Canonical home: BluCity-Docs Engineering-Standard/infrastructure/nas/. Paths of the form /volume1/AgentPlatform/Catalog below are the ORIGINAL AUDIT STAGING LOCATION (2026-08-02), retired after this merge; the dated machine-readable snapshot lives in evidence/2026-08-02/.
NAS AUDIT EVIDENCE — 2026-08-02¶
Read-only estate audit, blueflyNAS (DS224+), user bluefly. Companion to NAS-STORAGE-CONVERGENCE-PLAN.md. All values observed this session; no secrets printed.
Physical estate¶
- Single storage volume: /dev/vg1/volume_1, Btrfs, 5.3 TB, 1.3 TB used (25%), mounted /volume1 with
synoacl. Every share (AgentPlatform, docker, homes, chat, web, web_packages, MinimServer, PlexMediaServer, TimeMachine) is a Btrfs subvolume of this one filesystem → all moves between shares are same-filesystemmv. - System partition /dev/md0 ext4 7.9G (33% used).
- SMB (testparm):
[AgentPlatform] path=/volume1/AgentPlatform, globalfollow symlinks = Yes. Shares exported: AgentPlatform, chat, docker, homes, MinimServer, PlexMediaServer, TimeMachine, web, web_packages. - Snapshots:
/volume1/@sharesnapcontains onlydocker→ the AgentPlatform share (174 Git repos) has no snapshot protection. - Hyper Backup / Snapshot Replication configuration: NOT ESTABLISHED (root-only;
synoshare --getand scheduler configs denied; not bypassed).
/volume1/docker top level (sizes in KB unless noted)¶
| entry | size | owner mode | git | note |
|---|---|---|---|---|
| .env | 4 | bluefly 600 | – | secrets env |
| _archive | 268 | bluefly 777 | – | archive material inside runtime share (a2a-collector, clickhouse, phoenix, AUDIT-SEPARATION-OF-DUTIES.md) |
| agent-tools | 452,296 | bluefly 777 | – | workspace/home bind-mounted by stopped agent-tools container |
| agents | 232 | bluefly 777 | – | clickhouse-users.xml consumed RO by running clickhouse |
| anythingllm | 0 | bluefly 777 | – | EMPTY |
| artifacts | 0 | bluefly 755 | – | EMPTY |
| backups | 10,472 | bluefly 755 | – | oracle/ (700); postgres/ and redis/ EMPTY since 2026-01-13 |
| cache | 12 | bluefly 755 | – | near-empty |
| cloudflared | 0 | bluefly 777 | – | EMPTY (real config under services/) |
| compose | 124 | bluefly 777 | – | mutable compose defs, not Git-controlled |
| config | 100 | bluefly 777 | – | .env, .env.local, .env.bak, .env.sync-status.txt |
| copaw-api | 428 | bluefly 755 | – | cloudflared-copaw (exited) |
| databases | 14,472 | bluefly 777 | – | db files; consuming containers stopped |
| logs | 4 | bluefly 777 | – | near-empty |
| opencode | 1,476 | bluefly 777 | – | opencode container (exited) |
| projects | 0 | bluefly 777 | – | EMPTY |
| repos | 23,824 | bluefly 777 | contains git | Git clones inside runtime share |
| services | ~78 GB | bluefly 777 | – | 40 service dirs; ollama-models 77.4 GB, open-webui 489 MB |
| ssl | 16 | root 777 | – | cert.pem/fullchain/privkey/syno-ca — duplicated in AgentPlatform/config/ssl |
| AGENTS.md | 4 | bluefly 777 | – | doc |
/volume1/AgentPlatform top level¶
- Applications — 174 Git repos (inventory: nas_projects.json, 2026-07-31): groups __DRUPAL 71, _Archives 15, __BLU 14, __Infra 14, __AgenticTools 11, __LAB 10, __Apps 9, __DrupalSites 8, __NEXTJS 5, __CLI-SDK 4, __Libraries 4, __Models 4 (+ others). 66 repos flagged dirty. Full rows: NAS-REPOSITORIES.csv.
