Skip to content

BLUEFLY FACTORY --- MASTER RUNNING TODO, BEADS & PROOF CHAIN

Purpose: This is the simple execution-facing companion to the Bluefly Factory Living Plan. It answers four questions: What are we proving now? What Beads already own the work? What is blocked? What becomes eligible next?

The detailed Mountains, Convoys, blockers, strategy, and existing Bead inventory from the prior tracker are preserved below. This top section is the controlling execution order.

Architecture: ContextControl is the commercial Drupal product and governed human surface. Gas City is the backend orchestration authority. Beads/Dolt is durable work authority. Source-controlled definitions travel through the governed forge/release path. Drupal may brand Gas City concepts, but must not create a second scheduler, work graph, event system, mail system, or agent runtime.


0. THE PLAN --- SIMPLE VERSION

GATE ZERO
  Prove Oracle Gas City is healthy enough to trust.
  Resolve real Agents, service identities, Beads/Dolt, Events, Mail, Sessions,
  Claudex access, and self-hosted inference connectivity.

        ↓ ONLY WITH WITNESS PASS + RECEIPT

TEST 1 — AUTONOMOUS GAS CITY LIFECYCLE
  One real request enters Gas City.
  Gas City routes it.
  A real Agent claims durable work.
  The Agent executes.
  Delivery happens through the governed source path when required.
  Witness verifies it.
  A complete Operational Receipt is produced.
  Thomas transports nothing between agents.

        ↓ ONLY WITH WITNESS PASS + RECEIPT

TEST 2 — MINIMAL CONTEXTCONTROL READ PROOF
  Drupal shows exactly:
  1 Objective
  1 Initiative
  1 Work Item
  1 Agent
  1 live status
  1 event timeline
  1 Receipt
  All from real Gas City / Beads authority. No duplicate Drupal work graph.

        ↓

TEST 3 — LIVE EVENT PROJECTION
  ContextControl updates from native Gas City Events/SSE.
  No LLM polling loop. No fake event bus.

        ↓

TEST 4 — ONE GOVERNED WRITE
  A user performs one approved action in Drupal.
  Policy authorizes or denies it.
  Gas City performs the real mutation.
  Event + Receipt prove the result.

        ↓

TEST 5 — GOVERNED AI EXPLANATION
  Drupal AI explains authoritative state using scoped capabilities and evidence.
  The AI does not become authority.

        ↓

TEST 6 — COMPLETE OPERATOR LOOP
  A normal operator can understand, authorize, act, verify, and prove one
  operation through ContextControl without using the CLI.

        ↓

TEST 7 — CLEAN CONSUMER
  Reproduce the proven capability from released/version-pinned artifacts in a
  clean supported environment with no Thomas-local state or undocumented fixups.

        ↓

TEST 8 — SECOND REAL OBJECTIVE
  Run materially different real work through the same system and prove reuse,
  lower re-derivation, and cost per verified completed Work Item.

        ↓

TEST 9 — CUSTOMER / OPERATOR PROOF
  A real non-Gas-City expert can use the product language, understand state,
  identify what needs attention, take one safe action, and understand the
  evidence without Thomas or CLI knowledge.

        ↓

LATER NATIVE GAS CITY PRODUCT PROOFS
  Mail → Automations/Orders → Procedures/Formulas → Sessions → Pools/Polecats →
  Deacon/Dogs/health → connected-client Chat → Pack lifecycle → Commands/Doctor →
  Patches → resource governance.

Hard Chain Law

TEST_N+1_ELIGIBLE = TEST_N_PROVEN

REQUIRED_TO_ADVANCE:
  RESULT=PASS
  EXPECTED_EVIDENCE=OBSERVED
  FALSIFICATION_CONDITION=NOT_TRIGGERED
  WITNESS_VERIFICATION=PASS
  OPERATIONAL_RECEIPT=COMPLETE
  RUNTIME_EVIDENCE=VALID
  ADVANCEMENT_GATE=PASS
  UNLOCKS_NEXT_TEST=YES

PROHIBITED:
  PASS_BY_ASSERTION
  PASS_BY_REPOSITORY_STATE
  PASS_BY_SIMULATION
  PASS_BY_STUB
  SKIP_TEST
  PARALLEL_FUTURE_TEST_EXECUTION

If a test is FAIL, PARTIAL, DEGRADED, or UNVERIFIED, the next test stays blocked. Repair work attaches to the failed test, evidence is preserved, and the same test is rerun.


1. WHAT WE DO NOW

NOW --- Gate Zero only

  • [ ] mba-9l1 --- Oracle Gate Zero: finish the existing 15-step recovery and verification sequence.
  • [ ] Repair native Beads compatibility: eliminate the observed schema/client skew instead of relying on BD_IGNORE_SCHEMA_SKEW=1.
  • [ ] Restore trustworthy gc health: partial/unknown/unavailable state is degraded even if a command exits 0.
  • [ ] Resolve Oracle saturation/root runtime defects: use the existing P0 Beads, especially bc-lm6m, rather than opening duplicate work.
  • [ ] Resolve the actual runtime Agent roster: for every doctrine role record ROLE, RESOLVED_AGENT, AGENT_SOURCE, and SERVICE_IDENTITY.
  • [ ] Prove non-human identity: no Thomas credential may be required for unattended execution.
  • [ ] Prove Oracle is the sole Factory runtime authority: no workstation City and no NAS City.
  • [ ] Prove Claudex can operate against Oracle while using approved self-hosted model endpoints. Oracle runs Gas City; the model host is an inference dependency, not a second City.
  • [ ] Reconcile stale model-routing work: bc-yjyr currently describes moving Claudex profiles to NAS. Re-scope or supersede only after Bead search/evidence; do not move Gas City authority to NAS.
  • [ ] Witness Gate Zero: one independent PASS receipt before Test 1 is eligible.

DO NOT START YET

  • [ ] Test 1 implementation is BLOCKED by Gate Zero.
  • [ ] Tests 2--9 are BLOCKED by the immediately prior proof.
  • [ ] Later Mail/Orders/Formulas/Sessions/Pools/Deacon/Dog/connected-client/Pack proofs are recorded, not authorized.
  • [ ] Graphics and architecture diagrams may document the intended architecture, but they do not count as runtime proof and must not drive premature implementation.

2. PROOF CHAIN --- TODO + BEAD OWNERSHIP

Do not invent duplicate Beads just to mirror this list. For each proof, search the canonical Dolt store first. Reuse or refine the existing Bead when one already owns the effect. Create a new canonical Bead only when the gap is proven.


Stage Status Existing Beads / authority to Primary role Required evidence to unlock next reconcile


Gate Zero ACTIVE mba-9l1, bc-lm6m, MAYOR + DEACON + Oracle/City/Beads/Agents/identity/events bc-g2nl, PHANTOM:hq-zfuf, SENTINEL trustworthy; Witness PASS receipt PHANTOM:hq-zhg4, identity/security
P0s

Test 1 --- BLOCKED Search first; reuse existing BLU routes; MAYOR One real end-to-end lifecycle; Thomas Autonomous factory-loop / first-operation dispatches; transport = 0; receipt complete lifecycle work where scope matches POLECAT executes;
HARBORMASTER
delivers

Test 2 --- Minimal BLOCKED bc-jbsa, mba-dtn, DRUPAL 1 Objective + 1 Initiative + 1 Work Item + ContextControl read PHANTOM:bl-08nift and existing 1 Agent + status + events + receipt from API-normalization work as real authority applicable

Test 3 --- Live BLOCKED telemetry-event-stream only DRUPAL + DEACON Native event-driven update; Events where it does not replace replay/reconnect proven; polling daemon = native Gas City Events/SSE 0

Test 4 --- Governed BLOCKED Convoy B identity/policy work + DRUPAL + BLU + One authorized/denied real action; Gas write ContextControl operation work SENTINEL City mutation; event + receipt

Test 5 --- AI BLOCKED bc-nfnp, bc-13pv, DRUPAL Evidence-linked explanation over explanation ContextCard / Drupal AI authoritative state; AI is not authority capability work

Test 6 --- Operator BLOCKED mba-z5y and proven pieces DRUPAL + BLU Operator completes DETECT → UNDERSTAND → loop from Tests 2--5 AUTHORIZE → ACT → VERIFY → PROVE without CLI

Test 7 --- Clean BLOCKED package-clean-consumer-test FORGE Fresh supported environment reproduces consumer plus released/versioned capability with no local magic dependencies

Test 8 --- Second BLOCKED Reuse the proven path; no BLU Second real objective; reuse measured; objective bespoke architecture Bead cost/re-derivation measured

Test 9 --- BLOCKED Product usability proof; search PRODUCT/DRUPAL + Non-expert user succeeds without Gas City Customer/operator before creating canonical Bead BLU jargon, CLI, or Thomas

Later native LOCKED Create/reconcile only when Narrow owner per Native Gas City capability proven without proofs prior accepted proof unlocks capability rebuilding it them



3. PRODUCT LANGUAGE --- UI BRANDING WITHOUT CHANGING AUTHORITY

ContextControl product term Native authority


Objective Mountain Initiative Convoy Work Item Bead Workspace Rig Procedure Formula Automation Order Signal Event Capability Pack Pack Agent Agent Mail Gas City Mail Run Session / disposable execution Receipt Operational Receipt / evidence

The UI may use the product term. Receipts, API contracts, debugging surfaces, and evidence preserve the native identifier underneath.


