Bluefly Platform Priorities Doctrine¶
Canonical Operating Priorities for the Bluefly.io Ecosystem¶
Scope: This doctrine sits above the technical standards catalog. It does not describe architecture, code standards, or CI mechanics — it tells BLU, MAYOR-ORACLE, and every agent what to work on next, and in what order. When this doctrine and a technical standard disagree on priority (not on technical fact), this doctrine wins. Provenance: delivered verbatim by Thomas via BLU, 2026-09-06. Landed as canonical doctrine, not a chat artifact.
Execution Coordinator: BLU Runtime Authority: MAYOR-ORACLE Source Authority: GitLab Work Authority: Gas City / Beads Documentation Authority: BluCity-Docs Secret System of Record: 1Password Primary Product Platform: Drupal CMS
1. The Goal¶
Bluefly is not trying to maximize: repositories, agents, prompts, custom services, architecture documents, open MRs, lines of code.
Bluefly is trying to build a small number of working, monetizable products on top of a functioning autonomous engineering factory.
Operating sequence: FACTORY WORKS → FACTORY BUILDS REAL PRODUCTS → PRODUCTS PROVE REPEATABLE DELIVERY → REPEATED METHODS BECOME FORMULAS/PACKS/SHARED COMPONENTS → SCALE.
Priority order: P0 Gas City/Bluefly Factory, P1 bluefly.io, P2 ContextControl.ai, P3 AMCS, P4 Estate Convergence. Everything else is subordinate unless it directly enables one of these.
2. P0 — Gas City Working on Oracle¶
CITY=blucity, RUNTIME=Oracle, CITY_PATH=/opt/bluefly/blucity,
BEADS_AUTHORITY=Oracle, DOLT_AUTHORITY=Oracle.
Gas City defines work as living outside sessions in Beads, Formulas as reusable methods that materialize work graphs, Rigs as external projects, Packs as configuration, roles as Pack-defined not hardcoded.
Required P0 outcome: ORACLE_CITY=HEALTHY, BEADS=HEALTHY,
DOLT=HEALTHY, AGENT_EXECUTION=HEALTHY, FORMULAS_EXECUTE=YES,
ORDERS_EXECUTE=YES, RIGS_RESOLVE=YES, MACHINE_IDENTITIES=WORKING,
1PASSWORD_DELIVERY=WORKING, MODEL_GATEWAY=WORKING,
REMOTE_CLIENT_ACCESS=WORKING, LOCAL_MAC_CITY_AUTHORITY=NO.
3. BluCity and BluCity-Packs¶
blueflyio/blu/blucity = Bluefly's deployed City definition.
blueflyio/blu/blucity-packs = reusable Bluefly factory behavior.
blucity stays thin — owns pack.toml, city.toml, deployment-specific
composition, truly City-local config.
blucity-packs owns reusable agents, formulas, orders, skills,
commands, doctor checks, policies, provider configuration.
Official Gas City distinguishes portable pack.toml, City-local
city.toml, machine-local .gc/site.toml.
4. One City Authority¶
ORACLE_CITY_AUTHORITY=YES, MAC_CITY_AUTHORITY=NO. The Mac is:
remote operator client, editor, browser, DDEV host, worktree execution
surface. The Mac must not own: production supervisor, canonical Beads,
canonical Dolt, long-lived factory state, unique durable work.
5. Rigs¶
A Rig is not every GitLab project. Gas City defines a Rig as an
external project (usually a Git repo) registered with the City,
receiving its own Bead namespace and agent scope. Config: city.toml
(portable Rig declaration), .gc/site.toml (local filesystem binding).
Use a Rig when a project needs independent durable engineering work, its own Bead scope, agents working directly in it, independent execution lifecycle. Do not create 100+ Rigs because 100+ repositories exist.
6. P1 — Bluefly.io Rebuild¶
Repository: blueflyio/assets/bluefly.io. Existing/live site source
(input/reference, not future architecture): blueflyio/assets/bluefly.
Rebuild uses canonical Bluefly Drupal doctrine: CORE → CONTRIB → CONFIGURATION → RECIPE → CANVAS/SDC → ECA/FLOWDROP → DRUPAL AI → TOOL API/MCP → EXISTING BLUEFLY EXTENSION → CUSTOM ONLY AFTER PROVEN GAP.
Target: Drupal CMS, current, clean, rebuildable, fast, accessible, structured, AI-ready, minimal custom code. No accumulation of old Bluefly implementation merely because it existed previously.
