Skip to content

Canonical home: BluCity-Docs Engineering-Standard/infrastructure/nas/. Paths of the form /volume1/AgentPlatform/Catalog below are the ORIGINAL AUDIT STAGING LOCATION (2026-08-02), retired after this merge; the dated machine-readable snapshot lives in evidence/2026-08-02/.

NAS AUDIT EVIDENCE — 2026-08-02

Read-only estate audit, blueflyNAS (DS224+), user bluefly. Companion to NAS-STORAGE-CONVERGENCE-PLAN.md. All values observed this session; no secrets printed.

Physical estate

  • Single storage volume: /dev/vg1/volume_1, Btrfs, 5.3 TB, 1.3 TB used (25%), mounted /volume1 with synoacl. Every share (AgentPlatform, docker, homes, chat, web, web_packages, MinimServer, PlexMediaServer, TimeMachine) is a Btrfs subvolume of this one filesystem → all moves between shares are same-filesystem mv.
  • System partition /dev/md0 ext4 7.9G (33% used).
  • SMB (testparm): [AgentPlatform] path=/volume1/AgentPlatform, global follow symlinks = Yes. Shares exported: AgentPlatform, chat, docker, homes, MinimServer, PlexMediaServer, TimeMachine, web, web_packages.
  • Snapshots: /volume1/@sharesnap contains only docker → the AgentPlatform share (174 Git repos) has no snapshot protection.
  • Hyper Backup / Snapshot Replication configuration: NOT ESTABLISHED (root-only; synoshare --get and scheduler configs denied; not bypassed).

/volume1/docker top level (sizes in KB unless noted)

entry size owner mode git note
.env 4 bluefly 600 – secrets env
_archive 268 bluefly 777 – archive material inside runtime share (a2a-collector, clickhouse, phoenix, AUDIT-SEPARATION-OF-DUTIES.md)
agent-tools 452,296 bluefly 777 – workspace/home bind-mounted by stopped agent-tools container
agents 232 bluefly 777 – clickhouse-users.xml consumed RO by running clickhouse
anythingllm 0 bluefly 777 – EMPTY
artifacts 0 bluefly 755 – EMPTY
backups 10,472 bluefly 755 – oracle/ (700); postgres/ and redis/ EMPTY since 2026-01-13
cache 12 bluefly 755 – near-empty
cloudflared 0 bluefly 777 – EMPTY (real config under services/)
compose 124 bluefly 777 – mutable compose defs, not Git-controlled
config 100 bluefly 777 – .env, .env.local, .env.bak, .env.sync-status.txt
copaw-api 428 bluefly 755 – cloudflared-copaw (exited)
databases 14,472 bluefly 777 – db files; consuming containers stopped
logs 4 bluefly 777 – near-empty
opencode 1,476 bluefly 777 – opencode container (exited)
projects 0 bluefly 777 – EMPTY
repos 23,824 bluefly 777 contains git Git clones inside runtime share
services ~78 GB bluefly 777 – 40 service dirs; ollama-models 77.4 GB, open-webui 489 MB
ssl 16 root 777 – cert.pem/fullchain/privkey/syno-ca — duplicated in AgentPlatform/config/ssl
AGENTS.md 4 bluefly 777 – doc

/volume1/AgentPlatform top level

  • Applications — 174 Git repos (inventory: nas_projects.json, 2026-07-31): groups __DRUPAL 71, _Archives 15, __BLU 14, __Infra 14, __AgenticTools 11, __LAB 10, __Apps 9, __DrupalSites 8, __NEXTJS 5, __CLI-SDK 4, __Libraries 4, __Models 4 (+ others). 66 repos flagged dirty. Full rows: NAS-REPOSITORIES.csv.
  • Applications/qdrant/storage — live runtime DB: running container bluefly-nas-qdrant bind-mounts it RW (runtime data inside the source share).
  • BluCity / BluTown / BluCity-Docs — relative symlinks into Applications/__BLU (verified: test -L 0; alias inode == canonical inode: 42:45584194 / 42:45584467 / 42:41586859).
  • BluTown-minify — 412 KB, 777, purpose UNKNOWN.
  • Catalog, Worktrees — created this audit (operator-authorized).
  • config — 1.9 MB: AGENTS.md, OWNERSHIP.md, config.json, oracle-env, blu-cli/, git-hooks/, templates/, llms.txt + secrets (below).
  • data — 80 MB: backups/oracle, database_backups (2026-07-12 mariadb dumps, DDEV_EVACUATION, agent-docker-mac-migration-2026-07-20), OpenCode/, oracle-audit/, stash-preservation-20260731/ (blucity-packs stash patches), eadir-backup-20260731/ (git eaDir tarballs).
  • LLM — 107.2 GB = models/lm-studio/models (lmstudio-community, mlx-community [Apple-MLX ⇒ Mac-only], qwen, mistralai, deepseek-ai, google, meta-llama, anthropic, microsoft, ibm, ai21, cohere). Consumer as of this audit: LM Studio on the Mac over SMB. Seven sibling taxonomy dirs (cache, datasets, embeddings, indexes, rerankers, vision, whisper) empty since 2026-07-22. This audit also saw /volume1/docker/services/ollama-models/data (77.4 GB). Supersession (2026-09-02): two stores are not design. Model-storage SoR is /volume1/AgentPlatform/LLM only (LLM/llms.txt, LLM/ollama/data). docker/services/ollama-models is not AgentPlatform SoR. See Engineering-Standard/standards/architecture/inference-topology.md.
  • recycle — blu-root-convergence-20260802-142848 preservation (recycled BluCity, BluTown, BluCity-Docs + BluTown-preservation kit + manifests).

