Skip to content

CI/CD Variables Catalogue

Authoritative inventory of GitLab CI/CD variables used across the Bluefly platform. All variables defined at group level (blueflyio) and inherited by projects.

Last Audited: 2026-08-11 (21 projects with project-level overrides identified); spot-corrections 2026-08-24 (SERVICE_ACCOUNT_VERSION_MANAGER_TOKEN, ORACLE_SSH_KEY — see rows below), not a full re-audit Evidence: ledger/gitlab-cicd-variables-audit-evidence-2026-08-11.md


Group-Level Variables (Canonical)

All projects inherit these variables automatically. No secret values are printed; [SET]/[UNSET] records whether the variable has a value at GitLab group level — never a value fingerprint. OBSERVED 2026-08-11: all rows below are native GitLab group-level CI/CD variables (GET /groups/blueflyio/variables), not 1Password op:// references — "Set At" records where the variable lives today, not a claim that GitLab is the secret source of truth. Canonical secrets authority is 1Password (standards/core/STD-SEC-001-authentication-and-secrets.md); migrating these to reference-based delivery is tracked separately, not yet done.

Delivery-class legend (by name/purpose pattern only — no value inspected): NON_SECRET_CONFIG (identity strings, flags, IDs — not a credential), NATIVE_CI_IDENTITY (GitLab-native token, e.g. CI_JOB_TOKEN-class), LEGACY_SECRET_COPY (a credential value stored directly as a GitLab variable rather than a 1Password reference — current state for every SET credential row below, per the 2026-08-11 observation), UNKNOWN (purpose insufficiently documented to classify).

Variable Name Value Indicator Purpose Class Scope Owner Set At
BLUEFLY_DEVOPS_USER [SET] Platform operator identity NON_SECRET_CONFIG CI/CD Platform Team GitLab
DISCORD_WEBHOOK_URL [SET] Deployment notifications LEGACY_SECRET_COPY CI/CD Platform Team GitLab
GH_TOKEN [SET] GitHub API access for sync/automation LEGACY_SECRET_COPY CI/CD Platform Team GitLab
GITLAB_OBSERVABILITY_EXPORT [SET] Observability export configuration UNKNOWN CI/CD Platform Team GitLab
GITLAB_TOKEN [SET] GitLab API access (core automation) LEGACY_SECRET_COPY CI/CD Platform Team GitLab
KUBECONFIG_DEV [SET] Kubernetes dev cluster access LEGACY_SECRET_COPY CI/CD Infrastructure Team GitLab
KUBECONFIG_PROD [SET] Kubernetes prod cluster access LEGACY_SECRET_COPY CI/CD Infrastructure Team GitLab
NEO4J_ENABLED [SET] Graph database feature flag NON_SECRET_CONFIG CI/CD Platform Team GitLab
NEO4J_PASSWORD [SET] Graph database authentication LEGACY_SECRET_COPY CI/CD Platform Team GitLab
NEO4J_URI [SET] Graph database connection string NON_SECRET_CONFIG CI/CD Platform Team GitLab
NEO4J_USER [SET] Graph database user identity NON_SECRET_CONFIG CI/CD Platform Team GitLab
OPENAI_API_KEY [SET] OpenAI API authentication LEGACY_SECRET_COPY CI/CD Platform Team GitLab
OSSA_NPMJS [UNSET] OSSA npm registry token (unused) LEGACY_SECRET_COPY CI/CD Platform Team GitLab
SERVICE_ACCOUNT_DEPLOYMENT_TOKEN [SET] Deployment service account token LEGACY_SECRET_COPY CI/CD Infrastructure Team GitLab
SERVICE_ACCOUNT_MONITORING_TOKEN [SET] Monitoring service account token LEGACY_SECRET_COPY CI/CD Infrastructure Team GitLab
SERVICE_ACCOUNT_SECURITY_TOKEN [SET] Security service account token LEGACY_SECRET_COPY CI/CD Security Team GitLab
SERVICE_ACCOUNT_VERSION_MANAGER_TOKEN [SET] Release/version management service account LEGACY_SECRET_COPY CI/CD Release Team GitLab (protected=true, masked=true, environment_scope=*, confirmed 2026-08-24)
SLACK_CHANNEL_ID [SET] Slack channel for notifications NON_SECRET_CONFIG CI/CD Platform Team GitLab
SLACK_WEBHOOK_URL [SET] Slack webhook for integration LEGACY_SECRET_COPY CI/CD Platform Team GitLab
SSH_KEY [SET] SSH private key for Oracle/infrastructure access LEGACY_SECRET_COPY CI/CD Infrastructure Team GitLab
BUILD_RUNNER_TAG [SET] Portable build/test runner tag (saas-linux-small-amd64 normal; bluefly-overflow overflow). Sole portable compute switch for base-runner. NON_SECRET_CONFIG CI/CD Platform Team GitLab

Note: BUILD_RUNNER_TAG law: ci-portable-runner-and-topology.md. Consumers must not hard-code runner tags for portable jobs.

Note: LEGACY_SECRET_COPY here means "credential-shaped value stored as a plain GitLab variable" (per the 2026-08-11 observation that none of these are 1Password op:// references) — it does not imply the value itself is stale or wrong, only that its delivery mechanism hasn't migrated. NATIVE_CI_IDENTITY (GitLab-internal predefined variables) does not apply to any row here — all rows are custom group variables, not GitLab's own CI_* predefined set.


Project-Level Variables (Requires Migration)

The following variables are currently scattered across individual projects and should be migrated to group level (or have migration decisions documented).