7. Bluefly.io Acceptance¶
Complete only when: CLEAN_COMPOSER_BUILD=YES, DRUPAL_BOOT=YES,
CONFIG_VALID=YES, RECIPES_VALID=YES, CANVAS=YES, SDC=YES,
STRUCTURED_CONTENT=YES, EDITORIAL_WORKFLOW=YES,
ACCESSIBILITY=PASS, SECURITY=PASS, AI_CONFIGURATION=VALID,
NO_UNAUTHORIZED_PROVIDER_DEPENDENCIES=YES, NO_WORKSTATION_PATHS=YES,
NO_PLAINTEXT_SECRETS=YES, CI=PASS, DEPLOYED=YES,
PUBLIC_RUNTIME_VERIFIED=YES. Green CI alone is not acceptance.
8. P2 — ContextControl.ai¶
Canonical source: blueflyio/contextcontrol.ai/contextcontrol-ai. Core
value prop: REGISTER, GOVERN, REMEMBER. Do not allow it to become
another general-purpose orchestrator, scheduler, task database, secret
store, Git replacement, or agent runtime. Gas City owns engineering
orchestration. Beads owns engineering work. ContextControl owns
governed context/memory capability.
9. P3 — AMCS¶
Canonical product sources: blueflyio/amcs/site_template_amcs,
blueflyio/agent-platform/drupal/recipes/recipe_amcs. Consumer/demo:
blueflyio/amcs/amcs-demo. Rule: DO_NOT_MANUALLY_BUILD_AMCS_IN_AMCS_DEMO
— the demo must consume the canonical product.
Product = site template + foundation recipe + recipe_amcs + theme/SDC + packaged UI capabilities. AMCS is a Drupal 11 product assembled declaratively through Recipes and Site Templates, not heavy custom PHP.
10. AMCS Product Definition¶
SITE_TEMPLATE_AMCS = installable product entry point. RECIPE_AMCS =
AMCS capability composition. FOUNDATION_RECIPE = generic Drupal
platform baseline. AGENTIC_CANVAS_THEME = theme/SDC owner.
STUDIO_UI = framework-agnostic UI source/artifact. AMCS_DEMO =
consumer/acceptance environment.
Required AMCS capabilities: Canvas, SDC, Drupal AI, AI Agents, AI Agents OSSA, AI Context, ECA, Modeler, FlowDrop, Tool API, Tool Belt, MCP, Search/RAG, roles, permissions, content model, workflow.
11. Platform-Wide Shared CI¶
Every active Bluefly project should converge on
blueflyio/gitlab_components as the reusable CI authority.
Project-specific CI only for genuinely project-specific behavior;
reusable CI belongs in gitlab_components. Shared: build, test,
Composer auth, package publication, security, release, promotion,
deployment, quality gates, runner behavior. If ten projects fail with
one signature: fix one component, retry ten projects. Do not patch ten
repositories independently.
12. GitLab Workflow¶
Correction from older draft wording — do NOT use "feature → main MR" while also maintaining "feature → release" as the engineering path. Use one clean promotion model:
FEATURE/FIX → MR → release/v0.1.x → all required pipelines pass →
release accepted → release → main promotion MR → Thomas approves when
human gate is required.
So: FEATURE_TO_MAIN=NO, FEATURE_TO_RELEASE=YES,
RELEASE_TO_MAIN=YES. Thomas approves the promotion, not every
individual implementation branch.
13. Green Does Not Mean Merge¶
PIPELINE_GREEN != AUTO_MERGE_PERMISSION. Merge requires: correct
target, correct review, required approvals, no unresolved governance
blockers, no known regression. For releases:
SOURCE_CORRECT + PIPELINE_PASS + REVIEW_PASS + PROMOTION_AUTHORIZED,
then merge.
14. No Broken MR Estate¶
Target is not literally zero failing MRs at every instant — there will
always be legitimate WIP. Correct target: NO_UNOWNED_BROKEN_MRS=YES,
NO_UNKNOWN_FAILURE_SIGNATURES=YES, NO_STALE_ABANDONED_MRS=YES.
Every broken MR must be owned, classified, routed, or intentionally
closed. BLU/REFINERY converge failures by signature rather than
rediscovering them individually.
