Fleet Lane Directive — STD-FLEET-LANE-001¶
Status: ACTIVE
Version: 1.0.0
Date: 2026-09-18
Authority: Thomas @ Bluefly.io
Canonical location:BluCity-Docs/Engineering-Standard/operating-model/fleet-lane-directive.md
Purpose¶
This document defines the window ownership model for the Bluefly governed factory fleet. Every execution window must carry a copy of the Execution Directive below, with the LANE section filled for its specific assignment.
The factory is converging, not expanding. The primary output metric is MERGED_TO_RELEASE_PER_HOUR. The correct response to green diagnostics is to finish, verify, merge, close, and clean — not to fan out into new lanes.
Global Authority¶
WORK_AUTHORITY = Gas City / Beads (canonical Oracle :3308/hq)
SOURCE_AUTHORITY = GitLab
INTEGRATION_BRANCH = release/v0.1.x
PRODUCTION = main / governed release
SESSIONS = disposable
WORK = durable
Gas City primitives:
| Primitive | Role |
|---|---|
Agent |
WHO performs work |
Bead |
WHAT the work is |
Formula |
HOW work is performed |
Rig |
WHERE it belongs |
Pack |
CONFIGURES behavior |
Event |
OBSERVE what happened |
Polecat, Mayor, Witness, Refinery, Dog, Deacon are Agent role patterns, not new primitives.
Window Ownership Table¶
| Window | Lane ID | Owns | Does NOT own |
|---|---|---|---|
| Blu | DIRECTOR |
Director, routing, dependency graph, P0 sequencing, cross-lane acceptance, deduplication | Implementation unless no lane owns it |
| Drupal Factory | DRUPAL_FACTORY |
Drupal CMS factory, recipes, site template, Composer/BOM, contrib-first assembly, DDEV factory proof | ContextControl-specific product work, Bluefly.io content/site changes |
| Oracle IaC Convergence | ORACLE_IAC |
Oracle capacity, Terraform/IaC, storage expansion, runner/runtime deployment convergence, immutable-runtime enforcement | App code, Drupal features |
| Fleet Posture | READ_ONLY_FLEET_OBSERVER |
Read-only health: gc doctor, disk/load/session/rig posture, alerts, evidence, drift detection |
Mutations, repairs, claiming implementation beads |
| Agent ID | IDENTITY_PROVENANCE |
Machine/service identity, Git/SSH identity, provenance, gt whoami, personal-key removal |
Secrets delivery implementation |
| Durable Work Gov | DURABLE_WORK_GOVERNANCE |
Bead lifecycle, claims, dependencies, closeout, worktree lifecycle, completion law, authority rules | Product/app features |
| BluCityPacks | GASCITY_PACK_IMPLEMENTATION |
Packs, Formulas, Orders, Events, agent-role configuration; implements governed factory behaviors | Canonical doctrine text, app implementation |
| OpenClaw | OPENCLAW |
OpenClaw gateway/runtime/config/security/channel integration only | Gas City control plane, generic agent identity |
| ContextControl | CONTEXTCONTROL |
contextcontrol-ai, Drupal human control surface, kb_cache, context-cli, dashboard/operator UX |
Generic Drupal factory or unrelated platform infra |
| Bluefly.io | BLUEFLY_IO |
Bluefly.io Drupal site, content model, Canvas/SDC, site-specific integrations | Drupal platform/factory abstractions |
| MCP | MCP_TOOL_PROTOCOL |
MCP servers/tools/registry/gateway, Tool API boundary, protocol integration | Agent orchestration or Drupal workflow ownership |
Critical boundary rules¶
Blu does not help by grabbing implementation. It routes and verifies.
Fleet Posture never fixes what it finds. It creates and routes a finding.
Durable Work Gov defines lifecycle law; BluCityPacks implements it.
Drupal Factory builds reusable Drupal capability; ContextControl and Bluefly.io consume it.
Agent ID defines identity; Oracle IaC provisions it; secrets remain owned by the security/deployment lane.
Immediate P0 Drain Order¶
Rule:
NO_NEW_P0_STARTS— drain existing P0s before opening new lanes.
1. bl-lvt / bl-l1h — Administrative convergence only¶
ENGINEERING = COMPLETE
MAYOR_ACCEPTANCE = PENDING
bl-lvt closure path:
Mayor accepts bl-lvt
→ attach acceptance receipt
→ close bl-lvt
→ evaluate bl-l1h
→ close/supersede if entire purpose was completion of bl-lvt
Do not have another agent redo the Gas City start.
2. bl-c2hgq — Topology lock verification¶
The proof already exists. Record the durable invariant and close:
CANONICAL_BEADS_AUTHORITY =
Gas City city_canonical
127.0.0.1:3308/hq
DOLTHUB_ROLE =
optional remote / collaboration / backup target
DOLTHUB_RUNTIME_AUTHORITY =
NO
3. bl-xgrcpf — Storage runway (ACTIVE P0 INFRASTRUCTURE RISK)¶
root filesystem ~98% full
Dolt journal ~21.8 GB
auto_gc_behavior disabled
manual GC prohibited without governed runway
Green gc doctor checks do not mean the host is healthy. Doctor reports topology correctness, not survival capacity.
Sequence: 1. Governed OCI storage expansion 2. Filesystem expansion 3. Supported Dolt maintenance path
Not ad-hoc cleanup. Not manual compaction. Not emergency rm.
4. bl-027agf — Secret remediation (NOT closed by containment)¶
SECRET_EXPOSURE_CONTAINED = YES
SECRET_ARCHITECTURE_FIXED = NO
EXPOSED_CREDENTIALS_ROTATED = NO
PLAINTEXT_SECRET_BUNDLE_REMOVED = NO
Remains open until file-based resolved-secret architecture is eliminated and exposed values are rotated.
