Skip to content

Canonical home: BluCity-Docs Engineering-Standard/infrastructure/nas/. Paths of the form /volume1/AgentPlatform/Catalog below are the ORIGINAL AUDIT STAGING LOCATION (2026-08-02), retired after this merge; the dated machine-readable snapshot lives in evidence/2026-08-02/.

NAS CONVERGENCE — ORACLE BEAD HANDOFF

Prepared on blueflyNAS 2026-08-02. Beads authority is Oracle; none of these were created from the NAS. Program parent for all ten: NAS Storage Convergence (plan: Engineering-Standard/infrastructure/NAS-STORAGE-CONVERGENCE-PLAN.md via blucity-docs MR !97; operational evidence: /volume1/AgentPlatform/Catalog).

Shared context for every Bead: single Btrfs volume /volume1 (all moves same-filesystem); receipts discipline per blu-root-convergence-20260802-142848/MOVE-MANIFEST.md; nothing deleted without its own deletion gate.


1. Migrate NAS secrets to governed 1Password injection

  • Priority: P1 (highest of the set)
  • Owning repository: infra/IaC repo that owns compose (establish in Bead 4 if ambiguous)
  • Executor: NAS agent + operator (1Password vault owner)
  • Evidence: NAS-SECRETS-METADATA.csv; Wave-0 receipt in NAS-AUDIT-EVIDENCE.md (file modes now 600/700 but dirs .ssh/ssl are root-owned 777; docker/ssl/privkey.pem root-owned 644)
  • Acceptance: every secret value lives in 1Password; consumers use op run/injected env; share copies retired after consumer verification; zero private keys >0600 anywhere on SMB shares; the four share-only SSH keys (id_rsa, id_ed25519, id_ed25519_drupal, share-variant id_ed25519_gitlab) identified, rotated-or-retired with owners recorded; foreign-uid file config/.ssh/config (uid 1000) reowned.
  • Rollback: share copies retained until each consumer verifies; per-file receipts.
  • Production owner: Thomas. Dependencies: DSM admin for root-owned dirs (see Bead 3 note).

2. Converge Docker runtime mounts away from AgentPlatform source

  • Priority: P1
  • Owning repository: infra/IaC compose repo
  • Executor: Mac dev (MRs) + NAS agent (verification)
  • Evidence: NAS-RUNTIME-MOUNTS.csv — stopped opencode mounted Applications RW; stopped agent-ops mounted the entire share RW; stale mounts to five ABSENT AgentPlatform paths.
  • Acceptance: no container definition mounts any path under /volume1/AgentPlatform except explicitly whitelisted read-only doc/asset paths; stale container definitions removed or recreated correctly; docker ps -a shows no definition referencing absent sources.
  • Rollback: git revert of compose MRs. Dependencies: Bead 4.

3. Move qdrant persistence out of Applications

  • Priority: P2
  • Owning repository: infra/IaC compose repo
  • Executor: NAS agent (stop → same-fs mv → mount update → start → verify)
  • Evidence: running bluefly-nas-qdrant binds /volume1/AgentPlatform/Applications/qdrant/storage RW.
  • Acceptance: storage at /volume1/docker/services/qdrant/storage; container healthy; collection count identical pre/post; old path gone from Applications; receipt recorded.
  • Rollback: reverse mv + original mount. Production owner: Thomas.
  • Dependencies: Bead 2 MR merged. NOTE: also the DSM-admin items — snapshot AgentPlatform BEFORE this move (blocked Wave-0 item).

4. Reconcile stale Compose declarations with live runtime

  • Priority: P2
  • Owning repository: NEW or existing __Infra repo — first establish which repo already owns docker/services compose (do NOT create a duplicate; check __Infra group, 14 repos)
  • Executor: Mac dev
  • Evidence: 13 declarations point at absent AgentPlatform/data/ paths; live stack uses docker/services/*; docker/compose + services compose are mutable, not Git-owned.
  • Acceptance: all compose under Git; docker compose config clean per stack; declared mounts == live mounts for every running service; dockge (if kept) reads materialized artifacts from the repo.
  • Rollback: current files retained as .pre-iac copies until verified. Dependencies: none.