15. Agents Use One Durable Work Graph¶
WORK_AUTHORITY=ORACLE_BEADS. Agents use blu → Gas City API/context
→ Oracle → Beads. No separate local Beads universe, no local agent task
tracker, no private agent TODO database, no chat-only assignment. Gas
City makes Beads durable ground truth; sessions are disposable.
16. blu CLI¶
blu stays a thin Bluefly governance/operator layer, not another
orchestrator. Desired: authenticate/identify, select City/Rig/context,
call supported Gas City/Bluefly APIs, expose governed UX. Not:
duplicate Formula engine, duplicate scheduler, duplicate Beads,
duplicate Gas City API. blu-cli is the operator surface wrapping Gas
City, not replacing it.
17. Self-Hosted Models¶
Default: use a self-hosted model when quality sufficient, latency acceptable, security appropriate, required tools work. Do not self-host ideologically. Routing optimizes quality, cost, latency, privacy, capability. A cheap model causing repeated failures is not cheaper. Policy: self-hosted default → escalate to a frontier model only when task complexity/quality requires it.
18. Agent Provider Readiness¶
Every role needs a capability contract, e.g. FOUNDRY requires: shell, git, worktrees, source editing, GitLab push, MR creation, CI inspection. A session lacking those isn't healthy for that role. Contract shape: ROLE → REQUIRED CAPABILITIES → PROVIDER → MACHINE IDENTITY → READINESS PROBE → READY. Do not let incapable sessions sit idle for days asking Thomas to reconnect them.
19. Custom Service Standard¶
No custom service without a contract: SERVICE, INTERFACE,
CONFIGURATION, HANDLERS, OWNER, CONSUMERS, AUTH_MODEL, OBSERVABILITY,
TESTS, FAILURE_SEMANTICS, DELETION_TRIGGER. Rule: NO_INTERFACE =
NO_SERVICE. Before creating: does upstream already provide this? Does
Drupal already provide this? Does Gas City already provide this? Does
GitLab already provide this? Can configuration solve it? Can an
existing service be extended? Only create after a proven gap.
20. API-First Execution¶
Use existing APIs/services/shared components before creating new
scripts, services, databases, or side paths. API_FIRST=YES,
FILESYSTEM_COUPLING=AVOID, DIRECT_DATABASE_COUPLING=AVOID,
CUSTOM_SCRIPT_AS_API_REPLACEMENT=NO. For every service: interface
first, implementation second.
21. Studio-UI Is the Shared Interface System¶
Studio-UI is a shared UI product, not copied into individual applications. Architecture: Studio-UI = reusable framework-agnostic component library; Drupal → SDC/integration adapter; Next.js → native adapter; React dashboard → native adapter; other client → appropriate adapter. Do not fork components per product, copy UI source into apps, create a Drupal-only Studio UI fork, or create a dashboard-only duplicate. Each framework gets an adapter; the component contract stays shared.
22. Studio-UI Interface Rule¶
Check Studio-UI first for new human-facing interfaces. If it contains the component, use it. If close, extend Studio-UI. Only create product-local UI when the capability genuinely belongs only to that product. Shared: buttons, forms, cards, navigation, tables, dialogs, agent UI, status components, dashboard primitives, layout primitives — converge toward Studio-UI.
23. Documentation Is a Product Surface¶
Documentation is currently an operational risk because contradictory
doctrine changes agent behavior. Older master documents contain
valuable research but also stale material (old Gas City runtime
assumptions, historical Oracle topologies) — the July research still
contains multiple conflicting descriptions of Gas City/Gas City and old
runtime models. Therefore: DOCUMENTATION_CONVERGENCE=P0_GOVERNANCE.
24. One Documentation Authority¶
Canonical Bluefly engineering doctrine lives in BluCity-Docs. Project docs may contain project-specific contracts, README, setup, API usage, project architecture — but must point back to canonical Bluefly doctrine instead of copying it. Google Docs become working research, strategy, drafting, historical input — not a competing engineering authority.
25. Google Docs Consolidation¶
Listed docs: Bluefly_Gas_City_Drupal_Product_Factory_Research_2026-07-22,
MASTER-BLUEFLY-AGENT-FACTORY, GasCity/BluTown material,
Building_in_Drupal_The_2026_Way. These should NOT all remain active
canonical instructions. Classify each as: research source, historical,
superseded, active strategy, or canonical doctrine. The two attached
Google docs contain substantial duplicated/contradictory material — one
section says Gas City roles are configuration while other sections
still describe Gas City as the active runtime. Consolidation must
extract surviving intent, not simply merge documents together.
