Platform Ownership Matrix¶
Authority: Bluefly Engineering (hand-maintained; single source traced to
openclaw-mayor-operations.md)
Scope: What Bluefly owns vs. what upstream systems own, across capabilities, repositories, and Oracle host directories. Excludes document canon (document-ownership-matrix.md) and authority-domain "who decides" (authorities.md).
Status: Authoritative
Last verified: 2026-08-29
1. Purpose¶
Single source for capability ownership, repository ownership, Oracle host directory inventory, and open gaps between upstream doctrine and observed runtime. All rows below trace to qmd://BluCity-Docs/Engineering-Standard/standards/platforms/runtime/openclaw-mayor-operations.md unless noted otherwise — that single-source dependency is itself an open gap (see Known Gaps).
Preserves ARCH-001: Bluefly owns composition, governance, accountability, verification, and productization. Bluefly does not own Gas City orchestration runtime, Drupal CMS/business authority, the OpenClaw messaging gateway, the Dolt state ledger, or the OSSA/DUADP identity protocol — ownership rows below classify each capability against that boundary.
2. Classification Rules¶
- Evidence Classification —
VERIFIED(confirmed against a cited upstream doc),OBSERVED(confirmed against live runtime/host state), orNot established(no evidence yet). Never silently upgradeOBSERVEDtoVERIFIEDwithout an independent upstream citation. - Canonical tool name is
blu-cli— neverbcli.
3. Catalog¶
Capability Ownership¶
| Capability | Upstream Owner | Bluefly Owner | Evidence Classification | Evidence |
|---|---|---|---|---|
| Packs | Gas City (Gas City is imported configuration per ADR-0026) | blucity-packs |
VERIFIED |
openclaw-mayor-operations.md lists blucity-packs as Bluefly owner of Gas City packs. |
| OpenClaw Gateway | OpenClaw | Oracle Host | VERIFIED |
openclaw-mayor-operations.md states Oracle runs the authoritative OpenClaw gateway (copaw.us); NAS is explicitly deferred (storage/sidecars only). |
| Container / Runtime Wiring | Docker Compose | agent-docker |
VERIFIED |
openclaw-mayor-operations.md lists agent-docker as owner of container/runtime wiring. |
| Runtime Network Attachment | Tailscale | agent-tailscale |
VERIFIED |
openclaw-mayor-operations.md lists agent-tailscale as owner of network attachment. |
| Infrastructure Provisioning | Ansible / Terraform | iac |
VERIFIED |
openclaw-mayor-operations.md lists iac as owner of infrastructure provisioning. |
| CI/CD Components | GitLab | gitlab_components |
VERIFIED |
openclaw-mayor-operations.md lists gitlab_components as owner of CI/CD components. |
| LiteLLM Configuration | LiteLLM | Bluefly Platform / Unknown | OBSERVED |
Untracked ./data/bluefly/litellm/config.yml on Oracle host — see Known Gaps, Conflict 1. |
| Engineering Methodology | Gas City / OpenClaw (upstream docs governing contract per ADR-0027) | Bluefly Engineering | VERIFIED |
engineering-methodology.md mandates Graph-First capability/ownership tracking (Canon Candidate, 2026-07-07). |
| Cedar Policy Enforcement (runtime) | Cedar | cedar_policy (Drupal module, project 76284311) |
VERIFIED |
BLU source audit 2026-08-24 (ubuntu-bnug): local_evaluator/dev_policy_sync/gitlab_policy_sync are real, production-routable services (real routes/forms/ECA/Tool API), technically PRODUCTION_CAPABLE with zero environment guard — but the module defines no enforcement_mode key, so nothing gates them today. Technical capability and governance authorization are separate axes; see gas-city-deployment-wiring.md. |
| Cedar Policy Source (authoring) | Cedar | cedar-policies (project 80054291) |
VERIFIED |
Standalone repo confirmed real 2026-08-24 (Foundry): cedarschema/, policies/, policies/tests/ with decision fixtures, tools/run-validate-cedar.mjs. Not to be confused with the embedded copies inside compliance-engine/cedar-policies and blutown/cedar_policies — duplication status of those two Not established. |
Repository Ownership¶
Repositories evaluated against documented purpose and Oracle runtime needs:
| Repository | Purpose | Runtime Needs Git? | Evidence Classification | Evidence | Recommendation |
|---|---|---|---|---|---|
agent-docker |
OpenClaw container/runtime wiring | No | VERIFIED |
openclaw-mayor-operations.md; runtime state belongs to the runtime, not Git checkouts. |
PROPOSED: migrate to compiled artifact deployment rather than Git clone execution on Oracle. |
agent-tailscale |
Runtime network attachment | No | VERIFIED |
openclaw-mayor-operations.md. |
PROPOSED: manage network via CI/CD execution rather than manual Git clones. |
iac |
Infrastructure provisioning | No | VERIFIED |
openclaw-mayor-operations.md; executes against Oracle remotely. |
Retain as canonical source on NAS; execution occurs via runner. |
gitlab_components |
CI/CD components | No | VERIFIED |
openclaw-mayor-operations.md. |
Retain as canonical source on NAS. |
blucity-packs |
Bluefly-owned Gas City packs | No | VERIFIED |
openclaw-mayor-operations.md. |
PROPOSED: build packs in CI and publish to registry; do not sync repo to Oracle. |
agent-platform/models/* |
Domain schemas (NOT trained LLMs) | No | VERIFIED |
P0 Architecture Decision | Retain as domain schema definitions |
agent-platform/services/* |
Consolidation targets | No | VERIFIED |
P0 Architecture Decision | Target for consolidation |
Oracle Host Directory Inventory¶
Known directories on the Oracle runtime host. Facts only:
| Directory | Why It Exists | Owner | Required? | Evidence Classification | Evidence |
|---|---|---|---|---|---|
/opt/bluefly/agent-docker |
Git clone used to execute docker compose up for the Oracle OpenClaw Gateway. |
Bluefly | OBSERVED |
OBSERVED |
Confirmed by CI deployment pipeline (.gitlab-ci.yml) and deployments/oracle/docker-compose.yml. |
/opt/bluefly/agent-docker/deployments/oracle/data/bluefly/litellm |
Holds untracked config.yml for LiteLLM. |
Bluefly | OBSERVED |
OBSERVED |
services/litellm-proxy.yml bind-mounts ./data/bluefly/litellm/config.yml:/app/config.yaml. |
/opt/bluefly/blu-cli |
Local CLI tool source clone. | Bluefly | OBSERVED |
OBSERVED |
Prior runtime convergence audits. |
/opt/bluefly/bluguide |
Source clone for serving documentation. | Bluefly | OBSERVED |
OBSERVED |
Prior runtime convergence audits. |
4. Relationships & Known Gaps¶
Capability owners map to Repository owners, which map to Oracle host directories where they execute.
