Authority Catalog¶
Authority: Portfolio-Registry.yaml (Engineering-Standard/authority/) Scope: Composed execution environments and who decides within each domain (authority, not ownership). Distinct from platform-ownership-matrix.md, which records what Bluefly owns vs. what upstream owns. Status: Authoritative Last verified: 2026-08-29
Purpose¶
The canonical inventory of authorities (who decides) across the Bluefly portfolio. See authority-contract.md.
Catalog¶
| Authority | Domain | Kind | Scope | Standard | Status |
|---|---|---|---|---|---|
| 1Password | Secrets | OPERATIONAL | Secret lifecycle (storage, rotation, injection at runtime) | Agreement 12 | Operating |
| GitLab | Source Control | SOURCE | Git history, MR workflow, protected-branch merge | ADR-0005 | Operating |
| Terraform | Infrastructure | SOURCE | Desired infrastructure state (VMs, disks, networking, metadata) | ADR-0005 | Operating |
| OCI (Oracle Cloud Infrastructure) | Runtime Compute | OPERATIONAL | Running infrastructure realized from Terraform-declared state | ADR-0005 | Operating |
| Docker Compose / Kubernetes | Containers | OPERATIONAL | Service lifecycle (start/stop/health) for containerized workloads | Deployment Standard | Operating |
| Prometheus | Metrics | OPERATIONAL | Metrics collection | Observability Standard | Operating |
| Alertmanager | Alerts | OPERATIONAL | Alert routing | Operations Standard | Operating |
| Gas Town (gt tap guard) | Agent tool-execution guarding | OPERATIONAL | PreToolUse guard mechanism (exit 2 blocking) for agent Bash/tool calls; built-ins: pr-workflow, bd-init, mol-patrol, dangerous-command; external guards via settings.json | gt tap --help (verified live, 2026-07-13) | Operating |
| Gas City (gc) | Agent orchestration | SOURCE | Packs, formulas, orders, city orchestration, session providers | ADR-0022 | Operating |
| Beads (bd) / Dolt | Work ledger | SOURCE | Durable work state, bead graph, dependency routing | constitution.md; tools-standard.md | Operating |
| Cedar | Policy evaluation | SOURCE | Authorization policies (permit/forbid/obligations) | constitution.md | Operating |
| OpenClaw | Operator gateway | OPERATIONAL | Human-facing agent gateway, channels, mayor surface | ADR-0022 | Operating |
| Drupal | Content and editorial | SOURCE | Content model, workflows, CMS business authority plane | drupal-standard.md | Operating |
Relationships¶
An Authority is not a Product and not a repository. See platform-ownership-matrix.md for the Bluefly-vs-upstream ownership boundary over each of these authorities.