High Priority: Consolidate to Group Level

Variable Name Current Projects Value Indicator Purpose Class Action
COMPOSER_REGISTRY_TOKEN cedar_policy, ai_agents_tunnel, mcp_gateway [UNSET] Drupal module package registry auth (drupal-master template) LEGACY_SECRET_COPY Migrate to group; resolve auth issue
NPM_TOKEN / GITLAB_NPM_PUBLISH_TOKEN duadp, agentmarketplace, blu-book, blu-cli [SET] NPM registry authentication LEGACY_SECRET_COPY Consolidate as NPM_REGISTRY_TOKEN at group
ORACLE_SSH_KEY dragonfly, agentmarketplace, a2a-collector [SET] Oracle infrastructure SSH access LEGACY_SECRET_COPY CORRECTED 2026-08-24: already exists at blueflyio/blu group level (GET groups/blueflyio%2Fblu/variables, alongside ORACLE_DEPLOY_HOST_PRIVATE) — the "create ORACLE_SSH_KEY" action item was stale. Remaining action: confirm the three listed projects inherit it via group membership rather than carrying their own project-level copy.
GITLAB_TOKEN (project overrides) agentdev, ossa, others [SET] Project-specific GitLab API access LEGACY_SECRET_COPY Audit why project overrides are needed; consolidate if possible

Medium Priority: Evaluate for Group Level

No value indicator collected for this tier in the 2026-08-11 audit — class reflects purpose only, not a confirmed SET/UNSET/reference state.

Variable Name Current Project Purpose Class Decision Pending
CLOUDFLARE_ACCOUNT_ID iac Infrastructure automation NON_SECRET_CONFIG Is IaC deployed from multiple projects or isolated?
CLOUDFLARE_API_TOKEN iac Infrastructure automation LEGACY_SECRET_COPY Is IaC deployed from multiple projects or isolated?
CLOUDFLARE_ZONE_ID iac Infrastructure automation NON_SECRET_CONFIG Is IaC deployed from multiple projects or isolated?
OCI_TENANCY_OCID / OCI_COMPARTMENT_ID iac Oracle Cloud infrastructure IaC NON_SECRET_CONFIG Is IaC deployed from multiple projects or isolated?
ORACLE_DEPLOY_HOST / ORACLE_USER contractplane.ai-website, others Oracle deployment target NON_SECRET_CONFIG Do all deploys target same Oracle host or are there exceptions?

Low Priority: Keep at Project Level (With Documentation)

Variable Name Project Purpose Class Justification
LITELLM_ / VLLM_ agentdev Model-specific runtime configuration PROJECT_EXCEPTION Model-specific; not shared across projects
AUTHOR_TOKEN / CONTENT_ORCHESTRATOR_TOKEN / ... agents Agent persona service account tokens PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) Service-specific roles; evaluate if shared or isolated
SAST_DISABLED / SECRET_DETECTION_DISABLED blu-worker CI security job overrides NON_SECRET_CONFIG Document exception; verify if intentional or outdated
BLU_API_KEY / GITLAB_BLU_TOKEN agentblu.ai Agent-specific API authentication PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) Service-specific; keep local with justification
WEBSITE_TRIGGER_TOKEN / WEB_TOKEN ossa OSSA-specific CI/CD triggers PROJECT_EXCEPTION (LEGACY_SECRET_COPY shape) Project-specific; keep local with justification

Variable Naming Standards

Recommended conventions for new variables:

Pattern Usage Example
{SERVICE}_TOKEN Authentication/API access GITLAB_TOKEN, OPENAI_API_KEY
{SERVICE}_REGISTRY_TOKEN Package registry auth COMPOSER_REGISTRY_TOKEN, NPM_REGISTRY_TOKEN
{SERVICE}_{RESOURCE} Infrastructure access ORACLE_SSH_KEY, CLOUDFLARE_API_TOKEN
SERVICE_ACCOUNT_{ROLE}_TOKEN Service account by role SERVICE_ACCOUNT_DEPLOYMENT_TOKEN
{FEATURE}_ENABLED / DISABLED Feature flags NEO4J_ENABLED, SAST_DISABLED

Security & Access Control

Secrets policy (storage, rotation, delivery, access) is governed by standards/core/STD-SEC-001-authentication-and-secrets.md — not restated here. This catalog only records inventory facts:

  1. No Secrets in Logs
  2. GitLab masks variable values in job logs
  3. Audit evidence contains no actual values
  4. This catalog records presence class only ([SET]/[UNSET]), never value fingerprints

  5. Group-Level Inheritance

  6. Group variables cascade to all projects
  7. Project overrides permitted only with documented justification
  8. Audited quarterly

  9. Access Control

  10. Group variables: managed by Platform Team
  11. Project overrides: owned by project maintainers
  12. Changes require MR review and CI validation

Audit & Maintenance

Schedule Task Owner
Quarterly Review variable usage across active projects Platform Team
On Deploy Verify CI variables are accessible and correct Release Team
On New Project Audit for unnecessary project-level overrides Project Lead
On Rotation Rotate in 1Password (BlueflyAgents vault) per standards/core/STD-SEC-001-authentication-and-secrets.md. OBSERVED 2026-08-11: these are native GitLab group-level CI/CD variables, not 1Password op:// references — rotation currently also requires a manual GitLab-side value update until migrated to reference-based delivery. Security Team

Last Audit: 2026-08-11 (21 projects with project-level variables identified) Next Audit: 2026-11-11 (quarterly)


References

  • Audit Evidence: ledger/gitlab-cicd-variables-audit-evidence-2026-08-11.md
  • Migration Plan: governance/gitlab-cicd-variables-audit-plan.md
  • 1Password Integration: standards/core/STD-SEC-001-authentication-and-secrets.md
  • GitLab Docs: https://docs.gitlab.com/ee/ci/variables/

Catalogue Status: Evergreen Authority: Canonical (Bluefly Engineering) Last Updated: 2026-08-11 Next Review: 2026-11-11