Monday schedule)
MANUAL_ORDERS=9 (on-demand audits)
FIRST_DRUPAL_EXECUTION=mba-66s (mol-drupal-contrib-audit cooked on bluefly-io, dispatched to organization.worker)
CARTESIAN_EXPLOSION=91+ phantom order entries (13 orders × 7+ rigs, only 2 are Drupal) — bead mba-0y4
AGENT_BINDING_GAP=drupal-auditor not bound at rig level (gc sling bluefly-io/drupal-auditor fails)
Near-Term Actions¶
- [ ] Fix DrupalWorks cartesian explosion (mba-0y4 → refinery)
- [ ] Add drupal-auditor agent binding for bluefly-io and amcs-demo rigs
- [ ] Verify mol-drupal-contrib-audit completes on bluefly-io (mba-66s)
- [ ] Build target-account research list (50 organizations)
- [ ] Define Migration Readiness Assessment offer (scope, inputs, outputs, timeline, price)
- [ ] Choose repeatability experiment (2+ related real sites)
Factory Concepts --- Product Architecture Doctrine (Draft)¶
Full document:
strategy/factory-concepts.md(50 sections) Bead:mba-2nk--- Factory Concepts (audit + curation needed) Status: DRAFT_DOCTRINE --- needs verification against current Gas City/Beads, audit for overlap with STD-AUTH-001/STD-ECON-001/STD-FACT-002
Core Thesis¶
Bluefly Factory is a governed production system for turning complex recurring work into increasingly reusable operational capability.
Key Concepts Requiring Audit and Curation¶
- [ ] §1 Factory as OS for reusable work --- verify against STD-FACT-002 Mountains
- [ ] §2 One Factory many Packs --- verify against current BluCity-Packs architecture
- [ ] §3 Correct primitive model (AGENT/BEAD/FORMULA/RIG/PACK/EVENT) --- verify against Gas City docs
- [ ] §4 Verified Operations Loop (DETECT→UNDERSTAND→MATCH→AUTHORIZE→ACT→VERIFY→PROVE→IMPROVE)
- [ ] §5 Pattern-to-Capability conversion lifecycle
- [ ] §7 Exception-driven human work --- verify against existing witness/human-gate patterns
- [ ] §8 Decision Memory --- verify against existing bead evidence model
- [ ] §9 ContextControl as human control room --- verify against contextcontrol-factory-control-plane.md
- [ ] §10 Live context vs giant prompts --- verify against STD-CONTEXT-001
- [ ] §14 Human roles (Context Curator, Agent Ops Manager, Agentic Flow Engineer)
- [ ] §15 Service as Software model
- [ ] §16-17 Evidence as first-class output / Evidence before claims
- [ ] §19 Net negative ownership as measurable operation
- [ ] §22-23 Policy Plane + Obligation model --- verify against Cedar/ContractPlane
- [ ] §26 Model routing as economics
- [ ] §40 Factory Moat (accumulated proven capabilities)
- [ ] §41 Open core model --- public DrupalWorks vs private operating capability
- [ ] §44 Factory maturity levels 0-5
- [ ] §47 Candidate Pack families
- [ ] §49 Universal Factory Gate
DrupalWorks AI Automators Integration (COMPLETED)¶
BEAD=mba-q48 (closed)
COMMIT=fdcc07e on release/v0.1.x
REMOTE=gitlab-bluefly:blueflyio/agent-platform/drupal/drupalworks.git
NEW_SKILL=drupal-ai-automators (SKILL.md + references/upstream-docs.md)
FORMULA_UPDATED=mol-drupal-ai-baseline.toml (now detects ai_automators, token, ai_automator_extractor)
PACK_TOML_UPDATED=added drupal/token + drupal/ai_automator_extractor to required_packages
MINDMAP_UPDATED=drupal-ai-module-mindmap.md (AI Automators branch added)
UPSTREAM_FIRST_UPDATED=upstream-first.md (5-step escalation ladder)
VALIDATION=34/34 TOML valid, pack.toml valid, skill files exist, git push clean
IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES
WHY=Every future agent discovers AI Automators as upstream capability through skill/formula/mindmap. Eliminates rediscovery, prevents custom code where upstream handles the field type.
ORACLE GATE ZERO --- P0 INCIDENT (Active)¶
Full directive:
operations/oracle-gate-zero.md(22 sections) Bead:mba-9l1--- Oracle Gate Zero (P0, open) Mountain: 2 (Factory Economy) + 16 (Oracle Runtime)
FACTORY_RUNTIME_AUTHORITY=ORACLE
WORKSTATION_GAS_CITY_AUTHORITY=NO
WORKSTATION_BEADS_AUTHORITY=NO
Execution Order (15 steps)¶
- [ ] 1. Capture current load / memory / process baseline
- [ ] 2. Inventory native Gas City sessions + claims
- [ ] 3. Classify the 32 Claude processes
- [ ] 4. Identify PID 4880 container / source owner
- [ ] 5. Inventory bd/gc client versions across shared Dolt clients
- [ ] 6. Identify canonical binary installation owner
- [ ] 7. Search existing Oracle beads for each root defect
- [ ] 8. Update / dedup / route existing work
- [ ] 9. Build coordinated version-convergence plan
- [ ] 10. Apply only through source/IaC/release path
- [ ] 11. Restore native Beads
- [ ] 12. Verify worker ceiling
- [ ] 13. Verify load / memory / fork-rate recovery
- [ ] 14. Witness verify
- [ ] 15. Resume normal Factory execution
Factory Capability: Documentation Integrity (Candidate)¶
Full design:
capabilities/documentation-integrity-audit.md(24 sections) Bead:mba-e5j--- Documentation Integrity capability (P1, open) Central rule: Detect cheaply. Record once. Route to real owner. Spend model only on ambiguity.
CI = prevention
Gas City periodic audit = reconciliation
Agent = semantic resolution (only when needed)
What to Build (8 items)¶
- [ ] 1. Deterministic documentation-integrity check
- [ ] 2. Machine-readable result
- [ ] 3. GitLab CI component
- [ ] 4. Formula wrapping same check for estate reconciliation
- [ ] 5. Event only on material finding
- [ ] 6. Bead deduplication by finding signature
- [ ] 7. Routing by documented authority
- [ ] 8. Witness verification