4. CONTEXTCONTROL END STATE --- PRODUCT TODO, NOT CURRENT AUTHORIZATION

The commercial end state is ordinary product CRUD in Drupal while preserving native authority.

  • [ ] Objectives: list/view/manage the product representation of strategic work without inventing a second durable work authority.
  • [ ] Initiatives: list/view/create/manage Convoys through the native contract.
  • [ ] Work Items: list/view/create/update Beads through Beads/Gas City authority.
  • [ ] Agents: list configured Agents separately from live Sessions.
  • [ ] Procedures: manage Formula definitions through their native versioned representation.
  • [ ] Automations: manage Order triggers/actions through native Gas City semantics.
  • [ ] Signals: consume native Events/SSE with replay cursors.
  • [ ] Mail: Inbox/Sent/thread UX over Gas City Mail, including human and Agent destinations under policy.
  • [ ] Runs: observe Sessions, provider/runtime health, logs/peek/nudge where authorized.
  • [ ] Capability Packs: expose native Pack composition without creating Bluefly-only pack primitives.
  • [ ] Receipts: show evidence, policy decision, source revisions, runtime outcome, model/provider economics, Witness result, and next action.
  • [ ] Chat: use Gas City connected-client/extmsg semantics when proven so Drupal participates in a real Gas City session rather than becoming a parallel chat authority.
  • [ ] Source-controlled edits: when Procedures, Automations, Packs, or Agent definitions are source authority, Drupal produces the governed native representation and uses the governed forge/release path. Do not make the Drupal database the hidden source of truth.

5. PRODUCTION / SCIENCE RULES FOR EVERY BEAD

Every proof Bead must declare before execution:

HYPOTHESIS=
FALSIFICATION_CONDITION=
CURRENT_AUTHORITY=
BASELINE=
ROLE=
RESOLVED_AGENT=
AGENT_SOURCE=
SERVICE_IDENTITY=
UPSTREAM_OWNER=
CAPABILITY_MATCH=
MINIMUM_CHANGE=
TEST_INPUT=
EXPECTED_OBSERVATION=
ACCEPTANCE=
VERIFICATION=
DELIVERY_PATH=
EVIDENCE_PATH=

And finish with:

ACTUAL_OBSERVATION=
RESULT=PASS|FAIL|PARTIAL
WITNESS_VERIFICATION=
OPERATIONAL_RECEIPT=
UNLOCKS_NEXT_TEST=YES|NO
DEFECT_OR_NEXT_BEAD=

CUSTOM_LOC_ADDED=
CUSTOM_LOC_REMOVED=
DUPLICATE_CAPABILITIES_REMOVED=
OBSOLETE_FILES_REMOVED=
NEW_LONG_TERM_OWNER_SURFACES=
NET_OWNERSHIP_DELTA=

WHAT_WILL_THE_NEXT_AGENT_REUSE=
WHAT_WOULD_STILL_HAVE_TO_BE_RE_DERIVED=

Zero prototype debt

FAKE_DATA=NO
MOCK_GAS_CITY=NO
STUB_API=NO
SIMULATED_SUCCESS=NO
SECOND_WORK_GRAPH=NO
CUSTOM_SCHEDULER=NO
CUSTOM_AGENT_LOOP=NO
LLM_POLLING=NO
THOMAS_CREDENTIALS=NO
UNVERSIONED_PACK=NO
GENERIC_OPENAPI_TO_AI_TOOL_EXPLOSION=NO

A temporary compatibility workaround is allowed only for a proven upstream defect and must have an owner, test, removal condition, and tracked defect.


6. UPSTREAM-FIRST BUILD ORDER

Before source mutation, prove whether the capability already belongs to Gas City, Drupal core/contrib, Drupal AI, Tool API/MCP, ECA/FlowDrop, Canvas/SDC, AgenticTools, BluCity-Packs, Cedar/ContractPlane, the forge, or another accepted upstream component.

UPSTREAM_EXISTS
→ CONFIGURE / COMPOSE / PROJECT

EXISTING_BLUEFLY_CAPABILITY
→ WIRE / REPAIR / VERIFY

REAL_GAP
→ THIN ADAPTER ONLY

CUSTOM_CODE
→ LAST RESORT

For Drupal specifically:

Core
→ Contrib
→ Contrib configuration
→ Recipe / config action
→ Canvas / SDC
→ ECA / FlowDrop
→ Drupal AI
→ Tool API / MCP
→ Existing Bluefly extension
→ Custom code

api_normalization is a contract-normalization capability, not permission to turn every imported OpenAPI endpoint into an unrestricted AI tool.


7. LATER GAS CITY CAPABILITY HORIZON --- REMEMBER, DO NOT BUILD EARLY

These are explicitly retained so we do not discover them late and rebuild them badly:

  • [ ] Mail console proof --- native Gas City Mail projected into ContextControl.
  • [ ] Automation proof --- Orders with cooldown/cron/condition/event/manual triggers.
  • [ ] Procedure graph proof --- Formula execution and evidence.
  • [ ] Session operator proof --- tmux/provider-backed Sessions; attach/peek/logs/nudge without treating tmux as durable authority.
  • [ ] Elastic worker proof --- native pools / scale_check / Polecat-style bounded workers.
  • [ ] Health patrol proof --- native deterministic health/recovery; Deacon judgment only where judgment is actually needed.
  • [ ] Dog proof --- pack utility-agent patterns only where deterministic Orders/exec do not already own the job.
  • [ ] Connected-client Chat proof --- ContextControl Chat as a native external Gas City participant.
  • [ ] Pack lifecycle proof --- Agents, Formulas, Orders, Events, commands, patches, assets, overlays as the native Pack contract supports.
  • [ ] Commands/Doctor proof --- project native deterministic command and doctor results rather than rebuilding checks.
  • [ ] Patch-without-fork proof --- Agent/provider/Rig patching rather than copied Pack forks.
  • [ ] Resource-governance proof --- provider/model/session capacity and economics exposed without inventing another scheduler.

8. VISUAL / DATA / ARCHITECTURE TODO

These can be produced in parallel as documentation, but they do not unlock implementation stages.

  • [ ] Product architecture map: ContextControl → Gas City → Beads/Dolt → forge → evidence.
  • [ ] Chain-of-proof diagram: Gate Zero through Test 9 with hard advancement gates.
  • [ ] Primitive map: Agent / Bead / Formula / Rig / Pack / Event, plus Sessions, Mail, Orders, Pools, Commands and connected clients as mechanisms rather than extra primitives.
  • [ ] Authority map: what Drupal owns vs Gas City vs Beads/Dolt vs source control vs policy/evidence.
  • [ ] Mail + Chat sequence: human/Drupal → extmsg/Mail → Gas City → Agent Session → Work Item → reply/event/receipt.
  • [ ] CRUD contract map: product term ↔ native object ↔ read API ↔ write API ↔ source/runtime authority ↔ evidence.
  • [ ] Event lifecycle diagram: request → request_id/cursor → native Events/SSE → terminal event → Drupal projection.
  • [ ] Agent/session/runtime map: configured Agent vs disposable Session vs provider vs tmux vs pool.
  • [ ] Factory economics dashboard spec: cost per verified completed Work Item, human interventions, retries, custom LOC delta, reuse, latency, paid vs self-hosted model use.
  • [ ] Customer journey map: operator sees attention → understands why → authorizes → watches progress → receives proof.

9. CURATION NOTES / KNOWN TRACKER RECONCILIATION

  • The prior tracker says "15 Canonical Cross-Mountain Convoys" but contains Convoys A through P. Preserve all Convoys for now; reconcile the count and canonical status through the governing docs rather than deleting one here.
  • Existing Bead IDs below are retained as historical/current execution references. Before acting on any one, verify it still exists, is not closed/superseded, and still owns the described effect in canonical Dolt.
  • Existing tracker language that implies NAS-hosted inference or model routing must be reconciled with the current architecture before execution. Oracle remains Factory runtime authority. NAS remains durability/artifact infrastructure unless an accepted architecture decision explicitly changes that.
  • The detailed tracker below remains useful for Mountains, Convoys, P0s, package/release work, migration strategy, documentation integrity, and the GitLab/Forgejo transition. The proof chain above controls what may execute next.