- Applications/qdrant/storage — live runtime DB: running container bluefly-nas-qdrant bind-mounts it RW (runtime data inside the source share).
- BluCity / BluTown / BluCity-Docs — relative symlinks into Applications/__BLU (verified: test -L 0; alias inode == canonical inode: 42:45584194 / 42:45584467 / 42:41586859).
- BluTown-minify — 412 KB, 777, purpose UNKNOWN.
- Catalog, Worktrees — created this audit (operator-authorized).
- config — 1.9 MB: AGENTS.md, OWNERSHIP.md, config.json, oracle-env, blu-cli/, git-hooks/, templates/, llms.txt + secrets (below).
- data — 80 MB: backups/oracle, database_backups (2026-07-12 mariadb dumps, DDEV_EVACUATION, agent-docker-mac-migration-2026-07-20), OpenCode/, oracle-audit/, stash-preservation-20260731/ (blucity-packs stash patches), eadir-backup-20260731/ (git eaDir tarballs).
- LLM — 107.2 GB = models/lm-studio/models (lmstudio-community, mlx-community [Apple-MLX ⇒ Mac-only], qwen, mistralai, deepseek-ai, google, meta-llama, anthropic, microsoft, ibm, ai21, cohere). Consumer as of this audit: LM Studio on the Mac over SMB. Seven sibling taxonomy dirs (cache, datasets, embeddings, indexes, rerankers, vision, whisper) empty since 2026-07-22. This audit also saw
/volume1/docker/services/ollama-models/data(77.4 GB). Supersession (2026-09-02): two stores are not design. Model-storage SoR is/volume1/AgentPlatform/LLMonly (LLM/llms.txt,LLM/ollama/data). docker/services/ollama-models is not AgentPlatform SoR. SeeEngineering-Standard/standards/architecture/inference-topology.md. -
recycle — blu-root-convergence-20260802-142848 preservation (recycled BluCity, BluTown, BluCity-Docs + BluTown-preservation kit + manifests).¶
- Knowledge, Scratch — present; contents not classified this pass (sizes pending).
Containers (22 total: 7 running, 15 exited/created)¶
Running: litellm-proxy, bluefly-nas-ollama, bluefly-nas-qdrant, clickhouse-observability, bluefly-happy-server-1, agent-tracer (restart-looping), cloudflared-contextcontrol (restart-looping, exit 255).
Key mount findings (full table: NAS-RUNTIME-MOUNTS.csv):
- bluefly-nas-qdrant → /volume1/AgentPlatform/Applications/qdrant/storage RW — runtime inside source authority.
- Stopped opencode mounted /volume1/AgentPlatform/Applications RW; stopped agent-ops mounted the entire /volume1/AgentPlatform RW — source share exposed wholesale to containers.
- Stale mounts to ABSENT paths: AgentPlatform/OpenCode/{config,data}, AgentPlatform/services/{verdaccio,obsidian}/, AgentPlatform/data/sandbox/gascity-hq.
- gitlab-runner (stopped) binds /var/run/docker.sock (privileged pattern).
- 13 compose mount declarations point at /volume1/AgentPlatform/data/
Secrets (metadata only; full list NAS-SECRETS-METADATA.csv)¶
- /volume1/AgentPlatform/config/.ssh — five private keys (id_rsa, id_ed25519, id_ed25519_bluefly, id_ed25519_gitlab, id_ed25519_drupal) at mode 777 on an SMB share. Canonical 0600 copy of id_ed25519_bluefly already exists at ~/.ssh (proven working this session).
- /volume1/AgentPlatform/config/ssl — TLS privkey + OCI API private key + personal certs, 777; cert set duplicates /volume1/docker/ssl (root 777).
