CI/CD Variables Catalogue¶
Authoritative inventory of GitLab CI/CD variables used across the Bluefly platform.
All variables defined at group level (blueflyio) and inherited by projects.
Last Audited: 2026-08-11 (21 projects with project-level overrides identified); spot-corrections 2026-08-24 (SERVICE_ACCOUNT_VERSION_MANAGER_TOKEN, ORACLE_SSH_KEY — see rows below), not a full re-audit
Evidence: ledger/gitlab-cicd-variables-audit-evidence-2026-08-11.md
Group-Level Variables (Canonical)¶
All projects inherit these variables automatically. No secret values are printed; [SET]/[UNSET] records whether the variable has a value at GitLab group level — never a value fingerprint. OBSERVED 2026-08-11: all rows below are native GitLab group-level CI/CD variables (GET /groups/blueflyio/variables), not 1Password op:// references — "Set At" records where the variable lives today, not a claim that GitLab is the secret source of truth. Canonical secrets authority is 1Password (standards/core/STD-SEC-001-authentication-and-secrets.md); migrating these to reference-based delivery is tracked separately, not yet done.
Delivery-class legend (by name/purpose pattern only — no value inspected): NON_SECRET_CONFIG (identity strings, flags, IDs — not a credential), NATIVE_CI_IDENTITY (GitLab-native token, e.g. CI_JOB_TOKEN-class), LEGACY_SECRET_COPY (a credential value stored directly as a GitLab variable rather than a 1Password reference — current state for every SET credential row below, per the 2026-08-11 observation), UNKNOWN (purpose insufficiently documented to classify).
| Variable Name | Value Indicator | Purpose | Class | Scope | Owner | Set At |
|---|---|---|---|---|---|---|
| BLUEFLY_DEVOPS_USER | [SET] | Platform operator identity | NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
| DISCORD_WEBHOOK_URL | [SET] | Deployment notifications | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| GH_TOKEN | [SET] | GitHub API access for sync/automation | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| GITLAB_OBSERVABILITY_EXPORT | [SET] | Observability export configuration | UNKNOWN | CI/CD | Platform Team | GitLab |
| GITLAB_TOKEN | [SET] | GitLab API access (core automation) | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| KUBECONFIG_DEV | [SET] | Kubernetes dev cluster access | LEGACY_SECRET_COPY | CI/CD | Infrastructure Team | GitLab |
| KUBECONFIG_PROD | [SET] | Kubernetes prod cluster access | LEGACY_SECRET_COPY | CI/CD | Infrastructure Team | GitLab |
| NEO4J_ENABLED | [SET] | Graph database feature flag | NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
| NEO4J_PASSWORD | [SET] | Graph database authentication | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| NEO4J_URI | [SET] | Graph database connection string | NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
| NEO4J_USER | [SET] | Graph database user identity | NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
| OPENAI_API_KEY | [SET] | OpenAI API authentication | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| OSSA_NPMJS | [UNSET] | OSSA npm registry token (unused) | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| SERVICE_ACCOUNT_DEPLOYMENT_TOKEN | [SET] | Deployment service account token | LEGACY_SECRET_COPY | CI/CD | Infrastructure Team | GitLab |
| SERVICE_ACCOUNT_MONITORING_TOKEN | [SET] | Monitoring service account token | LEGACY_SECRET_COPY | CI/CD | Infrastructure Team | GitLab |
| SERVICE_ACCOUNT_SECURITY_TOKEN | [SET] | Security service account token | LEGACY_SECRET_COPY | CI/CD | Security Team | GitLab |
| SERVICE_ACCOUNT_VERSION_MANAGER_TOKEN | [SET] | Release/version management service account | LEGACY_SECRET_COPY | CI/CD | Release Team | GitLab (protected=true, masked=true, environment_scope=*, confirmed 2026-08-24) |
| SLACK_CHANNEL_ID | [SET] | Slack channel for notifications | NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
| SLACK_WEBHOOK_URL | [SET] | Slack webhook for integration | LEGACY_SECRET_COPY | CI/CD | Platform Team | GitLab |
| SSH_KEY | [SET] | SSH private key for Oracle/infrastructure access | LEGACY_SECRET_COPY | CI/CD | Infrastructure Team | GitLab |
| BUILD_RUNNER_TAG | [SET] | Portable build/test runner tag (saas-linux-small-amd64 normal; bluefly-overflow overflow). Sole portable compute switch for base-runner. |
NON_SECRET_CONFIG | CI/CD | Platform Team | GitLab |
Note: BUILD_RUNNER_TAG law: ci-portable-runner-and-topology.md. Consumers must not hard-code runner tags for portable jobs.