PRESERVED DETAILED TRACKER

The content below is the prior RunningTodo retained intact so we do not lose Beads, Convoys, Mountains, blockers, or strategic work while moving to the proof-chain execution model.

BLUEFLY FACTORY --- MASTER RUNNING TODO & CROSS-MOUNTAIN CONVOY TRACKER

Purpose: This document is the living execution tracker for the Bluefly Factory. It bridges the 40 Strategic Mountains into 15 Canonical Cross-Mountain Convoys, binding high-level durable missions to actionable, dependency-aware Beads in the canonical Dolt store (:3308/hq).

Policy & Architecture Authorities (Do Not Restate Here): - Authority Precedence & Light Factory: Engineering-Standard/standards/core/STD-AUTH-001-authority-precedence-and-light-factory-model.md - Pre-Execution Gate: Engineering-Standard/operating-model/STD-GATE-001-factory-execution-gate.md - Economic Completion Gate: Engineering-Standard/standards/core/STD-ECON-001-factory-economic-gate.md - Team Dispatch & Role Governance: Engineering-Standard/operating-model/agent-blu-factory-directive.md - ContextControl Architecture: Engineering-Standard/architecture/contextcontrol-factory-control-plane.md - Factory Mountains Strategy (1--40): Engineering-Standard/architecture/STD-FACT-002-factory-mountains-roadmap.md - Cross-Mountain Convoys & Reconciliation: Engineering-Standard/architecture/STD-FACT-003-cross-mountain-convoys-and-reconciliation.md - Gas City Platform Authority: https://docs.gascity.com/ (Agent reference: https://docs.gascity.com/llms-full.txt)


1. Operating Invariant & Team Dispatch

BLU_ROUTES=YES
BLU_EXECUTES=NO

MAYOR_DISPATCHES=YES
POLECAT_EXECUTES=YES
HARBORMASTER_DELIVERS=YES
REFINERY_CONVERGES=YES
DRUPAL_OWNS_DRUPAL=YES
SENTINEL_OWNS_SECURITY=YES
FORGE_PROVES_REUSE=YES
WITNESS_VERIFIES_INDEPENDENTLY=YES
FOUNDRY_BUILDS_ONLY_PROVEN_GAPS=YES
DEACON_PATROLS_DETERMINISTICALLY=YES

Team Taxonomy: Upstream vs. Bluefly-Owned


Category Roles Source


Upstream Gas City MAYOR, DEACON, Gas City organization (import/configure, do WITNESS, REFINERY, pack NOT rebuild) POLECAT

Bluefly-Owned BLU, HARBORMASTER, BluCity-Packs / OSSA (author and maintain) DRUPAL, SENTINEL, manifests FOUNDRY, FORGE


Implementation Strategy

Wire, substitute, and prove --- not build.

The Factory's main problem is not missing capability but that existing capability is unwired, unlocked, and unverified. Contrib/upstream capability must not be rebuilt unnecessarily.

Reuse Model

AUTHOR ONCE
→ Pack / CI Component
→ Version + Pin
→ Project through references
→ Project to each harness using upstream mechanisms
→ Verify

NOT:
  copy Skill / copy Formula / copy policy / copy agent / copy CI
  into every repository

Skills are projections of capabilities, not the capability itself. Harness-specific needs are patches, not forks. packs.lock makes composition reproducible.

Execution Wave Ordering

WAVE 0 — Repair the Factory runtime itself.
WAVE 1 — Execution Gate + agent/identity convergence.
WAVE 2 — Wire Mountains/Convoys to what already exists.
WAVE 3 — RUN THE PRODUCT: Drupal Security & Release on bluefly.io.
WAVE 4 — Run 2 on the same estate and measure reuse.
WAVE 5 — Second estate.
         Only then: PROVEN REUSABLE CAPABILITY.

Waves 0--2 are plumbing and must not expand. Wave 3 is the product.

Upstream Substitution Ledger


Capability Upstream Owner Bluefly Owns


Security/update Composer audit, Drupal Integration, policy, detection release/security feeds estate fan-out

Update application Renovate Decision, verification, receipt

Custom-code analysis PHPStan, Drupal Check, Classification, Rector/Upgrade Status disposition, retirement

Migration Drupal Migrate, Recipes, estate migrate_plus, playbook, verification migrate_tools

Sovereignty Group + entity access + Tenant policy, Cedar isolation proof

Context ai_context ContextCard structure, composition retrieval

Durability restic/borg/rclone Schedule, verification, SLA

Merge trains GitLab native Selective enablement, CI components

Observability OpenTelemetry, Wiring, dashboards, OtterMon, Gas City economic metrics events



2. Gas City Execution Hierarchy & Deduplication Law

The 40 Mountains are durable strategic missions, not 40 parallel task backlogs. They converge into 15 shared delivery Convoys feeding bounded Beads through native Gas City and Beads primitives:

MOUNTAIN (Durable Mission)
   ↓
SHARED CONVOY (Coordinated Multi-Bead Batch)
   ↓
BEAD GRAPH (Dolt-backed Work DAG: blocks, tracks, discovered-from)
   ↓
FORMULA / MOLECULE / GATE (Repeatable Method / Asynchronous Gate)
   ↓
AGENT (Configured Worker Role: OSSA v0.4.1)
   ↓
SESSION (Disposable Execution Process)
   ↓
EXECUTION (Smallest Verifiable Source Mutation)
   ↓
VERIFICATION (Independent Witness Proof & Economic Gate)

Deduplication Law

  1. Search existing Beads (bd list, bd ready) before creating new work.
  2. If a capability touches multiple Mountains (e.g. Identity in M1, M4, M6, M7, M21, M30) $\to$ ONE Bead under SHARED CONVOY B, not separate copies per Mountain.
  3. Use native dependency edges: blocks (ordering/readiness), tracks (convoy grouping), parent-child (containment), discovered-from (emergent findings).

Native Gas City & Beads Mechanics (Tutorial 06 Best Practices)

  • Dependency-Aware Work Pull: Use bd ready --metadata-field gc.routed_to=<agent> --unassigned --limit=1 --- work blocked by open dependencies is automatically invisible until the blocker closes.
  • Stranded Work Detection: Run gc convoy stranded to find open beads in active convoys with no assigned worker.
  • Automated Lifecycle & Reconciliation: Convoys auto-close via on_close hooks when all tracked beads close. Run gc convoy check to reconcile missed hooks; use gc convoy land <id> for --owned convoys.
  • Target Branch Inheritance: Set --target release/v0.1.x on convoys so member beads automatically inherit the governed release target branch.
  • Structured Metadata over Title Hacks: Set state via --set-metadata branch=..., --set-metadata reviewer=..., --set-metadata gc.routed_to=... rather than polluting bead titles.

3. Critical Path & Blocker Registry (Dolt :3308/hq)

P0 Active Blockers (Must Clear First)


Blocker Bead Priority Domain Blocker Impact & Scope Owning Agent Blocked Dependents


bc-ggku / P0 DrupalWorks Consolidation push rejected due to sentinel / Blocks bc-6fxp Authority service-account push credentials harbormaster DrupalWorks pack distribution & bc-a7fd

bc-4w9a / P0 Security Live Google API keys & blu_fleet sentinel Blocks all bc-0pqi Exposure tokens in bluefly.io / public package contextcontrol-ai release publishing & history MR merges

du-tjp P0 Security Static API key in tmux argv + 31 sentinel Blocks Exposure sessions with unattended --dangerously-skip-permissions multi-agent autonomy

bc-g2nl P0 Oracle Traefik dead on Oracle deacon / Blocks remote Gateway (claw.copaw.us & tunneled mayor webhook services unreachable) ingress & mobile monitoring

bc-lm6m P0 Oracle gastown-gateway crash-loops 48k deacon Blocks City Saturation times (MODULE_NOT_FOUND), supervisory starving gc controller loop

bc-w56f / P0 Event / GitLab group webhook 500 loop foundry / Blocks bc-uld Webhooks caused by broken bd city import forge event-driven pipeline triggers across 20 repos

bc-8mla P0 CI Quality gitlab_components refinery Blocks Gate pre-merge-validation.yml never verified merge included; 5 guard jobs inert train activation

bc-escm P0 GitLab Exit GitLab subscription A-S00141074 harbormaster Blocks source ⚠️ --- Dec 15 expires 2026-12-15 (84 days). sovereignty, Hard Cutoff Convoy P starts 2026-10-01. ON webhook HOLD until Oct 1 --- see CONVOY reliability, P. and factory autonomy


Blocked Beads (Awaiting Upstream Resolution)


