Skip to content

Machine Identity Catalog

Authority: Bluefly Engineering (hand-maintained). Scope: One row per standing autonomous role, recording its machine identity and the auth chain that identity uses. Governed by the Authentication & Secrets Constitution §21 (Per-Role Machine Identity Requirement) and the general Identity Contract (identity record schema; this catalog is the per-role auth-chain instance of that schema, not a replacement for it). No token values, secret values, or resolved credentials belong in this document — ever. Only identity names, 1Password/GitLab principal names, scope descriptions, and rotation methods.

Purpose

The Ecosystem Alignment Directive (2026-09-06) requires that every standing autonomous role have its own machine identity, never borrow another role's credentials — including the human operator's own session. This catalog is where that requirement is proven, one row at a time, as each role is actually provisioned.

Schema

Field Meaning
ROLE The standing role name (BLU, MAYOR, etc.)
MACHINE_IDENTITY The named machine/service identity this role authenticates as — never a human's identity, never another role's
ONEPASSWORD_PRINCIPAL The 1Password Service Account / Connect binding / Identity that vouches for this role (name only, no vault paths or item IDs)
GITLAB_PRINCIPAL The GitLab identity (service account, bot user, or native CI_JOB_TOKEN-scoped identity) this role uses for GitLab operations
AUTH_SCOPE What this identity is authorized to do — least-privilege description, not "full access"
ROTATION_METHOD How this identity's credential is rotated, per the Rotation contract §16 (target platform issues/rotates, 1Password stores/delivers)

Catalog

Status: not yet populated with real values. Rows below are placeholders naming the roles this directive requires to be provisioned; each row moves from bluefly-drupal-agent to a real entry only once that role's actual 1Password Service Account and GitLab principal exist and have been verified — not before. Do not fill these in with guessed or aspirational values.

ROLE MACHINE_IDENTITY ONEPASSWORD_PRINCIPAL GITLAB_PRINCIPAL AUTH_SCOPE ROTATION_METHOD
BLU bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
MAYOR bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
REFINERY bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
SENTINEL bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
FOUNDRY bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
DRUPAL bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
WITNESS bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent
HARBORMASTER bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent bluefly-drupal-agent

Verification

Before marking any row provisioned, verify — do not assert from memory or from a bead description:

op whoami --format json           # confirms the acting session, never the target role's identity
# For the target role's own Service Account (run as/via that identity, not as the operator):
op service-account get             # or equivalent read-only self-check
glab api /user                     # confirms which GitLab principal a token resolves to

A row is PROVISIONED only after both the 1Password principal and the GitLab principal have been independently confirmed to exist and to belong to that role specifically — not inferred from a bead, a prompt, or another document's claim.