Note: LEGACY_SECRET_COPY here means "credential-shaped value stored as a plain GitLab variable" (per the 2026-08-11 observation that none of these are 1Password op:// references) — it does not imply the value itself is stale or wrong, only that its delivery mechanism hasn't migrated. NATIVE_CI_IDENTITY (GitLab-internal predefined variables) does not apply to any row here — all rows are custom group variables, not GitLab's own CI_* predefined set.
Project-Level Variables (Requires Migration)¶
The following variables are currently scattered across individual projects and should be migrated to group level (or have migration decisions documented).
High Priority: Consolidate to Group Level¶
| Variable Name | Current Projects | Value Indicator | Purpose | Class | Action |
|---|---|---|---|---|---|
| COMPOSER_REGISTRY_TOKEN | cedar_policy, ai_agents_tunnel, mcp_gateway | [UNSET] | Drupal module package registry auth (drupal-master template) | LEGACY_SECRET_COPY | Migrate to group; resolve auth issue |
| NPM_TOKEN / GITLAB_NPM_PUBLISH_TOKEN | duadp, agentmarketplace, blu-book, blu-cli | [SET] | NPM registry authentication | LEGACY_SECRET_COPY | Consolidate as NPM_REGISTRY_TOKEN at group |
| ORACLE_SSH_KEY | dragonfly, agentmarketplace, a2a-collector | [SET] | Oracle infrastructure SSH access | LEGACY_SECRET_COPY | CORRECTED 2026-08-24: already exists at blueflyio/blu group level (GET groups/blueflyio%2Fblu/variables, alongside ORACLE_DEPLOY_HOST_PRIVATE) — the "create ORACLE_SSH_KEY" action item was stale. Remaining action: confirm the three listed projects inherit it via group membership rather than carrying their own project-level copy. |
| GITLAB_TOKEN (project overrides) | agentdev, ossa, others | [SET] | Project-specific GitLab API access | LEGACY_SECRET_COPY | Audit why project overrides are needed; consolidate if possible |
Medium Priority: Evaluate for Group Level¶
No value indicator collected for this tier in the 2026-08-11 audit — class reflects purpose only, not a confirmed SET/UNSET/reference state.