Blocked Bead Priority Reason Blocked Required Action Before Work


bc-fyyl P0 source_connector Fixed in branch; InputDefinition blocked on arity fatal republish (bc-ez0l), do NOT re-code

bc-inx7 P0 source_connector Fixed in branch; ComplianceToolBase blocked on logger fatal republish (bc-ez0l), do NOT re-code

bc-6ilk P1 agentic_canvas Fixed upstream; Twig & node_classes cannot reach defects bluefly.io until registry ships > 0.1.7

bc-uy73 P1 HarborMaster named Needs city-scoped session alignment agent aligned with always-on Gas City session

bc-f6y P1 Durable Agent Blocked on Identity Phase 0 machine identity service account provisioning

bc-3c4 P1 Post-deployment Blocked on agent governance governed deployment verification



4. The 15 Canonical Cross-Mountain Convoys

CONVOY A --- City Foundation

  • Supports: Mountains 1, 2, 3, 6, 16, 17, 37, 38, 40
  • Goal: One Gas City running reliably on Oracle as the sole Factory orchestration runtime (ONE_CITY=YES, SECOND_CITY=NO).
  • Assigned: MAYOR (Dispatch), DEACON (Patrol), WITNESS (Verification)
  • Active Dolt Beads:
    • [ ] bc-g2nl (P0): Recover Traefik gateway and tunnel endpoints on Oracle [DEACON]
    • [ ] bc-lm6m (P0): Remediate gastown-gateway crash loop and CPU starvation [DEACON]
    • [ ] bc-uld (P0): Fix broken bd import on missing remote to restore city start [FOUNDRY]
    • [ ] PHANTOM:hq-zfuf (P0): Recover dispatcher supervisor process (mol-dog-reaper) [MAYOR]
    • [ ] PHANTOM:hq-zhg4 (P0): Relocate shadow ledger beads into canonical :3308/hq [MAYOR]
    • [ ] PHANTOM:bl-38cejv (P0): Wire automated estate hygiene (blu audit estate) into Witness patrol [WITNESS]
    • [ ] PHANTOM:bl-ws9obz (P0): Pin Oracle detached HEAD checkouts with bind-mount protection [DEACON]
    • [ ] bc-d3k (P1): Classify and retire accidental per-rig databases created during recovery [DEACON]
    • [ ] city-backup-restore-proof: Execute cold-start Dolt database restoration proof from NAS snapshot [WITNESS]
  • Acceptance: ONE_CITY=PASS, DOLT_HEALTH=PASS, SESSIONS_DISPOSABLE=PASS, EVENTS_EMITTING=PASS.

CONVOY B --- Identity, Authority, and Policy

  • Supports: Mountains 1, 4, 6, 7, 21, 22, 30, 32, 33
  • Goal: Every action has an explicit machine identity, bounded authority, Cedar policy decision, and customer scope.
  • Assigned: SENTINEL (Security/Cedar), FOUNDRY (OSSA/DUADP), BLU (Contract Plane)
  • Active Dolt Beads:
    • [ ] bc-4w9a (P0): Coordinated BFG/git-filter-repo purge of live Google API key from bluefly.io history [SENTINEL]
    • [ ] bc-0pqi (P0): Rotate and purge blu_fleet.settings api_token from contextcontrol-ai [SENTINEL]
    • [ ] bc-ype1 (P0): Revoke and rotate GitLab PAT confirmed exposed in session transcript [SENTINEL]
    • [ ] du-tjp (P0): Purge static API keys from tmux arguments and enforce Cedar authorization on agent invocations [SENTINEL]
    • [ ] bc-ypy2 (P0): Complete canonical @blu and 8 specialist agent OSSA v0.4.1 manifests in agentictools/agents [FOUNDRY]
    • [ ] bc-fyna (P1): Implement 1Password Credential Broker architecture converging with Drupal authority model [SENTINEL]
    • [ ] bc-t3b (P1): Split cedar_policy scope creep --- remove custom SAML/LDAP/MFA, adopt standard contrib [DRUPAL]
    • [ ] identity-machine-git-config: Standardize machine identity commit author across all agent sessions [HARBORMASTER]
  • Acceptance: PERSONAL_CREDENTIALS_IN_AGENT_PATHS=0, SERVICE_IDENTITIES=PASS, CEDAR_DENIAL_PROVEN=PASS.

CONVOY C --- Source, CI, Merge, and Release Fabric

  • Supports: Mountains 4, 18, 19, 20, 21, 25, 39, 40
  • Goal: Source travels through one predictable automated path from branch to verified release artifact.
  • Assigned: HARBORMASTER (Delivery/MRs), REFINERY (CI Components), WITNESS (Proof)
  • Active Dolt Beads:
    • [ ] bc-8mla (P0): Fix gitlab_components pre-merge-validation.yml inclusion to activate 5 inert guard jobs [REFINERY]
    • [x] bc-ccdv (P1): Correct 5 undeclared-input sites in gitlab_components (MERGED MR !1218) [REFINERY]
    • [ ] PHANTOM:bl-sd98nf (P1): Remove manual approval rules on feature -> release/v0.1.x across 18 delivery repos [MAYOR]
    • [ ] PHANTOM:bl-iybdig (P1): Remediate review comments and clean up 9 closed MRs (!504, !191, etc.) [REFINERY]
    • [ ] PHANTOM:hq-pm1a (P0): Repair merge request pipeline configuration for studio-ui [HARBORMASTER]
    • [ ] ci-merge-trains-selective: Enable GitLab merge trains on high-concurrency repos (BluCity, DrupalWorks, bluefly.io, contextcontrol-ai) [HARBORMASTER]
    • [ ] ci-shared-components-adopt: Convert leaf .gitlab-ci.yml files to consume versioned GitLab components [REFINERY]
  • Acceptance: MERGED_RESULTS=PASS, MERGE_TRAINS_SELECTIVE=PASS, CI_FALSE_GREENS=0.

CONVOY D --- Package and Registry Publication

  • Supports: Mountains 5, 18, 19, 25, 39
  • Goal: Every reusable artifact has one canonical package identity and intentional registry distribution strategy.
  • Assigned: FOUNDRY (Packaging), REFINERY (Publishing), FORGE (Clean Consumer Proof)
  • Active Dolt Beads:
    • [ ] bc-ftdk (P1): Converge Drupal estate release: 42/47 projects never reach main, 20 have no stable package [DRUPAL + REFINERY]
    • [ ] bc-yrw4 (P1): Fix workflow block in 6 Drupal package repos omitting CI_COMMIT_TAG [REFINERY]
    • [ ] bc-ubjf (P1): Fix agentic_canvas release pipeline omitting CI_COMMIT_TAG [REFINERY]
    • [ ] package-duadp-npm: Publish verified DUADP JS client to npmjs registry [REFINERY]
    • [ ] package-ossa-npm: Publish vetted @bluefly/ossa to npmjs registry [REFINERY]
    • [ ] package-clean-consumer-test: Verify clean consumer installation in empty project without local path magic [FORGE]
  • Acceptance: NPM_PUBLISHED=PASS, COMPOSER_REGISTRY=PASS, CLEAN_CONSUMER_PROOF=PASS.

CONVOY E --- Pack Architecture

  • Supports: Mountains 3, 5, 6, 8, 26, 27, 28, 29, 38
  • Goal: Reusable Factory capability lives in versioned Packs and Formulas rather than giant session prompts.
  • Assigned: FOUNDRY (Pack Builder), BLU (Architecture/Portability)
  • Active Dolt Beads:
    • [ ] bc-9vir (P0): DrupalWorks Architecture Directive --- Formula v2 engine, evidence-governed lifecycle [FOUNDRY]
    • [ ] bc-oay5 (P2): Evidence and learning pack --- author remaining 6 formulas, 4 orders, 5 events [FOUNDRY]
    • [ ] mba-0y4 (P1): Gas City audit --- DrupalWorks cartesian explosion (66 phantom agents on non-Drupal rigs), 46 config-ref issues, 66 formula-requirement warnings, gc sling not adopted, scripts→commands layout [WITNESS → FOUNDRY]
    • [ ] pack-public-private-boundary: Lock strict boundary: public DrupalWorks vs. private BluCity-Packs [BLU]
    • [ ] pack-schema-validation: Validate pack manifests against Gas City v2 schema [FOUNDRY]
    • [ ] formula-single-purpose-gate: Enforce single-purpose I/O contracts on all newly materialized formulas [FOUNDRY]
  • Acceptance: PUBLIC_PRIVATE_BOUNDARY=PASS, FORMULA_V2_COMPLIANT=PASS, ZERO_INTERNAL_SECRETS_IN_PACKS=PASS, ZERO_PHANTOM_AGENTS=PASS.