Conflict 1 — Runtime State vs. Git Checkouts¶
Upstream expectation: openclaw-mayor-operations.md — "runtime state belongs to the runtime that creates it"; agent-docker is container/runtime wiring, not a persistent state store.
Observed: the deployment pipeline clones agent-docker to /opt/bluefly/agent-docker and runs docker compose up; services/litellm-proxy.yml bind-mounts the untracked ./data/bluefly/litellm/config.yml, so host filesystem acts as an undocumented config database.
Proposed changes:
1. Eliminate relative ./data/ bind mounts — bake LiteLLM config.yml into an immutable deployment artifact or inject via secrets/IaC.
2. Stop cloning agent-docker to Oracle — CI should bundle compose files/config into a deployable artifact (or deploy via API), eliminating the /opt/bluefly/agent-docker Git checkout.
Conflict 2 — Authoritative Gateway Placement¶
Upstream expectation: openclaw-mayor-operations.md — Oracle is the authoritative OpenClaw gateway (copaw.us); NAS is explicitly not a gateway in this pass.
Observed: NAS serves as the canonical engineering workspace, but repositories are occasionally executed directly on NAS out of convenience.
Proposed change: enforce execution boundaries — CI/CD contexts must strictly target OpenClaw gateway components at the Oracle host only, keeping NAS strictly engineering/storage.
Structural gap — single-source evidence¶
Every VERIFIED row in this file traces to one document, openclaw-mayor-operations.md. No independent cross-verification exists yet. Treat VERIFIED here as "verified against one upstream doc," not "cross-checked against runtime," until an OBSERVED-tier pass confirms each row against the live Oracle host.
5. Ecosystem Adoption Ladder (Phase A Evidence)¶
Evergreen summary from 2026-08-29 GitLab API evidence. Status vocabulary: BUILT / RELEASED / ADOPTED / CONVERGED.
| Repository | Adoption | Consumers (evidence class) | Notes |
|---|---|---|---|
blueflyio/gitlab_components |
ADOPTED | CI includes (e.g. blu/blu-book .gitlab-ci.yml) |
Preferred shared CI surface |
blueflyio/security-policies |
BUILT | Docs/ownership mentions; CI include not proven | Do not mass-migrate |
blueflyio/blu/blu-cli |
ADOPTED | Blob refs + tags | Operator CLI |
blueflyio/contextcontrol.ai/context-cli |
BUILT | Blob refs; RELEASED unknown (no semver tag) | Distinct from blu-cli |
blueflyio/cedar-policies |
BUILT | Many blob refs; RELEASED unknown | Tag attestation pending |
blueflyio/agent-platform/services/compliance-engine |
ADOPTED | Blob refs + tags | PDP evaluation |
blueflyio/contractplane.ai/contractplane-sdk |
ADOPTED | Blob refs + v0.1.0 |
Schemas-only shared surface |
blueflyio/agent-platform/tools/api-schema-registry |
ADOPTED | Blob refs + tags | Contract primitives |
blueflyio/agent-platform/infra/agent-docker |
ADOPTED | Blob refs + v1.0.0 |
Compose deploy |
blueflyio/duadp/duadp |
ADOPTED | Blob refs + tags | Discovery/resolution |
blueflyio/dragonfly/dragonfly |
ADOPTED | Blob refs + tags | Browser E2E authority |
blueflyio/agentictools/agents |
RELEASED | Consumer refs unknown in sample | Catalog/agents |
blueflyio/agentictools/skills |
BUILT | — | RELEASED unknown |
blueflyio/agentictools/plugins |
BUILT | Consumes gitlab_components golden | RELEASED unknown |
Service plane (agent-protocol, agent-mesh, agent-router, agent-brain, agent-tracer, foundation-bridge, agent-tailscale, studio-ui) |
RELEASED | ADOPTED unknown in sample | Tags present; estate consumers not proven |
a2a-collector, blu-worker, iac |
BUILT | — | No durable release tag proven |