5. Establish scheduled database and container-volume backups

  • Standing contract: see Backup / Restore Contract for the evergreen BACKUP_EXISTS/BACKUP_CURRENT/CHECKSUM_OR_NATIVE_INTEGRITY/ RESTORE_REHEARSAL acceptance bar this Bead's acceptance criteria should be read against — a scheduled job existing is not sufficient on its own.
  • Priority: P1 (currently NO working scheduled backups: docker/backups/{postgres,redis} empty since 2026-01-13; only ad-hoc July dumps exist)
  • Owning repository: infra repo (backup job definitions)
  • Executor: operator (DSM: create /volume1/Backups share + Hyper Backup) + NAS agent (jobs)
  • Acceptance: /volume1/Backups DSM share exists with restrictive ACL (admin full, bluefly operator, no Everyone); scheduled dumps for every live database; container named-volume backup routine; retention defined; first run verified.
  • Rollback: n/a (additive). Dependencies: DSM admin session.

6. Create and validate archive migration

  • Priority: P3
  • Executor: operator (create /volume1/Archive DSM share) + NAS agent (moves per NAS-MIGRATION-MAP.csv: AgentPlatform/data/* archives, docker/_archive, #recycle retention)
  • Acceptance: archive material relocated with per-item receipts; recycle retention policy written; source dirs emptied but deleted only after verification gates.
  • Rollback: same-fs mv back. Dependencies: Bead 5 share pattern.

7. Deduplicate repositories under docker/repos

  • Priority: P2
  • Executor: NAS agent (read-mostly, per-repo receipts)
  • Evidence: git clones inside /volume1/docker/repos (23.8 MB); 174 canonical repos under Applications; 66 dirty repos (NAS-REPOSITORIES.csv); BluTown-minify unclassified.
  • Acceptance: one clone per remote on the NAS; docker/repos empty or justified; dirty-repo count driven to 0 via bounded batches (commit-via-MR / preserve-branch / classify-as-drift, exactly like the BLU convergence); BluTown-minify classified.
  • Rollback: preservation branches + #recycle pattern. Dependencies: snapshot coverage (blocked Wave-0 item) strongly preferred first.

8. Normalize LLM consumer metadata without moving the library

  • Priority: P4
  • Executor: NAS agent
  • Topology owner: Engineering-Standard/standards/architecture/inference-topology.md (2026-09-02 SoR). 2026-08-02 audit treated two stores as canonical; that is superseded — not a second design.
  • Evidence: /volume1/AgentPlatform/LLM is model-storage SoR (LM Studio library is a Mac client of that tree; register in LLM/llms.txt before download). /volume1/docker/services/ollama-models is not AgentPlatform SoR. Live NAS Ollama (blueflynas.tailcf98b3.ts.net:11434) served only qwen2.5:7b, qwen2.5:0.5b, nomic-embed-text as of 2026-09-02.
  • Acceptance: one SoR documented; LLM/ollama/data is the Ollama blob path; docker/services/ollama-models not listed as canonical; 7 empty taxonomy dirs pruned or justified; NO relocation of weights to Mac or Oracle.
  • Rollback: n/a. Dependencies: none. Do not pull models onto Mac/Oracle to "complete" this bead.

9. Implement retention policies (logs, cache, artifacts, backups, #recycle)

  • Priority: P3
  • Executor: NAS agent + operator approval of the policy document
  • Acceptance: written retention policy in Catalog; empty dirs (docker/{anythingllm,artifacts,projects,cloudflared}) deleted after verification; .env.bak removed after Bead 1; scheduled cleanup receipts.
  • Rollback: policy revert. Dependencies: Beads 1, 5.

10. Perform a full restore test

  • Priority: P2
  • Executor: operator + NAS agent
  • Acceptance: one database dump restored end-to-end to a scratch instance; one snapshot file-level recovery browsed and copied; results receipted in Catalog; quarterly cadence agreed. "A backup is proven by a restore."
  • Rollback: n/a (scratch). Dependencies: Beads 3 (DSM snapshots), 5.

Blocked Wave-0 items requiring a DSM administrative session (exact steps)

  1. Snapshots — DSM → Snapshot Replication → Snapshots → select AgentPlatform → Take Snapshot (name: nas-convergence-wave0-agentplatform-20260802); repeat for docker. CLI equivalent requires root (synowebapi SYNO.Core.Share.Snapshot), which this session verifiedly lacks (binary is root-execute-only; sudo requires password).
  2. Shares — DSM → Control Panel → Shared Folder → Create Backups and Archive with ACLs per plan §1 (no Everyone, no guest, admin full control, bluefly scoped).
  3. Root-owned residuals — chown/chmod 700 on /volume1/AgentPlatform/config/{.ssh,ssl} dirs (root-owned; contents already 600 but dirs remain 777 → replacement risk); chmod 600 /volume1/docker/ssl/privkey.pem (root-owned, world-readable); reown config/.ssh/config (uid 1000).