CONVOY F --- Drupal Quality and Upstream Convergence

  • Supports: Mountains 5, 7, 8, 24, 25, 26, 27, 28, 29
  • Goal: Upstream-first Drupal engineering (core → contrib → config → recipe → Canvas → custom code last).
  • Assigned: DRUPAL (DrupalWorks), FORGE (Packaging Proof), WITNESS (QA Verification)
  • Active Dolt Beads:
    • [ ] bc-hadp (P0): Fix undefined logger channel in ai_search_block_log_tag breaking container compilation [DRUPAL]
    • [ ] bc-4zb2 (P0): bluefly.io config recovery --- reconcile entity-display, Canvas, MCP, and Views drift [DRUPAL]
    • [ ] bc-g4rm (P0): contextcontrol-ai config recovery --- reconcile 139-module gap between DB and config/sync [DRUPAL]
    • [ ] bc-6fj7 (P0): Upgrade webonyx/graphql-php to 15.32.2+ to resolve 3 critical security advisories [DRUPAL]
    • [x] bc-w0ue (P1): Fix dragonfly_client PostDragonflyRunToGkg logger type fatal (MERGED MR !23) [DRUPAL]
    • [ ] PHANTOM:bl-s06j5b (P1): Implement 5 reusable verification checks from STD-VERIFY-001 in DrupalWorks [DRUPAL]
    • [ ] PHANTOM:bl-08nift (P1): Refactor api_normalization custom module to core JSON:API [DRUPAL]
    • [ ] PHANTOM:bl-oqev8j (P1): Split bluefly_theme into core Recipes + Canvas SDC starterkit [DRUPAL]
    • [ ] kb-cache-governance: Standardize kb_cache worktree lifecycle; resolve ai_context boundary [DRUPAL]
  • Acceptance: PHPCS_CLEAN=PASS, PHPSTAN_L8=PASS, NET_CUSTOM_LOC_REDUCED=PASS.

BEFORE CREATING A NEW G* BEAD: 1. search existing Beads 2. reuse or rename existing work 3. reconcile stale closed Beads against evidence 4. update RunningTodo from Bead state 5. never create a duplicate because a session lost context

CONVOY G — Governed Human Control Plane (ContextControl)

STATUS: ACTIVE / RECONCILE AGAINST CURRENT BEADS

ContextControl is the governed human/customer control surface.

Gas City = orchestration Beads = durable work ContractPlane / Cedar = authorization OtterMon = checks / evidence / reverification GitLab = source / MR / CI / release ContextControl = review / approval / governed context / operator UX

ContextControl MUST NOT become a scheduler or second work authority.

G1 — contextcontrol-tenancy-model

OWNER=DRUPAL

  • Prove current Group tenancy model.
  • Prefer Group contrib configuration.
  • Verify Organization → Team → Project → Estate only where product semantics require each level.
  • Remove custom tenancy code where upstream/config already owns behavior.

ACCEPTANCE: GROUP_MODEL_PROVEN=YES CROSS_TENANT_ACCESS_DENIED=YES CUSTOM_TENANCY_FRAMEWORK=NO

G2 — contextcontrol-registration-provisioning

EXISTING_BEAD=mba-d61o OWNER=DRUPAL STATUS=RECONCILE

  • Re-evaluate current implementation.
  • Prefer Group + ECA + Recipe/Config Action.
  • Remove procedural custom hook glue if upstream/config/ECA can replace it.
  • Custom plugin allowed only after proven upstream gap.

ACCEPTANCE: ECA_FIRST=YES CUSTOM_HOOK_GLUE=0 CLEAN_IMPORT=PASS REGISTRATION_PROVISIONING=PASS RUNTIME_VERIFIED=YES

G3 — contextcontrol-tenant-access-isolation

OWNER=DRUPAL AUDIT=SENTINEL VERIFY=WITNESS

  • Prove entity access isolation.
  • Prove ai_context isolation.
  • Prove Search API/vector isolation.
  • Prove JSON:API and Tool/MCP access isolation.

ACCEPTANCE: CROSS_TENANT_ENTITY_READ=DENIED CROSS_TENANT_ENTITY_WRITE=DENIED CROSS_TENANT_CONTEXT_RETRIEVAL=DENIED CROSS_TENANT_VECTOR_RETRIEVAL=DENIED

G4 — contextcontrol-ai-asset-group-binding

OWNER=DRUPAL

  • Determine native Group relation support for:
  • ai_context_item
  • OSSA agents
  • API normalization entities
  • governed capability entities
  • Use upstream relation plugins/config first.
  • If upstream gap is real, route the smallest reusable producer fix.

ACCEPTANCE: UPSTREAM_GAP_PROVEN= CUSTOM_RELATION_PLUGIN_REQUIRED= TENANT_BINDING_PROVEN=YES

G5 — contextcontrol-zero-scheduler

OWNER=WITNESS

Verify that ContextControl only: - displays - reviews - approves - authorizes - requests execution - displays receipts

It must not: - own Beads - schedule agents - maintain work queues - implement retries - become another orchestrator

ACCEPTANCE: PARALLEL_SCHEDULER=NO PARALLEL_WORK_DB=NO GAS_CITY_EXECUTION_BOUNDARY=PROVEN

G6 — contextcontrol-api-catalog

OWNER=DRUPAL

Use api_normalization as the Drupal-native API catalog.

Flow:

OpenAPI → api_normalization → Drupal entities → Views / Canvas → Tool API → MCP → ECA

Import only approved estate APIs with explicit owners.

ACCEPTANCE: NORMALIZED_ENTITIES_CREATED=YES SOURCE_IDENTIFIER_PRESERVED=YES SECRETS_IN_ENTITIES=NO HARDCODED_ENV_ENDPOINTS=0

G7 — contextcontrol-api-tool-exposure

OWNER=DRUPAL / FOUNDRY

  • Expose approved normalized API operations through Tool API.
  • Use MCP for external tool transport.
  • Do not build custom REST/MCP bridges unless upstream gap is proven.

ACCEPTANCE: CUSTOM_REST_BRIDGE=0 CUSTOM_MCP_PROTOCOL=0 TOOL_SCHEMA_DEFINED=YES AUTH_REFERENCE_ONLY=YES

G8 — contextcontrol-eca-api-automation

OWNER=DRUPAL

Use ECA for: - normalized API lifecycle - event-driven state updates - approval triggers - integrity findings - human review routing

No polling framework. No custom workflow engine.

ACCEPTANCE: ECA_FIRST=YES CUSTOM_POLLING=0 CUSTOM_WORKFLOW_ENGINE=0

G9 — contextcontrol-knowledge-authority-assurance

OWNER=DRUPAL POLICY=CONTRACTPLANE AUDIT=SENTINEL VERIFY=WITNESS

  • Surface deterministic docs.integrity_finding events.
  • ContextControl presents findings and approvals.
  • ContractPlane evaluates policy.
  • Gas City routes remediation.
  • ContextControl does not become evidence or execution authority.

G10 — contextcontrol-human-approval-surface

OWNER=DRUPAL

Model approvals for: - tools - policy exceptions - knowledge conflicts - API capability approval - sensitive operations - release/deploy requests

Prefer Drupal entities + moderation/workflow + ECA + Views/Canvas.

G11 — contextcontrol-receipt-and-evidence-ui

OWNER=DRUPAL VERIFY=WITNESS

Render authoritative lifecycle state:

REQUESTED AUTHORIZED DISPATCHED RUNNING SOURCE_DELIVERED CI_VERIFIED DEPLOYED RUNTIME_ACCEPTED INDEPENDENTLY_VERIFIED FAILED BLOCKED

ContextControl displays evidence. It does not independently declare execution success.

CONVOY H --- Verified Security & Release Operation

  • Supports: Mountains 8, 25, 26, 34, 35, 36, 40
  • Goal: Complete the first commercially meaningful Factory operation end-to-end (ESTATE=bluefly.io, OPERATION=Security Update).
  • Assigned: DRUPAL (Implementation), SENTINEL (Security Gate), WITNESS (Independent Signing)
  • Active Dolt Beads:
    • [ ] PHANTOM:bl-m2a9un (P0): Cryptographic revocation proof for compromised credentials [SENTINEL]
    • [ ] security-detector-coverage: Standardize upstream security advisory detection via GitLab native component [SENTINEL]
    • [ ] security-first-operation-run1: Execute Run 1 end-to-end (DETECT → UNDERSTAND → AUTHORIZE → ACT → VERIFY → PROVE) [DRUPAL + WITNESS]
    • [ ] security-operational-receipt: Emit signed operational receipt conforming to STD-ECON-001 and STD-GATE-001 [WITNESS]
    • [ ] security-second-run-rehearsal: Execute Run 2 to prove compounding economic cost reduction [FORGE + WITNESS]
  • Acceptance: OPERATION_VERIFIED=PASS, RECEIPT_SIGNED=PASS, NEXT_RUN_CHEAPER=YES.