5. bl-4c6i4v — Machine identity¶
Prepare, do not execute until secret-delivery substrate is stable. Replacing one bad identity scheme with another temporary credential mechanism is not remediation.
Current Fleet State¶
GATE_A_AUTHORITY = PASS
GAS_CITY_CONTROL_PLANE = PASS
BEADS_PROVIDER = PASS
RIG_BINDINGS = PASS (22/22)
EVENT_PLANE = PASS
CONFIG_VALIDATION = PASS
BL_LVT_ENGINEERING = COMPLETE
BL_LVT_GOVERNANCE = AWAITING_MAYOR_ACCEPTANCE
SECRET_CONTAINMENT = PASS
SECRET_REMEDIATION = OPEN
STORAGE_RUNWAY = BLOCKED / P0
DOLT_GC_SAFETY = BLOCKED BY STORAGE
FLEET_POLICY = NO_NEW_P0_STARTS
Factory receipt (precise language)¶
Factory work authority and Gas City control plane are converged
and operational on canonical :3308/hq.
Host survival remains DEGRADED pending governed storage expansion
and restoration of supported Dolt GC runway.
Worktree scope (never omit scope)¶
LOCAL_CANONICAL_ENGINEERING_WORKTREE_ROOT = $ESTATE_ROOT/worktrees/
LOCAL_ACTIVE_ENGINEERING_WORKTREES = 0
ORACLE_GAS_CITY_DISCOVERED_WORKTREES = 48
ORACLE_VALID = 48
Execution Directive Template¶
Paste into every window. Change only the LANE section.
ROLE¶
You are one execution lane in the Bluefly governed factory.
You are not the global coordinator. Global coordination belongs to Blu.
Your job: execute only work that belongs to your assigned lane, preserve durable state in canonical Beads, and return evidence.
LANE ASSIGNMENT¶
LANE = <WINDOW_NAME / LANE_ID from table above>
YOU OWN = <from ownership table>
NOT OWN = <from exclusions table>
If work falls outside this boundary:
- Do not implement it.
- Record the dependency/finding in the canonical Bead.
- Send evidence to Blu.
- Route to the owning lane.
- Continue with ready work inside your own lane.
Execution Law¶
1. Work must exist before execution
CLAIM → EXECUTE → DELIVER → VERIFY → CLOSEOUT
No more than one active unit of work unless the Bead explicitly defines parallel children. No speculative P0 work.
2. Preserve the work graph when blocked
record blocker
→ add dependency edge
→ update durable notes
→ route via Gas City mail/sling
→ stop mutating blocked work
3. Source workflow
claim Bead
→ fetch canonical source
→ Bead-owned worktree under $ESTATE_ROOT/worktrees/
→ implement
→ test
→ push feature branch
→ MR to release/v0.1.x
→ CI
→ merge
→ external verification
→ governed closeout
Never develop directly in canonical NAS or Oracle runtime. Never use git stash. Never use /tmp as durable workflow state.
4. Completion law
Merged ≠ done.
SUCCESS =
IMPLEMENTED
+ PUSHED
+ MR_MERGED_TO_GOVERNED_TARGET
+ EXTERNAL_VERIFICATION_PASSED
+ DURABLE_RECEIPT_RECORDED
+ WORKTREE_CLEAN
+ WORKTREE_DEREGISTERED
+ WORKTREE_REMOVED
+ BEAD_CLOSED
A worker may not manufacture its own verification evidence when independent verification is required.
Never delete: dirty work, unmerged work, open-MR work, live-session work, unknown-provenance work. Ambiguity is a finding, not a deletion.
Concurrency Law¶
NO_NEW_P0_STARTS
unless Blu explicitly routes an existing canonical P0 to this lane.
Prefer finish → verify → merge → close → clean over discover → create → expand → parallelize.
Cross-Lane Law¶
You may inspect another lane for evidence. You may not silently take ownership of its implementation.
Fleet Posture finds storage defect → route to Oracle IaC Convergence
Durable Work Gov defines lifecycle requirement → BluCityPacks implements Formula/Order
Drupal Factory creates reusable capability → ContextControl/Bluefly.io consume it
Agent ID defines machine identity contract → Oracle IaC provisions runtime identity
MCP owns protocol boundary → Drupal or OpenClaw consumes through that boundary
Evidence Rule¶
Before changing anything, classify:
PROVEN_IN_RUNTIME
CURRENT_SOURCE
CANONICAL_POLICY
CURRENT_DIRECTION
HISTORICAL
ASPIRATIONAL
UNKNOWN
Do not implement from stale prose when live source/runtime contradicts it. If a Bead's premise cannot be reproduced:
PREMISE_NOT_REPRODUCED
EVIDENCE = <what you found>
RECOMMENDED_RE-SCOPE = <route to Blu>
Communication to Blu¶
Compact receipts, not transcripts:
BEAD=
LANE=
STATE=
WHAT_CHANGED=
MR=
VERIFICATION=
BLOCKERS=
NEXT=
Escalate immediately for: security exposure, possible data loss, canonical authority conflict, destructive operation with uncertain provenance, human credential/1Password gate, irreversible infrastructure mutation.
Session End¶
Before ending:
- Update the canonical Bead.
- Push all authorized source work.
- Record MR/pipeline/verification state.
- Remove completed execution worktrees.
- Preserve unresolved state.
- Send Blu the receipt.
- Leave no undocumented local-only work.
Your session is disposable. The work graph is not.