  • Knowledge, Scratch — present; contents not classified this pass (sizes pending).

Containers (22 total: 7 running, 15 exited/created)

Running: litellm-proxy, bluefly-nas-ollama, bluefly-nas-qdrant, clickhouse-observability, bluefly-happy-server-1, agent-tracer (restart-looping), cloudflared-contextcontrol (restart-looping, exit 255).

Key mount findings (full table: NAS-RUNTIME-MOUNTS.csv): - bluefly-nas-qdrant → /volume1/AgentPlatform/Applications/qdrant/storage RW — runtime inside source authority. - Stopped opencode mounted /volume1/AgentPlatform/Applications RW; stopped agent-ops mounted the entire /volume1/AgentPlatform RW — source share exposed wholesale to containers. - Stale mounts to ABSENT paths: AgentPlatform/OpenCode/{config,data}, AgentPlatform/services/{verdaccio,obsidian}/, AgentPlatform/data/sandbox/gascity-hq. - gitlab-runner (stopped) binds /var/run/docker.sock (privileged pattern). - 13 compose mount declarations point at /volume1/AgentPlatform/data/ paths that do not exist*; live runtime converged on /volume1/docker/services instead. Compose(-declared) vs runtime(-actual) drift is systemic.

Secrets (metadata only; full list NAS-SECRETS-METADATA.csv)

  • /volume1/AgentPlatform/config/.ssh — five private keys (id_rsa, id_ed25519, id_ed25519_bluefly, id_ed25519_gitlab, id_ed25519_drupal) at mode 777 on an SMB share. Canonical 0600 copy of id_ed25519_bluefly already exists at ~/.ssh (proven working this session).
  • /volume1/AgentPlatform/config/ssl — TLS privkey + OCI API private key + personal certs, 777; cert set duplicates /volume1/docker/ssl (root 777).
  • .env sprawl: /volume1/docker/.env (600), docker/config/.env{,.local,.bak}, docker/compose/.env, services/{code-server,intel-feed,nas-ai-stack,otel-collector,docker}/.env; qwenpaw/secrets bind-mounted RW.
  • termius-bridge-credentials.json, .op-env.txt on the share.
  • 1Password CLI (op 2.30.3) present — the intended secret authority already exists on-box.

Backups

  • docker/backups: oracle/ only real content; postgres/ & redis/ empty since January — a backups folder that isn't backing up.
  • AgentPlatform/data/database_backups: one-off July dumps (bluefly.io, contextcontrol mariadb).
  • Snapshot protection: docker share only. AgentPlatform: none. Restore tests: no evidence found. Hyper Backup: NOT ESTABLISHED (root-only).
  • TimeMachine share exists (Mac backup target).

Reference inventories (moved into Catalog this session per operator instruction)

  • gitlab_projects.json — 176 GitLab projects (2026-07-30)
  • nas_projects.json — 174 NAS repos (2026-07-30)
  • cloudflare_domains.json — Cloudflare estate (2026-07-31)

Evidence gaps (NOT ESTABLISHED)

  • Hyper Backup job definitions, Snapshot Replication schedule (root-only)
  • Synology scheduled tasks (root-only)
  • happy-server anonymous volume contents/purpose
  • agent-tracer and cloudflared-contextcontrol restart-loop root causes
  • BluTown-minify, Knowledge, Scratch classification
  • docker/repos remote identities vs Applications copies (per-repo comparison pending)
  • Applications/Knowledge/Scratch exact sizes (du pass still running at write time)

WAVE 0 + EMERGENCY SECRET CONTAINMENT — EXECUTION RECEIPT (2026-08-02, appended)

Statuses: OBSERVED / CHANGED / VERIFIED / BLOCKED / NOT ESTABLISHED. Nothing deleted.

Own processes

  • CHANGED: background du (PIDs 10850 parent, 11015 child) terminated via exact-PID SIGTERM. VERIFIED exited. Applications/Knowledge/Scratch sizes remain NOT ESTABLISHED.

Snapshots (Wave 0)

  • BLOCKED — VERIFIED DSM ADMINISTRATIVE BLOCKER: bluefly is in administrators group but sudo requires a password (none available to session), /usr/syno/sbin/synoshare and /usr/syno/bin/synowebapi are root-execute-only, btrfs subvolume snapshot requires root. No unsupported bypass attempted; no tar-file fake snapshots created.
  • Exact operator steps recorded in NAS-CONVERGENCE-BEAD-HANDOFF.md (DSM → Snapshot Replication → take snapshot for AgentPlatform and docker with wave0 names).