CONVOY I --- Custom Module Assurance

  • Supports: Mountains 8, 27, 35
  • Goal: Audit, classify, and shrink custom Drupal module footprint across the estate.
  • Assigned: DRUPAL (Module Auditor/Engineer), WITNESS (Verification)
  • Active Dolt Beads:
    • [ ] bc-tw16 (P2): Module surface audit --- audit 250 contrib modules, retire 25 leaf modules with no config [DRUPAL]
    • [ ] custom-module-disposition-register: Classify 60+ custom modules (KEEP, REPLACE, RETIRE, CONSOLIDATE) [DRUPAL]
    • [ ] custom-module-contrib-substitution: Replace custom glue code with top-100 vetted contrib equivalents [DRUPAL]
    • [ ] custom-module-test-coverage: Establish automated unit and kernel test baselines for retained modules [DRUPAL]
  • Acceptance: CUSTOM_LOC_REDUCED>30%, ZERO_UNAUDITED_MODULES=PASS.

CONVOY J --- Upgrade and Migration

  • Supports: Mountains 28, 29
  • Goal: Productize automated Drupal core/contrib major upgrades and migration recipes without custom rework.
  • Assigned: DRUPAL (Migration Specialist), FORGE (Consumer Verification)
  • Active Dolt Beads:
    • [ ] ubuntu-z2g8 (P2): Rename recipe_blucity and migrate all consumer sites [DRUPAL]
    • [ ] upgrade-core-automation: Build automated Composer core/contrib update pipeline with visual regression [DRUPAL]
    • [ ] migration-recipes-catalog: Author reusable Drupal migration recipes for D7/D9/D10 $\to$ D11 [DRUPAL]
    • [ ] migration-clean-environment-proof: Verify migration recipes execute cleanly on fresh target environments [FORGE]
  • Acceptance: MIGRATION_RECIPES_REUSABLE=PASS, REGRESSION_TESTS_PASS=PASS.

CONVOY K --- Factory Observability, Evidence, and Economics

  • Supports: Mountains 2, 34, 35, 36, 37
  • Goal: Make factory execution measurable without turning agents into monitoring daemons.
  • Assigned: WITNESS (Proof Signing), BLU (Economic Metrics), FOUNDRY (Telemetry)
  • Active Dolt Beads:
    • [ ] PHANTOM:bl-ssf49r (P1): Model Cost & Context Optimization Epic (7 children: PHANTOM:bl-k9x12a..PHANTOM:bl-x5y91k) [BLU]
    • [ ] ubuntu-qay (P2): Converge LiteLLM runtime routing and tier pricing catalog [FOUNDRY]
    • [ ] bc-yjyr (P1): Repoint Claudex profiles from workstation to NAS for durable overnight inference [FOUNDRY]
    • [ ] telemetry-event-stream: Normalize Gas City events with OpenTelemetry traces [FOUNDRY]
    • [ ] factory-economic-scorecard: Automated calculation of CUSTOM_LOC_REMOVED, MODEL_COST, HUMAN_TIME_SAVED [BLU]
  • Acceptance: POLLING_DAEMONS=0, STD_ECON_001_ENFORCED=PASS.

CONVOY L --- Infrastructure as Code and Execution Surfaces

  • Supports: Mountains 14, 15, 16, 17, 21, 23, 37
  • Goal: Every execution surface (Oracle, Mac, NAS, Container, DDEV) is reproducible, disposable, and governed via IaC.
  • Assigned: HARBORMASTER (Infra Delivery), DEACON (Daemon Health), SENTINEL (Network Security)
  • Active Dolt Beads:
    • [ ] PHANTOM:hq-kupp (P0): Cloudflare tunnel tokens in compose.lock.yaml remediation [SENTINEL]
    • [ ] PHANTOM:hq-0p9q (P0): Purge 28 secret leaks in code_executor repository history [SENTINEL]
    • [ ] PHANTOM:hq-arol (P0): Purge cloudflared tunnel tokens from git history and lock 0700 permissions [SENTINEL]
    • [ ] PHANTOM:hq-xe2n (P1): Restart stalled GitLab runner on Oracle and align runners.tf limits [DEACON + HARBORMASTER]
    • [ ] infra-oracle-iac-reproducibility: Reconcile Terraform definitions with live Oracle container state [HARBORMASTER]
    • [ ] infra-agent-docker-standard: Standardize agent container images and eliminate workstation host dependencies [FOUNDRY]
  • Acceptance: IAC_PROVEN=PASS, ZERO_MANUAL_PROD_SERVICES=PASS.

CONVOY M --- Moshi / OMO / Upstream Toolchain

  • Supports: Mountains 14, 15, 23
  • Goal: Adopt high-value upstream tools with thin configuration rather than Bluefly forks.
  • Assigned: FOUNDRY (Toolchain Evaluator), SENTINEL (Security Clearance)
  • Active Dolt Beads:
    • [ ] PHANTOM:hq-yo0h.2 (P1): Moshi speech model benchmark and Oracle resource allocation assessment [FOUNDRY]
    • [ ] bc-f1m2 (P0): Bluefly context resolution ladder architecture: CodeGraph, QMD, Orbit, Claudex [FOUNDRY]
    • [ ] bc-ck1y (P1): Orbit Local vs CodeGraph bakeoff and GitLab Orbit SDLC pilot [REFINERY]
    • [ ] upstream-tool-adoption-matrix: Formalize adoption status (ADOPT, CONFIG_ONLY, DEFER, REJECT) [BLU]
  • Acceptance: ZERO_UNGOVERNED_FORKS=PASS.

CONVOY N --- Documentation, Schema, and Authority Convergence

  • Supports: Mountains 1, 9, 10, 11, 12, 13
  • Goal: Define doctrine once in BluCity-Docs, reference everywhere, and enforce schema mechanically in CI.
  • Assigned: REFINERY (Docs/CI Gate), FOUNDRY (Schema Authoring)
  • Active Dolt Beads:
    • [ ] bc-nboe (P2): Curate BluCity-Docs --- one home, one name, one authority (resolve 145 relative links) [REFINERY]
    • [ ] bc-3b3i (P1): QMD Governed Documentation Indexing & Slim AGENTS.md Navigation Standard [SENTINEL + REFINERY]
    • [ ] ci-doc-enforcement: Add CI checks rejecting local paths, duplicate ADRs, and stale markdown queues [REFINERY]
    • [ ] schema-canonical-contracts: Maintain canonical JSON/YAML schemas for OSSA, Beads metadata, Receipts, and ContextCards [FOUNDRY]
  • Acceptance: SCHEMA_ENFORCED_IN_CI=PASS, ZERO_DOC_DUPLICATION=PASS.

CONVOY O --- Durability and Disaster Recovery

  • Supports: Mountains 16, 17, 34, 37
  • Goal: Critical factory state survives total loss of Oracle, workstation, or NAS.
  • Assigned: HARBORMASTER (NAS Mirroring), DEACON (Backup Automation), WITNESS (Recovery Proof)
  • Active Dolt Beads:
    • [ ] PHANTOM:hq-we0d (P0): Add git remote to NAS for gt/portfolio-registry to eliminate data loss hazard [HARBORMASTER]
    • [ ] bc-nsh8 (P0): Sync NAS BluCity-Packs mirror (\~47 commits stale) [HARBORMASTER]
    • [ ] bc-u2yt (P0): Inventory NAS BluCity-Docs mirror (117 commits behind) [HARBORMASTER]
    • [ ] dr-dolt-offhost-proof: Prove full Factory recovery from cold start using NAS persistence alone (PHANTOM:hq-xoty.3) [WITNESS]
    • [ ] dr-backup-sla: Formalize backup schedule and SLA for Dolt :3308, Keycloak, and PostgreSQL [DEACON]

CONVOY P --- GitLab Exit & Forgejo Migration ⚠️ SCHEDULED: STARTS OCTOBER 1, 2026

⚠️ 7-DAY HOLD (Sept 23--Sept 30): Architecture frozen. No implementation until October 1, 2026.

