Canonical home: BluCity-Docs Engineering-Standard/infrastructure/nas/. Paths of the form /volume1/AgentPlatform/Catalog below are the ORIGINAL AUDIT STAGING LOCATION (2026-08-02), retired after this merge; the dated machine-readable snapshot lives in evidence/2026-08-02/.
NAS CONVERGENCE — ORACLE BEAD HANDOFF¶
Prepared on blueflyNAS 2026-08-02. Beads authority is Oracle; none of these were created from the NAS. Program parent for all ten: NAS Storage Convergence (plan: Engineering-Standard/infrastructure/NAS-STORAGE-CONVERGENCE-PLAN.md via blucity-docs MR !97; operational evidence: /volume1/AgentPlatform/Catalog).
Shared context for every Bead: single Btrfs volume /volume1 (all moves same-filesystem); receipts discipline per blu-root-convergence-20260802-142848/MOVE-MANIFEST.md; nothing deleted without its own deletion gate.
1. Migrate NAS secrets to governed 1Password injection¶
- Priority: P1 (highest of the set)
- Owning repository: infra/IaC repo that owns compose (establish in Bead 4 if ambiguous)
- Executor: NAS agent + operator (1Password vault owner)
- Evidence: NAS-SECRETS-METADATA.csv; Wave-0 receipt in NAS-AUDIT-EVIDENCE.md (file modes now 600/700 but dirs .ssh/ssl are root-owned 777; docker/ssl/privkey.pem root-owned 644)
- Acceptance: every secret value lives in 1Password; consumers use
op run/injected env; share copies retired after consumer verification; zero private keys >0600 anywhere on SMB shares; the four share-only SSH keys (id_rsa, id_ed25519, id_ed25519_drupal, share-variant id_ed25519_gitlab) identified, rotated-or-retired with owners recorded; foreign-uid file config/.ssh/config (uid 1000) reowned. - Rollback: share copies retained until each consumer verifies; per-file receipts.
- Production owner: Thomas. Dependencies: DSM admin for root-owned dirs (see Bead 3 note).
2. Converge Docker runtime mounts away from AgentPlatform source¶
- Priority: P1
- Owning repository: infra/IaC compose repo
- Executor: Mac dev (MRs) + NAS agent (verification)
- Evidence: NAS-RUNTIME-MOUNTS.csv — stopped
opencodemounted Applications RW; stoppedagent-opsmounted the entire share RW; stale mounts to five ABSENT AgentPlatform paths. - Acceptance: no container definition mounts any path under /volume1/AgentPlatform except
explicitly whitelisted read-only doc/asset paths; stale container definitions removed or
recreated correctly;
docker ps -ashows no definition referencing absent sources. - Rollback: git revert of compose MRs. Dependencies: Bead 4.
3. Move qdrant persistence out of Applications¶
- Priority: P2
- Owning repository: infra/IaC compose repo
- Executor: NAS agent (stop → same-fs mv → mount update → start → verify)
- Evidence: running bluefly-nas-qdrant binds /volume1/AgentPlatform/Applications/qdrant/storage RW.
- Acceptance: storage at /volume1/docker/services/qdrant/storage; container healthy; collection count identical pre/post; old path gone from Applications; receipt recorded.
- Rollback: reverse mv + original mount. Production owner: Thomas.
- Dependencies: Bead 2 MR merged. NOTE: also the DSM-admin items — snapshot AgentPlatform BEFORE this move (blocked Wave-0 item).
4. Reconcile stale Compose declarations with live runtime¶
- Priority: P2
- Owning repository: NEW or existing __Infra repo — first establish which repo already owns docker/services compose (do NOT create a duplicate; check __Infra group, 14 repos)
- Executor: Mac dev
- Evidence: 13 declarations point at absent AgentPlatform/data/
paths; live stack uses docker/services/*; docker/compose + services compose are mutable, not Git-owned. - Acceptance: all compose under Git;
docker compose configclean per stack; declared mounts == live mounts for every running service; dockge (if kept) reads materialized artifacts from the repo. - Rollback: current files retained as .pre-iac copies until verified. Dependencies: none.