Backup/Archive shares (Wave 0)

  • BLOCKED — same DSM administrative blocker. No insecure 0777 fallback directories created. Exact DSM share-creation steps + ACL intent recorded in the handoff.

Secret containment (CHANGED + VERIFIED)

  • config/.ssh: 14 private keys → 0600; all .pub → 0644. Key census larger than initial sweep: bb_rsa, Bluefly2024Q3, ccme_id_rsa, gitlab_rsa, id_rsa, id_ed25519, id_ed25519_bluefly, id_ed25519_drupal, id_ed25519_gitlab, + others (see ls evidence).
  • Fingerprint comparison (no private material displayed): id_ed25519_bluefly share==home MATCH (SHA256:18MZzk7E…) — home ~/.ssh copy is canonical (700/600 VERIFIED). id_ed25519_gitlab share≠home (4K86pnds… vs KrDi8prg…) — TWO DISTINCT KEYS share one name. id_rsa(share) ≠ gitlab_rsa(home). Share-only keys with no home canonical: id_rsa, id_ed25519, id_ed25519_drupal, id_ed25519_gitlab(share variant) — retained, restricted.
  • config/ssl: privkey.pem, oci_api_key.pem, [email protected]…01.434Z.pem → 0600; public certs remain 0644.
  • config: .op-env.txt, termius-bridge-credentials.json → 0600 (.npm-op-env already 0600).
  • docker: config/.env{,.local,.bak}, compose/.env, services/{code-server,intel-feed, nas-ai-stack,otel-collector,docker}/.env{,-deploy} → 0600; services/qwenpaw/secrets → 0700. docker/.env was already 0600 (OBSERVED).
  • BLOCKED (root-owned, needs DSM admin): dirs config/.ssh and config/ssl remain root:root 0777+ACL (contents protected at file level; directory-level replacement risk remains); /volume1/docker/ssl/privkey.pem root:root 0644 world-readable; config/.ssh/config owned by foreign uid 1000 (0777).
  • Consumer preflight: no RUNNING container binds any contained path (mount table re-checked); wiki-sync (sole compose consumer of config/.ssh, ro) is not running; scheduled tasks NOT ESTABLISHED (root-only) — residual risk noted.

Post-change verification (VERIFIED)

  • SSH as bluefly with ~/.ssh/id_ed25519_bluefly: Welcome @bluefly ✓
  • docker ps before/after: same 7 containers; agent-tracer restart-loop PRE-EXISTING; happy-server and cloudflared-contextcontrol were already flapping before changes and were Up at final check. No new restart loops introduced. Nothing restarted by agent.
  • BluCity/BluTown/BluCity-Docs symlinks intact ✓. Repositories untouched. LLM untouched.

Inventory corrections

  • NAS-SECRETS-METADATA.csv: supersede modes with this receipt (files now 600/700 as above); add share-only key census delta (bb_rsa, Bluefly2024Q3, ccme_id_rsa et al.).

MR !97

  • Pipeline 2725509997: status at receipt time recorded in final session receipt; merge evidence appended below when completed.

CONTAINMENT CLASSIFICATION CORRECTION (2026-08-02, effective-ACL inspection)

Unix mode ≠ effective Synology access; this section records effective state per synoacltool.

VERIFIED CONTAINED (file is Linux-mode → Unix 600 IS the effective control; no Synology ACL entries; Everyone: no access; guest: no access; parent dir ACL grants group users r-x only — read/traverse, NO write → no replacement capability for non-root users): - config/.ssh/* private keys (14 files, 600, owner bluefly) - config/ssl/{privkey.pem, oci_api_key.pem, thomas@…01.434Z.pem} (600) - config/{.op-env.txt, .npm-op-env, termius-bridge-credentials.json} (600) - docker/{.env, config/.env, config/.env.local, config/.env.bak, compose/.env} (600) - docker/services/{code-server,intel-feed,nas-ai-stack,otel-collector,docker}/.env{,-deploy} (600) - docker/services/qwenpaw/secrets (700)

UNIX MODE HARDENED — ACL BLOCKED (correction: dir ACL inspection shows group users allow r-x only, so effective exposure is read-only listing, not replacement; the BLOCKED part is the inability to chown/tighten the root-owned dirs themselves): - config/.ssh (dir: root-owned, ACL group users r-x + user tm r-x) - config/ssl (dir: same ACL)

NOT CONTAINED — BLOCKED (root-owned; needs DSM admin): - /volume1/docker/ssl/privkey.pem — root:root 644 Linux mode → world-readable TLS private key - config/.ssh/config — uid 1000, 777

CONSUMER VERIFICATION: - VERIFIED: bluefly GitLab SSH (~/.ssh/id_ed25519_bluefly → Welcome @bluefly) - VERIFIED (by absence): zero RUNNING containers bind any contained path (mount table) - DEFERRED: TLS privkey consumers (no active consumer identified; owning Bead: secrets migration #1); OCI key consumer (no active tooling run without mutation risk); stopped compose stacks' .env resolution (verify at next authorized stack start; Bead #1/#4); wiki-sync (stopped; verify when its stack is next started) - Everyone effective access: NONE on all contained files. Guest: NONE (no ACL entries).