  • Phase 1 --- Foundation & Inventory (Oct 1--14):
    • [ ] bc-or8m (P0): Machine-readable GitLab estate inventory (127 projects, variables, LFS, runners) [HARBORMASTER]
    • [ ] bc-45h4 (P0): Subscription topology verification (A-S00141074, expiry Dec 15, 2026) [SENTINEL]
    • [ ] bc-sr6q (P1): Update executive and operational playbooks with verified inventory data [HARBORMASTER]
  • Phase 2 --- Platform POC (Oct 1--14):
    • [ ] bc-sqxb (P0): Forgejo 15 LTS on reprovisioned VPS; Host Tailscale; PostgreSQL internal; ALLOWED_HOST_LIST [DEACON]
    • [ ] bc-g5jp (P0): Gas City native webhook POC (HMAC-SHA256 via Tailscale Serve; 127.0.0.1:8372) [DEACON]
    • [ ] bc-hcc4 (P1): PILOT PROOF --- ONE Drupal repo through full Forgejo ↔ Gas City factory loop [HARBORMASTER]
  • Phase 3 --- Classification & Delivery Contract (Oct 15--31):
    • [ ] bc-kfsv (P1): Classify all 32 GitLab components → FORGEJO_ACTION | GC_FORMULA | GC_ORDER | GC_PACK | DELETE [REFINERY]
    • [ ] bc-93e7 (P1): Build forge-agnostic delivery contract (delivery/core + delivery/forgejo thin adapter) [REFINERY]
    • [ ] bc-sttw (P1): Agent identity migration --- Phase 1: per-agent bot accounts + scoped 1Password tokens; Phase 2: JWT (v17+) [SENTINEL]
    • [ ] bc-oi9p (P1): Isolated act_runner pool on Oracle/UM790 --- NO runners on Forgejo VPS [DEACON]
  • Phase 4 --- Bulk Migration (Nov 1--25):
    • [ ] bc-7qkj (P1): Bulk import 127 projects with automated Rig admission via webhook → Order → Formula [HARBORMASTER]
    • [ ] bc-fek7 (P1): Backup architecture --- daily Forgejo/PG dumps to NAS + encrypted offsite [DEACON]
  • Phase 5 --- Cutover (Nov 26--30):
    • [ ] bc-c56b (P1): Disaster recovery exercise --- restore from NAS backup on clean compute [WITNESS]
    • [ ] bc-m0j6 (P0): Production Cutover Day --- GitLab freeze, final delta sync, remote URL cutover [HARBORMASTER]
    • [ ] bc-77rg (P0): Final factory acceptance verification (22-point checklist) [WITNESS]
  • Phase 6 --- Decommission (Dec 1--15):
    • [ ] bc-852c (P2): GitLab decommission --- rotate credentials, archive exports, let A-S00141074 expire [SENTINEL]
    • [ ] bc-th5q (P1): Curate playbooks with final Gas City integration architecture [HARBORMASTER]
    • [ ] bc-og39 (P2): Register CAP-FORGEJO-001, retire CAP-GITLAB-001 in capability registry [WITNESS]
    • [ ] bc-0n49 (P2): Port skills (gitlab-workflow → forgejo-workflow; pin Actions to SHAs) [REFINERY]
  • Acceptance: NO_GITLAB_REMOTES=PASS, FORGEJO_FACTORY_LOOP_PROVEN=PASS, DRUPAL_MASTER_DELETED=PASS, DR_EXERCISE_PASS=PASS, SUBSCRIPTION_COST_ZERO=PASS, READY_BEADS_UNBLOCKED=PASS.

5. Reconciled 40 Strategic Mountains Scope

Baselined Foundational Mountains (1--16)

Per STD-FACT-002, Mountains 1--16 establish the architectural baseline and are operationalized through the Convoys: - Mountain 1 (BLU Identity & Governance): Baselined $\to$ Operational in Convoy B (OSSA @blu, MR !276). - Mountain 2 (Gas City Execution Discipline): Baselined $\to$ Operational in Convoy A & K (No polling, disposable sessions). - Mountain 3 (Formula / Order / Event Standards): Baselined $\to$ Operational in Convoy E (Formula v2 compiler, Orders). - Mountain 4 (Forge Factory Convergence): Transitioning → Convoy C (MR pipelines, shared components) + Convoy P ⚠️ (GitLab exit → Forgejo + Gas City; cutover by Nov 30, 2026). - Mountain 5 (DrupalWorks Public Pack): Baselined $\to$ Operational in Convoy E & F (Public portable Drupal pack). - Mountain 6 (BluCity-Packs Private Overlay): Baselined $\to$ Operational in Convoy E (Private operational bindings). - Mountain 7 (ContextControl Console Architecture): Baselined $\to$ Operational in Convoy G (STD-ARCH-003). - Mountain 8 (Drupal Maintenance Factory): Baselined $\to$ Umbrella for Convoys E, F, H, I, J. - Mountain 9 (Project .agents/ Standard): Baselined $\to$ Operational in Convoy N (Committed manifests, clean gitignores). - Mountain 10 (Project Documentation Standard): Baselined $\to$ Operational in Convoy N (Predictable repo docs). - Mountain 11 (BluCity-Docs Governance): Baselined $\to$ Operational in Convoy N (DOCUMENTATION_DRIFT=YES). - Mountain 12 (Product Documentation): Baselined $\to$ Operational in Convoy N (Separate product from session state). - Mountain 13 (Schema Enforcement): Baselined $\to$ Operational in Convoy N (CI-enforced schema contracts). - Mountain 14 (Local Workstation Environment): Baselined $\to$ Operational in Convoy L (Disposable dev environments). - Mountain 15 (Model & Inference Architecture): Baselined $\to$ Operational in Convoy K & L (LiteLLM, Claudex NAS). - Mountain 16 (Oracle / Production Convergence): Baselined $\to$ Operational in Convoy A & L (IaC-driven Oracle).

Strategic Delivery Mountains (17--40)

  • Mountain 17 (NAS / Durability): Active in Convoy A, O [Beads: PHANTOM:bl-ws9obz, PHANTOM:hq-we0d, bc-nsh8, bc-u2yt]
  • Mountain 18 (Public Package & Release): Active in Convoy C, D [Beads: PHANTOM:bl-sd98nf, PHANTOM:bl-hii14j, PHANTOM:hq-pm1a]
  • Mountain 19 (Multi-Registry Release Standard): Active in Convoy C, D [Beads: package-duadp-npm, ci-npm-release]
  • Mountain 20 (Merge Trains & Delivery Flow): Active in Convoy C [Beads: PHANTOM:bl-iybdig, PHANTOM:hq-y6t3]
  • Mountain 21 (GitLab Agent Delivery): Active in Convoy B, C, L [Beads: PHANTOM:bl-l6fhpj, PHANTOM:hq-xe2n]
  • Mountain 22 (GitLab Duo / MCP / Tool Governance): Active in Convoy B, M [Beads: du-tjp, tool-gate-cedar]
  • Mountain 23 (Moshi + OMO Evaluation): Active in Convoy M [Bead: PHANTOM:hq-yo0h.2]
  • Mountain 24 (KB_Cache Recovery): Active in Convoy F [Beads: kb-cache-governance, bc-3b3i]
  • Mountain 25 (Drupal Package Quality Gate): Active in Convoy C, F [Bead: PHANTOM:bl-s06j5b]
  • Mountain 26 (Security & Release Factory): Active in Convoy B, H [Beads: PHANTOM:bl-m2a9un, PHANTOM:hq-kupp, PHANTOM:hq-0p9q, PHANTOM:hq-arol]
  • Mountain 27 (Custom Module Assurance): Active in Convoy F, I [Beads: PHANTOM:bl-08nift, bc-tw16]
  • Mountain 28 (Drupal Upgrade Factory): Active in Convoy F, J [Bead: ubuntu-z2g8]
  • Mountain 29 (Migration Factory Pack): Active in Convoy F, J [Bead: migration-recipes-catalog]
  • Mountain 30 (ContextControl Customer UI): Active in Convoy G [Beads: bc-nfnp, bc-jbsa]
  • Mountain 31 (AGUI Product Experience): Active in Convoy G [Bead: bc-13pv]
  • Mountain 32 (Customer Data Sovereignty): Active in Convoy B, G [Bead: contextcontrol-tenant-isolation]
  • Mountain 33 (Context Model): Active in Convoy B, G [Bead: contextcontrol-context-cards]
  • Mountain 34 (Operational Receipt): Active in Convoy H, K [Bead: security-operational-receipt]
  • Mountain 35 (Capability Flywheel): Active in Convoy E, K [Bead: formula-promotion]
  • Mountain 36 (Factory Product Economics): Active in Convoy K [Beads: PHANTOM:bl-ssf49r, ubuntu-qay]
  • Mountain 37 (Factory Observability): Active in Convoy A, K [Bead: PHANTOM:bl-38cejv]
  • Mountain 38 (Factory Pack Architecture): Active in Convoy E [Beads: bc-ypy2, PHANTOM:bl-xzpb5f, mba-0y4]
  • Mountain 39 (Released Product Inventory): Active in Convoy C, D [Bead: bc-ftdk]
  • Mountain 40 (Factory Completion Program): Active in Convoy A, H, N [Bead: bc-t1ox]

6. Factory Completion Receipt Contract

Every completed operation, MR, or closed Bead must append this verified economic receipt:

REQUESTED_EFFECT=
VERIFIED=

SOURCE_DELIVERED=
RUNTIME_VERIFIED=
EVIDENCE=

CAPABILITY_CHANGE=
  NONE | CANDIDATE | UPDATED | PROVEN | REMOVED | TRANSFERRED_TO_UPSTREAM

REUSE_EFFECT=
  REUSED_EXISTING_UPSTREAM | REMOVED_CUSTOM_OWNERSHIP | CONSOLIDATED_DUPLICATION |
  CREATED_REUSABLE_CAPABILITY | IMPROVED_DISCOVERABILITY | REDUCED_RE_DERIVATION |
  REDUCED_MODEL_USAGE | REDUCED_HUMAN_INTERVENTION | REDUCED_FAILURE_RISK |
  REDUCED_EXECUTION_TIME | IMPROVED_VERIFICATION | IMPROVED_RECOVERY | NONE

IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES|NO
WHY=

WHAT_WILL_THE_NEXT_AGENT_REUSE=
WHAT_WOULD_STILL_HAVE_TO_BE_RE_DERIVED=

Migration Factory --- Product Strategy & Execution

Full strategy document: strategy/migration-factory-strategy.md (53 sections) Bead: mba-72p --- Migration Factory Strategy --- Team Discussion & Decisions

Core Thesis

Bluefly can turn repeated digital-estate migration work into an accumulating library of proven capability, allowing increasingly complex portfolios to be migrated with less rediscovery, less human effort, better verification, and lower cost per accepted outcome.