- .env sprawl: /volume1/docker/.env (600), docker/config/.env{,.local,.bak}, docker/compose/.env, services/{code-server,intel-feed,nas-ai-stack,otel-collector,docker}/.env; qwenpaw/secrets bind-mounted RW.
- termius-bridge-credentials.json, .op-env.txt on the share.
- 1Password CLI (op 2.30.3) present — the intended secret authority already exists on-box.
Backups¶
- docker/backups: oracle/ only real content; postgres/ & redis/ empty since January — a backups folder that isn't backing up.
- AgentPlatform/data/database_backups: one-off July dumps (bluefly.io, contextcontrol mariadb).
- Snapshot protection: docker share only. AgentPlatform: none. Restore tests: no evidence found. Hyper Backup: NOT ESTABLISHED (root-only).
- TimeMachine share exists (Mac backup target).
Reference inventories (moved into Catalog this session per operator instruction)¶
- gitlab_projects.json — 176 GitLab projects (2026-07-30)
- nas_projects.json — 174 NAS repos (2026-07-30)
- cloudflare_domains.json — Cloudflare estate (2026-07-31)
Evidence gaps (NOT ESTABLISHED)¶
- Hyper Backup job definitions, Snapshot Replication schedule (root-only)
- Synology scheduled tasks (root-only)
- happy-server anonymous volume contents/purpose
- agent-tracer and cloudflared-contextcontrol restart-loop root causes
- BluTown-minify, Knowledge, Scratch classification
- docker/repos remote identities vs Applications copies (per-repo comparison pending)
- Applications/Knowledge/Scratch exact sizes (du pass still running at write time)
WAVE 0 + EMERGENCY SECRET CONTAINMENT — EXECUTION RECEIPT (2026-08-02, appended)¶
Statuses: OBSERVED / CHANGED / VERIFIED / BLOCKED / NOT ESTABLISHED. Nothing deleted.
Own processes¶
- CHANGED: background du (PIDs 10850 parent, 11015 child) terminated via exact-PID SIGTERM. VERIFIED exited. Applications/Knowledge/Scratch sizes remain NOT ESTABLISHED.
Snapshots (Wave 0)¶
- BLOCKED — VERIFIED DSM ADMINISTRATIVE BLOCKER: bluefly is in
administratorsgroup butsudorequires a password (none available to session),/usr/syno/sbin/synoshareand/usr/syno/bin/synowebapiare root-execute-only,btrfs subvolume snapshotrequires root. No unsupported bypass attempted; no tar-file fake snapshots created. - Exact operator steps recorded in NAS-CONVERGENCE-BEAD-HANDOFF.md (DSM → Snapshot Replication → take snapshot for AgentPlatform and docker with wave0 names).
Backup/Archive shares (Wave 0)¶
- BLOCKED — same DSM administrative blocker. No insecure 0777 fallback directories created. Exact DSM share-creation steps + ACL intent recorded in the handoff.
Secret containment (CHANGED + VERIFIED)¶
- config/.ssh: 14 private keys → 0600; all .pub → 0644. Key census larger than initial sweep: bb_rsa, Bluefly2024Q3, ccme_id_rsa, gitlab_rsa, id_rsa, id_ed25519, id_ed25519_bluefly, id_ed25519_drupal, id_ed25519_gitlab, + others (see ls evidence).
- Fingerprint comparison (no private material displayed): id_ed25519_bluefly share==home MATCH (SHA256:18MZzk7E…) — home ~/.ssh copy is canonical (700/600 VERIFIED). id_ed25519_gitlab share≠home (4K86pnds… vs KrDi8prg…) — TWO DISTINCT KEYS share one name. id_rsa(share) ≠ gitlab_rsa(home). Share-only keys with no home canonical: id_rsa, id_ed25519, id_ed25519_drupal, id_ed25519_gitlab(share variant) — retained, restricted.
- config/ssl: privkey.pem, oci_api_key.pem, [email protected]…01.434Z.pem → 0600; public certs remain 0644.