5. Establish scheduled database and container-volume backups¶
- Standing contract: see Backup / Restore Contract
for the evergreen
BACKUP_EXISTS/BACKUP_CURRENT/CHECKSUM_OR_NATIVE_INTEGRITY/RESTORE_REHEARSALacceptance bar this Bead's acceptance criteria should be read against — a scheduled job existing is not sufficient on its own. - Priority: P1 (currently NO working scheduled backups: docker/backups/{postgres,redis} empty since 2026-01-13; only ad-hoc July dumps exist)
- Owning repository: infra repo (backup job definitions)
- Executor: operator (DSM: create /volume1/Backups share + Hyper Backup) + NAS agent (jobs)
- Acceptance: /volume1/Backups DSM share exists with restrictive ACL (admin full, bluefly operator, no Everyone); scheduled dumps for every live database; container named-volume backup routine; retention defined; first run verified.
- Rollback: n/a (additive). Dependencies: DSM admin session.
6. Create and validate archive migration¶
- Priority: P3
- Executor: operator (create /volume1/Archive DSM share) + NAS agent (moves per NAS-MIGRATION-MAP.csv: AgentPlatform/data/* archives, docker/_archive, #recycle retention)
- Acceptance: archive material relocated with per-item receipts; recycle retention policy written; source dirs emptied but deleted only after verification gates.
- Rollback: same-fs mv back. Dependencies: Bead 5 share pattern.
7. Deduplicate repositories under docker/repos¶
- Priority: P2
- Executor: NAS agent (read-mostly, per-repo receipts)
- Evidence: git clones inside /volume1/docker/repos (23.8 MB); 174 canonical repos under Applications; 66 dirty repos (NAS-REPOSITORIES.csv); BluTown-minify unclassified.
- Acceptance: one clone per remote on the NAS; docker/repos empty or justified; dirty-repo count driven to 0 via bounded batches (commit-via-MR / preserve-branch / classify-as-drift, exactly like the BLU convergence); BluTown-minify classified.
- Rollback: preservation branches + #recycle pattern. Dependencies: snapshot coverage (blocked Wave-0 item) strongly preferred first.
8. Normalize LLM consumer metadata without moving the library¶
- Priority: P4
- Executor: NAS agent
- Topology owner: Engineering-Standard/standards/architecture/inference-topology.md (2026-09-02 SoR). 2026-08-02 audit treated two stores as canonical; that is superseded — not a second design.
- Evidence:
/volume1/AgentPlatform/LLMis model-storage SoR (LM Studio library is a Mac client of that tree; register inLLM/llms.txtbefore download)./volume1/docker/services/ollama-modelsis not AgentPlatform SoR. Live NAS Ollama (blueflynas.tailcf98b3.ts.net:11434) served onlyqwen2.5:7b,qwen2.5:0.5b,nomic-embed-textas of 2026-09-02. - Acceptance: one SoR documented;
LLM/ollama/datais the Ollama blob path; docker/services/ollama-models not listed as canonical; 7 empty taxonomy dirs pruned or justified; NO relocation of weights to Mac or Oracle. - Rollback: n/a. Dependencies: none. Do not pull models onto Mac/Oracle to "complete" this bead.
9. Implement retention policies (logs, cache, artifacts, backups, #recycle)¶
- Priority: P3
- Executor: NAS agent + operator approval of the policy document
- Acceptance: written retention policy in Catalog; empty dirs (docker/{anythingllm,artifacts,projects,cloudflared}) deleted after verification; .env.bak removed after Bead 1; scheduled cleanup receipts.
- Rollback: policy revert. Dependencies: Beads 1, 5.
10. Perform a full restore test¶
- Priority: P2
- Executor: operator + NAS agent
- Acceptance: one database dump restored end-to-end to a scratch instance; one snapshot file-level recovery browsed and copied; results receipted in Catalog; quarterly cadence agreed. "A backup is proven by a restore."
- Rollback: n/a (scratch). Dependencies: Beads 3 (DSM snapshots), 5.
Blocked Wave-0 items requiring a DSM administrative session (exact steps)¶
- Snapshots — DSM → Snapshot Replication → Snapshots → select
AgentPlatform→ Take Snapshot (name: nas-convergence-wave0-agentplatform-20260802); repeat fordocker. CLI equivalent requires root (synowebapi SYNO.Core.Share.Snapshot), which this session verifiedly lacks (binary is root-execute-only; sudo requires password). - Shares — DSM → Control Panel → Shared Folder → Create
BackupsandArchivewith ACLs per plan §1 (no Everyone, no guest, admin full control, bluefly scoped). - Root-owned residuals — chown/chmod 700 on /volume1/AgentPlatform/config/{.ssh,ssl} dirs (root-owned; contents already 600 but dirs remain 777 → replacement risk); chmod 600 /volume1/docker/ssl/privkey.pem (root-owned, world-readable); reown config/.ssh/config (uid 1000).