Strategic Framing

MIGRATION FACTORY = LAND / TRANSFORMATION OFFER (not standalone product)
DIGITAL ESTATE OPERATIONS = RECURRING PRODUCT
CONTEXTCONTROL = CUSTOMER CONTROL SURFACE
BLUEFLY FACTORY = EXECUTION + MARGIN ENGINE

Migration as Land Motion → Recurring Operations

MIGRATION → KNOWN ESTATE → SECURITY OPS → A11Y → UPGRADES → CUSTOM-CODE REDUCTION → DIGITAL ESTATE OPS

Key Decisions Needed (§51)

  • [ ] Is Migration Factory a land offer or independent product?
  • [ ] Which source problem first? (Drupal legacy / WP sprawl / portfolio consolidation / long-tail rescue)
  • [ ] Which market first? (higher-ed / state gov / enterprise)
  • [ ] Minimum estate size for Factory economics?
  • [ ] Which named accounts to research immediately?
  • [ ] Which existing client becomes the first proof?

DrupalWorks Pack Discovery (2026-09-23)

DRUPALWORKS_PACK=EXISTS (30+ production formulas, 13 orders)
FORMULAS=PRODUCTION_GRADE (real bash: composer audit, drush pm:list, jq, drupal.evidence.v1 JSON)
CRON_ORDERS=4 (config-verify, contrib-audit, estate-inventory, release-verify — Monday schedule)
MANUAL_ORDERS=9 (on-demand audits)
FIRST_DRUPAL_EXECUTION=mba-66s (mol-drupal-contrib-audit cooked on bluefly-io, dispatched to organization.worker)
CARTESIAN_EXPLOSION=91+ phantom order entries (13 orders × 7+ rigs, only 2 are Drupal) — bead mba-0y4
AGENT_BINDING_GAP=drupal-auditor not bound at rig level (gc sling bluefly-io/drupal-auditor fails)

Near-Term Actions

  • [ ] Fix DrupalWorks cartesian explosion (mba-0y4 → refinery)
  • [ ] Add drupal-auditor agent binding for bluefly-io and amcs-demo rigs
  • [ ] Verify mol-drupal-contrib-audit completes on bluefly-io (mba-66s)
  • [ ] Build target-account research list (50 organizations)
  • [ ] Define Migration Readiness Assessment offer (scope, inputs, outputs, timeline, price)
  • [ ] Choose repeatability experiment (2+ related real sites)

Factory Concepts --- Product Architecture Doctrine (Draft)

Full document: strategy/factory-concepts.md (50 sections) Bead: mba-2nk --- Factory Concepts (audit + curation needed) Status: DRAFT_DOCTRINE --- needs verification against current Gas City/Beads, audit for overlap with STD-AUTH-001/STD-ECON-001/STD-FACT-002

Core Thesis

Bluefly Factory is a governed production system for turning complex recurring work into increasingly reusable operational capability.

Key Concepts Requiring Audit and Curation

  • [ ] §1 Factory as OS for reusable work --- verify against STD-FACT-002 Mountains
  • [ ] §2 One Factory many Packs --- verify against current BluCity-Packs architecture
  • [ ] §3 Correct primitive model (AGENT/BEAD/FORMULA/RIG/PACK/EVENT) --- verify against Gas City docs
  • [ ] §4 Verified Operations Loop (DETECT→UNDERSTAND→MATCH→AUTHORIZE→ACT→VERIFY→PROVE→IMPROVE)
  • [ ] §5 Pattern-to-Capability conversion lifecycle
  • [ ] §7 Exception-driven human work --- verify against existing witness/human-gate patterns
  • [ ] §8 Decision Memory --- verify against existing bead evidence model
  • [ ] §9 ContextControl as human control room --- verify against contextcontrol-factory-control-plane.md
  • [ ] §10 Live context vs giant prompts --- verify against STD-CONTEXT-001
  • [ ] §14 Human roles (Context Curator, Agent Ops Manager, Agentic Flow Engineer)
  • [ ] §15 Service as Software model
  • [ ] §16-17 Evidence as first-class output / Evidence before claims
  • [ ] §19 Net negative ownership as measurable operation
  • [ ] §22-23 Policy Plane + Obligation model --- verify against Cedar/ContractPlane
  • [ ] §26 Model routing as economics
  • [ ] §40 Factory Moat (accumulated proven capabilities)
  • [ ] §41 Open core model --- public DrupalWorks vs private operating capability
  • [ ] §44 Factory maturity levels 0-5
  • [ ] §47 Candidate Pack families
  • [ ] §49 Universal Factory Gate

DrupalWorks AI Automators Integration (COMPLETED)

BEAD=mba-q48 (closed)
COMMIT=fdcc07e on release/v0.1.x
REMOTE=gitlab-bluefly:blueflyio/agent-platform/drupal/drupalworks.git
NEW_SKILL=drupal-ai-automators (SKILL.md + references/upstream-docs.md)
FORMULA_UPDATED=mol-drupal-ai-baseline.toml (now detects ai_automators, token, ai_automator_extractor)
PACK_TOML_UPDATED=added drupal/token + drupal/ai_automator_extractor to required_packages
MINDMAP_UPDATED=drupal-ai-module-mindmap.md (AI Automators branch added)
UPSTREAM_FIRST_UPDATED=upstream-first.md (5-step escalation ladder)
VALIDATION=34/34 TOML valid, pack.toml valid, skill files exist, git push clean
IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=YES
WHY=Every future agent discovers AI Automators as upstream capability through skill/formula/mindmap. Eliminates rediscovery, prevents custom code where upstream handles the field type.

ORACLE GATE ZERO --- P0 INCIDENT (Active)

Full directive: operations/oracle-gate-zero.md (22 sections) Bead: mba-9l1 --- Oracle Gate Zero (P0, open) Mountain: 2 (Factory Economy) + 16 (Oracle Runtime)

FACTORY_RUNTIME_AUTHORITY=ORACLE
WORKSTATION_GAS_CITY_AUTHORITY=NO
WORKSTATION_BEADS_AUTHORITY=NO

Execution Order (15 steps)

  • [ ] 1. Capture current load / memory / process baseline
  • [ ] 2. Inventory native Gas City sessions + claims
  • [ ] 3. Classify the 32 Claude processes
  • [ ] 4. Identify PID 4880 container / source owner
  • [ ] 5. Inventory bd/gc client versions across shared Dolt clients
  • [ ] 6. Identify canonical binary installation owner
  • [ ] 7. Search existing Oracle beads for each root defect
  • [ ] 8. Update / dedup / route existing work
  • [ ] 9. Build coordinated version-convergence plan
  • [ ] 10. Apply only through source/IaC/release path
  • [ ] 11. Restore native Beads
  • [ ] 12. Verify worker ceiling
  • [ ] 13. Verify load / memory / fork-rate recovery
  • [ ] 14. Witness verify
  • [ ] 15. Resume normal Factory execution

Factory Capability: Documentation Integrity (Candidate)

Full design: capabilities/documentation-integrity-audit.md (24 sections) Bead: mba-e5j --- Documentation Integrity capability (P1, open) Central rule: Detect cheaply. Record once. Route to real owner. Spend model only on ambiguity.

CI = prevention
Gas City periodic audit = reconciliation
Agent = semantic resolution (only when needed)

What to Build (8 items)

  • [ ] 1. Deterministic documentation-integrity check
  • [ ] 2. Machine-readable result
  • [ ] 3. GitLab CI component
  • [ ] 4. Formula wrapping same check for estate reconciliation
  • [ ] 5. Event only on material finding
  • [ ] 6. Bead deduplication by finding signature
  • [ ] 7. Routing by documented authority
  • [ ] 8. Witness verification