Classification (landed here; Google Docs' own headers are a separate follow-up, not a blocker — see Note below):
| Document | Classification |
|---|---|
MASTER-BLUEFLY-AGENT-FACTORY |
RESEARCH / INPUT — not canonical |
Bluefly_Gas_City_Drupal_Product_Factory_Research_2026-07-22 |
RESEARCH / HISTORICAL — contains known contradictions on Gas City vs Gas City runtime; superseded by Gas City architecture and this doctrine |
| GasCity/BluTown material | HISTORICAL / SUPERSEDED — Gas City terminology superseded by Gas City; BluTown persona superseded by BluCity (see gc-cities.md) |
Building_in_Drupal_The_2026_Way |
RESEARCH / INPUT — not canonical; canonical Drupal doctrine is drupal-standard.md |
Note (follow-up, not a blocker): Bluefly does not have write access to edit these Google Docs directly from BluCity-Docs tooling. This table is the authoritative classification. Flagging to Thomas separately: the Google Docs' own headers should eventually be updated to point here and self-identify as non-canonical, so a reader opening the doc directly (not via BluCity-Docs) doesn't mistake it for current doctrine.
26. Documentation Precedence¶
Intent: Thomas's current intent → current Bluefly doctrine → historical strategy.
Technical fact: current upstream authority → current GitLab source → authoritative runtime evidence → current Bluefly doctrine → historical docs → agent memory.
This prevents old Google Docs from overriding current Gas City behavior.
27. Documentation Consolidation Workflow¶
For every subject: search current docs, identify active owner, identify duplicates, verify upstream facts, verify current Bluefly source, verify runtime if relevant, preserve unique intent, update one owner, archive/retire duplicates, update indexes, MR, verify a second agent resolves the correct answer. Do not create a new standard until existing owners have been searched.
28. Documentation Subjects to Converge¶
14 subjects, not 40 overlapping manifestos. This doctrine (#1) is landed; the remaining 13 are the target list for future convergence passes — not built now, so nobody reinvents this list:
- Bluefly Platform Priorities (this doc)
- Gas City Operating Standard
- City/Rig/Pack Model
- Authentication & Secrets Constitution
- Drupal CMS Product Doctrine
- AMCS Product Composition Doctrine
- Source/Runtime Convergence
- GitLab Delivery/Release Standard
- Machine Identity Standard
- Backup/Restore Contract
- Shared CI Standard
- Studio-UI Interface Standard
- Documentation Governance
- Failure Signature Catalog
29. WITNESS and REFINERY Own Documentation Convergence¶
WITNESS = detect contradictions, verify technical facts, identify stale doctrine, read-only. BLU = resolve architecture/policy ownership. REFINERY = consolidate docs, update owner, retire duplicates, repair references, push MR. No agent independently creates "the new canonical architecture" because it found an old document.
30. Project Documentation Rule¶
Every project needs only what it requires: README.md, AGENTS.md, API/interface docs, project-specific architecture, testing/build docs. AGENTS.md navigates agents to canonical doctrine — it does not duplicate entire Bluefly standards. E.g.: for Bluefly engineering policy → BluCity-Docs; for Drupal → Building in Drupal doctrine; for auth → Authentication & Secrets Constitution; for Gas City → Gas City Operating Standard.
31. Google Drive Rule¶
Google Drive is for research, strategy, business docs, drafting, meeting notes, long-form analysis — not the source of runtime engineering truth. Final technical doctrine converges into GitLab/BluCity-Docs. Google documents may link to final doctrine or be labeled research/superseded/archive.
32. Source/Runtime Law¶
Recurring failure: source says one thing, Oracle runs another. Lock:
SOURCE_CORRECT != DONE. Terminal acceptance: SOURCE_CORRECT=YES,
CI=PASS, MERGED=YES, DEPLOYED=YES,
AUTHORITATIVE_RUNTIME_VERIFIED=YES. Only then close runtime-impacting
work.
33. Infrastructure Law¶
No manual infrastructure architecture: GitLab → IaC → Oracle. Manual
SSH only for read-only diagnosis or emergency evidence collection, not
to establish final desired state. If the only way to fix production is
SSH → edit file, that's SOURCE_RUNTIME_CONVERGENCE_FAILURE=YES — fix
source/IaC instead.
34. Net-Negative Ownership¶
Every technical decision asks: what can we delete? What can upstream own? What can configuration own? What can a shared component own? What can a Recipe own? What can a Pack own? Composition over implementation, Drupal as crystallized knowledge — one of the strongest Bluefly principles.