- config: .op-env.txt, termius-bridge-credentials.json → 0600 (.npm-op-env already 0600).
- docker: config/.env{,.local,.bak}, compose/.env, services/{code-server,intel-feed, nas-ai-stack,otel-collector,docker}/.env{,-deploy} → 0600; services/qwenpaw/secrets → 0700. docker/.env was already 0600 (OBSERVED).
- BLOCKED (root-owned, needs DSM admin): dirs config/.ssh and config/ssl remain root:root 0777+ACL (contents protected at file level; directory-level replacement risk remains); /volume1/docker/ssl/privkey.pem root:root 0644 world-readable; config/.ssh/config owned by foreign uid 1000 (0777).
- Consumer preflight: no RUNNING container binds any contained path (mount table re-checked); wiki-sync (sole compose consumer of config/.ssh, ro) is not running; scheduled tasks NOT ESTABLISHED (root-only) — residual risk noted.
Post-change verification (VERIFIED)¶
- SSH as bluefly with ~/.ssh/id_ed25519_bluefly: Welcome @bluefly ✓
- docker ps before/after: same 7 containers; agent-tracer restart-loop PRE-EXISTING; happy-server and cloudflared-contextcontrol were already flapping before changes and were Up at final check. No new restart loops introduced. Nothing restarted by agent.
- BluCity/BluTown/BluCity-Docs symlinks intact ✓. Repositories untouched. LLM untouched.
Inventory corrections¶
- NAS-SECRETS-METADATA.csv: supersede modes with this receipt (files now 600/700 as above); add share-only key census delta (bb_rsa, Bluefly2024Q3, ccme_id_rsa et al.).
MR !97¶
- Pipeline 2725509997: status at receipt time recorded in final session receipt; merge evidence appended below when completed.
CONTAINMENT CLASSIFICATION CORRECTION (2026-08-02, effective-ACL inspection)¶
Unix mode ≠ effective Synology access; this section records effective state per synoacltool.
VERIFIED CONTAINED (file is Linux-mode → Unix 600 IS the effective control; no Synology
ACL entries; Everyone: no access; guest: no access; parent dir ACL grants group users
r-x only — read/traverse, NO write → no replacement capability for non-root users):
- config/.ssh/* private keys (14 files, 600, owner bluefly)
- config/ssl/{privkey.pem, oci_api_key.pem, thomas@…01.434Z.pem} (600)
- config/{.op-env.txt, .npm-op-env, termius-bridge-credentials.json} (600)
- docker/{.env, config/.env, config/.env.local, config/.env.bak, compose/.env} (600)
- docker/services/{code-server,intel-feed,nas-ai-stack,otel-collector,docker}/.env{,-deploy} (600)
- docker/services/qwenpaw/secrets (700)
UNIX MODE HARDENED — ACL BLOCKED (correction: dir ACL inspection shows group users allow r-x only, so effective exposure is read-only listing, not replacement; the BLOCKED part is the inability to chown/tighten the root-owned dirs themselves): - config/.ssh (dir: root-owned, ACL group users r-x + user tm r-x) - config/ssl (dir: same ACL)
NOT CONTAINED — BLOCKED (root-owned; needs DSM admin): - /volume1/docker/ssl/privkey.pem — root:root 644 Linux mode → world-readable TLS private key - config/.ssh/config — uid 1000, 777
CONSUMER VERIFICATION: - VERIFIED: bluefly GitLab SSH (~/.ssh/id_ed25519_bluefly → Welcome @bluefly) - VERIFIED (by absence): zero RUNNING containers bind any contained path (mount table) - DEFERRED: TLS privkey consumers (no active consumer identified; owning Bead: secrets migration #1); OCI key consumer (no active tooling run without mutation risk); stopped compose stacks' .env resolution (verify at next authorized stack start; Bead #1/#4); wiki-sync (stopped; verify when its stack is next started) - Everyone effective access: NONE on all contained files. Guest: NONE (no ACL entries).