Machine Identity Catalog¶
Authority: Bluefly Engineering (hand-maintained). Scope: One row per standing autonomous role, recording its machine identity and the auth chain that identity uses. Governed by the Authentication & Secrets Constitution §21 (Per-Role Machine Identity Requirement) and the general Identity Contract (identity record schema; this catalog is the per-role auth-chain instance of that schema, not a replacement for it). No token values, secret values, or resolved credentials belong in this document — ever. Only identity names, 1Password/GitLab principal names, scope descriptions, and rotation methods.
Purpose¶
The Ecosystem Alignment Directive (2026-09-06) requires that every standing autonomous role have its own machine identity, never borrow another role's credentials — including the human operator's own session. This catalog is where that requirement is proven, one row at a time, as each role is actually provisioned.
Schema¶
| Field | Meaning |
|---|---|
ROLE |
The standing role name (BLU, MAYOR, etc.) |
MACHINE_IDENTITY |
The named machine/service identity this role authenticates as — never a human's identity, never another role's |
ONEPASSWORD_PRINCIPAL |
The 1Password Service Account / Connect binding / Identity that vouches for this role (name only, no vault paths or item IDs) |
GITLAB_PRINCIPAL |
The GitLab identity (service account, bot user, or native CI_JOB_TOKEN-scoped identity) this role uses for GitLab operations |
AUTH_SCOPE |
What this identity is authorized to do — least-privilege description, not "full access" |
ROTATION_METHOD |
How this identity's credential is rotated, per the Rotation contract §16 (target platform issues/rotates, 1Password stores/delivers) |
Catalog¶
Status: not yet populated with real values. Rows below are placeholders
naming the roles this directive requires to be provisioned; each row moves
from bluefly-drupal-agent to a real entry only once that role's actual
1Password Service Account and GitLab principal exist and have been
verified — not before. Do not fill these in with guessed or aspirational
values.
| ROLE | MACHINE_IDENTITY | ONEPASSWORD_PRINCIPAL | GITLAB_PRINCIPAL | AUTH_SCOPE | ROTATION_METHOD |
|---|---|---|---|---|---|
| BLU | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| MAYOR | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| REFINERY | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| SENTINEL | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| FOUNDRY | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| DRUPAL | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| WITNESS | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
| HARBORMASTER | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent | bluefly-drupal-agent |
Verification¶
Before marking any row provisioned, verify — do not assert from memory or from a bead description:
op whoami --format json # confirms the acting session, never the target role's identity
# For the target role's own Service Account (run as/via that identity, not as the operator):
op service-account get # or equivalent read-only self-check
glab api /user # confirms which GitLab principal a token resolves to
A row is PROVISIONED only after both the 1Password principal and the
GitLab principal have been independently confirmed to exist and to belong
to that role specifically — not inferred from a bead, a prompt, or another
document's claim.