35. Current Priority Board¶
BLUEFLY PLATFORM PRIORITY BOARD
P0 — FACTORY: GASCITY_ORACLE, BLUCITY, BLUCITY_PACKS, BEADS_DOLT, AGENT_EXECUTION, REMOTE_CLIENT, MACHINE_IDENTITIES, SELF_HOSTED_MODELS, BACKUP_RESTORE
P1 — BLUEFLY.IO: SOURCE, OLD_SITE_REFERENCE, DRUPAL_BUILD, COMPOSER, CONTENT_MODEL, CANVAS_SDC, STUDIO_UI, AI, CI, DEPLOY, PUBLIC_ACCEPTANCE
P2 — CONTEXTCONTROL.AI: SOURCE, MVP, BUILD, INTERFACES, STUDIO_UI, CI, DEPLOY, PRODUCT_ACCEPTANCE
P3 — AMCS: SITE_TEMPLATE, RECIPE_AMCS, FOUNDATION_RECIPE, THEME, STUDIO_UI, COMPOSER, CANVAS_SDC, AI, ECA_FLOWDROP, TOOL_API, MCP, FRESH_CREATE_PROJECT, DEMO_CONSUMER_PROOF
P4 — ESTATE: SHARED_CI_ADOPTION, OPEN_MRS, UNKNOWN_FAILURES, BROKEN_PIPELINES, DOC_CONTRADICTIONS, AGENT_IDENTITY_GAPS, LOCAL_AUTHORITY_COPIES
36. Work Selection Rule¶
BLU chooses work in this order: 1. Does it unblock P0? 2. Does it directly move P1? 3. Does it directly move P2? 4. Does it directly move P3? 5. Does it eliminate an estate-wide blocker affecting these? 6. Otherwise: defer.
Prevents spending two days on an unrelated dashboard while bluefly.io doesn't build.
37. Agents Do Not Invent Busywork¶
Keep ready work moving, not keep every agent busy. Idle workers are acceptable. Unowned ready work is not. Gas City's orchestrator fans out ready Beads and blocks work until dependencies close.
38. Factory Promotion Rule¶
Evaluate every manual solution afterward: would we run this again? If
yes, encode a Formula, run again. If proven across multiple Rigs,
promote into a Pack. If reusable CI, promote into gitlab_components.
If Drupal product composition, promote into a Recipe/Site Template.
39. Final Operating Law¶
THOMAS SETS BUSINESS AND PRODUCT INTENT. BLU PRIORITIZES THE PORTFOLIO AND IMPROVES THE FACTORY. MAYOR-ORACLE OPERATES THE AUTHORITATIVE FACTORY. GAS CITY ORCHESTRATES. BEADS HOLDS DURABLE WORK. FORMULAS HOLD REPEATABLE METHODS. RIGS DEFINE ENGINEERING WORK DOMAINS. PACKS CARRY PROVEN FACTORY BEHAVIOR. GITLAB OWNS SOURCE, CI, PACKAGES, AND RELEASE. GITLAB_COMPONENTS OWNS SHARED CI. ORACLE OWNS FACTORY RUNTIME. NAS OWNS DURABILITY AND RESTORE EVIDENCE. 1PASSWORD STORES AND DELIVERS SECRETS. TARGET SYSTEMS AUTHORIZE AND ROTATE CREDENTIALS. DRUPAL OWNS DRUPAL PRODUCT BEHAVIOR. DDEV PROVES DRUPAL LOCALLY. STUDIO_UI OWNS SHARED HUMAN INTERFACE COMPONENTS. BLUCITY-DOCS OWNS BLUEFLY ENGINEERING DOCTRINE. GOOGLE DRIVE HOLDS RESEARCH AND STRATEGY, NOT COMPETING RUNTIME TRUTH. CUSTOM SERVICES REQUIRE AN INTERFACE. CUSTOM CODE REQUIRES A PROVEN GAP. CHAT IS NOT THE WORK GRAPH. LOCAL MACHINE STATE IS NOT AUTHORITY. GREEN CI IS NOT PRODUCT ACCEPTANCE. MERGED IS NOT DEPLOYED. DEPLOYED IS NOT HEALTHY.
PROVE SMALL. LEARN. ENCODE. REPEAT. SCALE. OWN LESS. SHIP THE PRODUCTS.