| Variable Name | Current Project | Purpose | Class | Decision Pending |
|---|---|---|---|---|
| CLOUDFLARE_ACCOUNT_ID | iac | Infrastructure automation | NON_SECRET_CONFIG | Is IaC deployed from multiple projects or isolated? |
| CLOUDFLARE_API_TOKEN | iac | Infrastructure automation | LEGACY_SECRET_COPY | Is IaC deployed from multiple projects or isolated? |
| CLOUDFLARE_ZONE_ID | iac | Infrastructure automation | NON_SECRET_CONFIG | Is IaC deployed from multiple projects or isolated? |
| OCI_TENANCY_OCID / OCI_COMPARTMENT_ID | iac | Oracle Cloud infrastructure IaC | NON_SECRET_CONFIG | Is IaC deployed from multiple projects or isolated? |
| ORACLE_DEPLOY_HOST / ORACLE_USER | contractplane.ai-website, others | Oracle deployment target | NON_SECRET_CONFIG | Do all deploys target same Oracle host or are there exceptions? |
Low Priority: Keep at Project Level (With Documentation)¶
| Variable Name | Project | Purpose | Class | Justification |
|---|---|---|---|---|
| LITELLM_ / VLLM_ | agentdev | Model-specific runtime configuration | PROJECT_EXCEPTION | Model-specific; not shared across projects |
| AUTHOR_TOKEN / CONTENT_ORCHESTRATOR_TOKEN / ... | agents | Agent persona service account tokens | PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) | Service-specific roles; evaluate if shared or isolated |
| SAST_DISABLED / SECRET_DETECTION_DISABLED | blu-worker | CI security job overrides | NON_SECRET_CONFIG | Document exception; verify if intentional or outdated |
| BLU_API_KEY / GITLAB_BLU_TOKEN | agentblu.ai | Agent-specific API authentication | PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) | Service-specific; keep local with justification |
| WEBSITE_TRIGGER_TOKEN / WEB_TOKEN | ossa | OSSA-specific CI/CD triggers | PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) | Project-specific; keep local with justification |
Variable Naming Standards¶
Recommended conventions for new variables:
| Pattern | Usage | Example |
|---|---|---|
{SERVICE}_TOKEN |
Authentication/API access | GITLAB_TOKEN, OPENAI_API_KEY |
{SERVICE}_REGISTRY_TOKEN |
Package registry auth | COMPOSER_REGISTRY_TOKEN, NPM_REGISTRY_TOKEN |
{SERVICE}_{RESOURCE} |
Infrastructure access | ORACLE_SSH_KEY, CLOUDFLARE_API_TOKEN |
SERVICE_ACCOUNT_{ROLE}_TOKEN |
Service account by role | SERVICE_ACCOUNT_DEPLOYMENT_TOKEN |
{FEATURE}_ENABLED / DISABLED |
Feature flags | NEO4J_ENABLED, SAST_DISABLED |
Security & Access Control¶
Secrets policy (storage, rotation, delivery, access) is governed by
standards/core/STD-SEC-001-authentication-and-secrets.md — not restated here.
This catalog only records inventory facts:
- No Secrets in Logs
- GitLab masks variable values in job logs
- Audit evidence contains no actual values
-
This catalog records presence class only (
[SET]/[UNSET]), never value fingerprints -
Group-Level Inheritance
- Group variables cascade to all projects
- Project overrides permitted only with documented justification
-
Audited quarterly
-
Access Control
- Group variables: managed by Platform Team
- Project overrides: owned by project maintainers
- Changes require MR review and CI validation
Audit & Maintenance¶
| Schedule | Task | Owner |
|---|---|---|
| Quarterly | Review variable usage across active projects | Platform Team |
| On Deploy | Verify CI variables are accessible and correct | Release Team |
| On New Project | Audit for unnecessary project-level overrides | Project Lead |
| On Rotation | Rotate in 1Password (BlueflyAgents vault) per standards/core/STD-SEC-001-authentication-and-secrets.md. OBSERVED 2026-08-11: these are native GitLab group-level CI/CD variables, not 1Password op:// references — rotation currently also requires a manual GitLab-side value update until migrated to reference-based delivery. |
Security Team |
Last Audit: 2026-08-11 (21 projects with project-level variables identified) Next Audit: 2026-11-11 (quarterly)
References¶
- Audit Evidence:
ledger/gitlab-cicd-variables-audit-evidence-2026-08-11.md - Migration Plan:
governance/gitlab-cicd-variables-audit-plan.md - 1Password Integration:
standards/core/STD-SEC-001-authentication-and-secrets.md - GitLab Docs: https://docs.gitlab.com/ee/ci/variables/
Catalogue Status: Evergreen Authority: Canonical (Bluefly Engineering) Last Updated: 2026-08-11 Next Review: 2026-11-11