Skip to content

OpenCode Execution Harness Operating Model

1. Role & Authority Boundary

OpenCode is strictly an execution harness and inference client for Bluefly agents. It is never a work, source, or doctrine authority.

THOMAS (Human Intent)
   │
   ▼
BLU (Cross-Fleet Orchestrator)
   │
   ├── Gas City / Beads (`bd`) ───────────► Work & Dependency Authority
   ├── GitLab (`glab`) ───────────────────► Source, MR & Release Authority
   ├── BluCity-Docs ──────────────────────► Engineering Doctrine Authority
   ├── CMUX ──────────────────────────────► Operator & Attention Surface
   │
   └── OpenCode ──────────────────────────► Governed Execution Harness
         ├── Inference Providers (NAS Ollama, Mac Ollama, LM Studio)
         ├── Specialist Agents (10-role mesh with scoped permissions)
         ├── Native Skill Discovery (`.agents/skills/`)
         ├── Lifecycle Hooks (`gascity.js`, `cmux-session.js`, `cmux-feed.js`)
         └── Mechanical Safety Guardrails (deny destructive operations)

What OpenCode Does NOT Own:

  • Work graph: Owned by Gas City Beads (bd). OpenCode does not persist work item truth.
  • Source code & PRs: Owned by GitLab (glab). OpenCode only edits within assigned branches/worktrees.
  • Doctrine & Standards: Owned by BluCity-Docs. OpenCode reads AGENTS.md and standard docs; it never forks doctrine.
  • Operator Surface: Owned by CMUX. OpenCode emits feed and session events to CMUX via socket.

2. Tiered Model Cost Routing

All OpenCode agent operations are routed to appropriate inference tiers based on task complexity, avoiding unconstrained 30B invocation for lightweight tasks.

Tier Models Primary Use Cases Assigned Roles
TINY / SMALL phi4-mini
qwen2.5-coder:3b
Titling, session naming, metadata extraction, small checks, heartbeat small_model
harbormaster
mayor
MEDIUM qwen2.5-coder:7b
granite3.3:8b
gemma3:4b
Code search, diff inspection, MR review, release classification, validation forge
refinery
witness
openclaw
LARGE qwen3-coder:30b
qwen3:14b
Complex refactoring, multi-file code implementation, Drupal modules, platform packages drupal
foundry
sentinel
primary builder

Host Endpoints:

  • Primary NAS (Synology DS224+): http://blueflynas:11434/v1 (Ollama OpenAI-compatible)
  • Local Fallback (Mac M4): http://127.0.0.1:11434/v1
  • LM Studio (Local GUI): http://localhost:1234/v1

3. Mechanical Guardrails & Permission Matrix

OpenCode enforces strict mechanical permissions at both the global and agent levels to eliminate destructive errors.

Global Deny Rules:

  • Prohibit destructive git resets, working tree discards, stashing, and root deletions.
  • File edits allowed within active repository bounds.
  • External directory access requires confirmation.

Role-Specific Permissions:

Agent Role Edit / Write Bash Tools Target Scope
blu Deny Allowed (read/query) Estate-wide orchestration
drupal Allowed Allowed Drupal modules, recipes, config
forge Allowed Allowed Consumer repo & DDEV verification
foundry Allowed Allowed Shared SDKs, CLI, platform packages
harbormaster Deny Allowed (storage/docker) NAS health & backups
mayor Deny Allowed (read/query) Oracle runtime & Gas City health
openclaw Allowed Allowed MCP bridges & external integrations
refinery Allowed Allowed GitLab CI, MRs, release branches
sentinel Deny Allowed (audit/scan) Security, Cedar, CODEOWNERS, paths
witness Deny Allowed (read/verify) Independent verification & reconciliation

4. Hook Architecture & Operator Plane Integration

OpenCode integrates bidirectionally with Gas City and CMUX through three standard plugins:

OpenCode Execution Loop
   │
   ├── gascity.js (Plugin)
   │     ├── session.created / session.compacted ──► gc prime --hook
   │     ├── experimental.session.compacting ─────► gc handoff --auto
   │     └── experimental.chat.system.transform ──► inject system nudges & unread mail
   │
   ├── cmux-session.js (Plugin)
   │     └── Session lifecycle events ─────────────► CMUX session store (restorable)
   │
   └── cmux-feed.js (Plugin)
         └── Interactive prompts & plans ─────────► CMUX socket feed.* (operator approval)

5. Portability & Path Isolation (GOV-PATH-PRIV-001)

All OpenCode configuration files, agent prompts, and plugin hooks MUST adhere to strict path isolation: - No hardcoded workstation paths: Zero occurrences of personal home directories in committed or durable configuration files. - Path resolution: Use ~, process.env.HOME, or relative paths (./plugins/...). - Discovery paths: OpenCode automatically discovers global configs in ~/.config/opencode/ and workspace overrides in .opencode/opencode.jsonc.