OpenCode Execution Harness Operating Model¶
1. Role & Authority Boundary¶
OpenCode is strictly an execution harness and inference client for Bluefly agents. It is never a work, source, or doctrine authority.
THOMAS (Human Intent)
│
▼
BLU (Cross-Fleet Orchestrator)
│
├── Gas City / Beads (`bd`) ───────────► Work & Dependency Authority
├── GitLab (`glab`) ───────────────────► Source, MR & Release Authority
├── BluCity-Docs ──────────────────────► Engineering Doctrine Authority
├── CMUX ──────────────────────────────► Operator & Attention Surface
│
└── OpenCode ──────────────────────────► Governed Execution Harness
├── Inference Providers (NAS Ollama, Mac Ollama, LM Studio)
├── Specialist Agents (10-role mesh with scoped permissions)
├── Native Skill Discovery (`.agents/skills/`)
├── Lifecycle Hooks (`gascity.js`, `cmux-session.js`, `cmux-feed.js`)
└── Mechanical Safety Guardrails (deny destructive operations)
What OpenCode Does NOT Own:¶
- Work graph: Owned by Gas City Beads (
bd). OpenCode does not persist work item truth. - Source code & PRs: Owned by GitLab (
glab). OpenCode only edits within assigned branches/worktrees. - Doctrine & Standards: Owned by
BluCity-Docs. OpenCode readsAGENTS.mdand standard docs; it never forks doctrine. - Operator Surface: Owned by CMUX. OpenCode emits feed and session events to CMUX via socket.
2. Tiered Model Cost Routing¶
All OpenCode agent operations are routed to appropriate inference tiers based on task complexity, avoiding unconstrained 30B invocation for lightweight tasks.
| Tier | Models | Primary Use Cases | Assigned Roles |
|---|---|---|---|
| TINY / SMALL | phi4-miniqwen2.5-coder:3b |
Titling, session naming, metadata extraction, small checks, heartbeat | small_modelharbormastermayor |
| MEDIUM | qwen2.5-coder:7bgranite3.3:8bgemma3:4b |
Code search, diff inspection, MR review, release classification, validation | forgerefinerywitnessopenclaw |
| LARGE | qwen3-coder:30bqwen3:14b |
Complex refactoring, multi-file code implementation, Drupal modules, platform packages | drupalfoundrysentinelprimary builder |
Host Endpoints:¶
- Primary NAS (Synology DS224+):
http://blueflynas:11434/v1(Ollama OpenAI-compatible) - Local Fallback (Mac M4):
http://127.0.0.1:11434/v1 - LM Studio (Local GUI):
http://localhost:1234/v1
3. Mechanical Guardrails & Permission Matrix¶
OpenCode enforces strict mechanical permissions at both the global and agent levels to eliminate destructive errors.
Global Deny Rules:¶
- Prohibit destructive git resets, working tree discards, stashing, and root deletions.
- File edits allowed within active repository bounds.
- External directory access requires confirmation.
Role-Specific Permissions:¶
| Agent Role | Edit / Write | Bash Tools | Target Scope |
|---|---|---|---|
blu |
Deny | Allowed (read/query) | Estate-wide orchestration |
drupal |
Allowed | Allowed | Drupal modules, recipes, config |
forge |
Allowed | Allowed | Consumer repo & DDEV verification |
foundry |
Allowed | Allowed | Shared SDKs, CLI, platform packages |
harbormaster |
Deny | Allowed (storage/docker) | NAS health & backups |
mayor |
Deny | Allowed (read/query) | Oracle runtime & Gas City health |
openclaw |
Allowed | Allowed | MCP bridges & external integrations |
refinery |
Allowed | Allowed | GitLab CI, MRs, release branches |
sentinel |
Deny | Allowed (audit/scan) | Security, Cedar, CODEOWNERS, paths |
witness |
Deny | Allowed (read/verify) | Independent verification & reconciliation |
4. Hook Architecture & Operator Plane Integration¶
OpenCode integrates bidirectionally with Gas City and CMUX through three standard plugins:
OpenCode Execution Loop
│
├── gascity.js (Plugin)
│ ├── session.created / session.compacted ──► gc prime --hook
│ ├── experimental.session.compacting ─────► gc handoff --auto
│ └── experimental.chat.system.transform ──► inject system nudges & unread mail
│
├── cmux-session.js (Plugin)
│ └── Session lifecycle events ─────────────► CMUX session store (restorable)
│
└── cmux-feed.js (Plugin)
└── Interactive prompts & plans ─────────► CMUX socket feed.* (operator approval)
5. Portability & Path Isolation (GOV-PATH-PRIV-001)¶
All OpenCode configuration files, agent prompts, and plugin hooks MUST adhere to strict path isolation:
- No hardcoded workstation paths: Zero occurrences of personal home directories in committed or durable configuration files.
- Path resolution: Use ~, process.env.HOME, or relative paths (./plugins/...).
- Discovery paths: OpenCode automatically discovers global configs in ~/.config/opencode/ and workspace overrides in .opencode/opencode.jsonc.