Skip to content

Engineering Standard knowledge map (2026-07-28 snapshot)

Recovered from workstation Scratch on 2026-08-27. This is a dated corpus map, not a replacement for BLU-BIBLE. Treat live catalogs, ADRs, and the authentication constitution as CURRENT.


Bluefly.io Engineering Standard — Knowledge Map

Corpus: /Volumes/AgentPlatform/BluCity-Docs/Engineering-Standard/ Analysis date: 2026-07-28 Documents analyzed: ~70+ across 13 subdirectories Evidence basis: All claims derived from observed document content. No speculative or inferred standards.


1. Executive Overview

The Engineering Standard is a constitution-rooted governance framework for the Bluefly.io Agent Platform. It governs ~70+ documents across 13 directories, organized around a single axiom: "Bluefly owns composition, not implementation."

The corpus operates as a four-layer enforcement stack:

  1. Constitutional — The axiom plus the Standards Retention Rule (supersede, never delete). Root authority: governance/constitution.md.
  2. Lane Control — Four product lanes with hard boundaries, enforced by a 12-field BOUNDARY_CHECK and 6 failure codes. Binding standing instruction: bluefly-lane-control-standing-instruction.md.
  3. Artifact & Documentation Discipline — Every artifact requires Owner/Consumer/Lifetime/Replacement (4-field gate). Documentation follows a 3-layer hierarchy: BluCity-Docs → .agents/context → Task Context.
  4. Deployment Immutability — Release Bundles are the sole deployment artifact. Violations trigger destroy-and-reprovision. No SSH, no manual runtime mutation.

The framework is epistemologically self-aware: it defines its own evidence classification (OBSERVED → INFERRED → VERIFIED), decision vocabulary (closed terminal states), and investigation methodology (gate-ordered, 6-phase execution). This is unusual and intentional — it was built to govern AI agent behavior, not just human engineering practice.

Maturity assessment: The governance and rules layers are operationally mature — binding, versioned, with enforcement mechanisms. The standards layer is structurally complete but has significant status gaps: foundational epistemological documents remain "proposed" while downstream canonical standards depend on them. The ADR system is active (20 records) but 9 remain unresolved. Infrastructure and integration layers are the weakest — integration/ is empty, inference routing is broken, and several operational models are candidates without decisions.


2. Taxonomy of Standards

2.1 Classification by Authority Level

Level Count Description
BINDING 7 Enforceable rules with violation consequences. Versioned, with Standard IDs.
Canonical 12 Authoritative definitions accepted as standard practice.
Implicit Canonical 9 Treated as canonical by reference but lacking formal acceptance marker.
Authoritative 5 Trusted operational documents with production evidence.
Proposed 8 Formally structured but awaiting acceptance decision.
Candidate/Draft 4 Under consideration, no commitment.
Informational 3 Reference material, non-normative.
Empty/Placeholder 5 Created but contain no content.
Superseded/Redirect 4 Replaced by newer documents.

2.2 Classification by Domain

Governance (6 documents) Core governance framework: constitution, canonical index, lane control, governance plan lifecycle, Cloudflare tunnel inventory, GitLab env-split runbook. Plus 4 empty placeholders (archive-index, engineering-standard-index, folder-ownership-matrix, ownership-matrix).

Rules (5 documents) Binding operational rules: artifact production (ES-APR), deployment contract (ES-DEPLOY), deployment rule (ES-DEPLOY — duplicate ID), documentation production, git completion contract (ES-GITCC).

Architecture (3 documents) Factory operating contract (master governance, freeze gates), Gas City master spec (SDK with production evidence), Oracle canonical architecture (artifact-consumer-only constraint).

Decision Records (20 documents) ADR-0001 through ADR-0017 plus lowercase variants adr-0001, adr-0002. Statuses: 5 accepted, 8 proposed, 3 candidate/open, 2 unknown, 2 conflicting.

Standards (19 documents) Root engineering standard (ES-0001), agent contract, evidence contract, decision vocabulary, deployment standard, documentation governance, Drupal standard, DDEV standard, execution receipt specification, Gas City worker contract, git standard, investigation methodology, lockdown standard, runtime dependency investigation, execution environment constitution, tools standard, upstream synchronization, capability convergence, inference topology.

Infrastructure (4 documents) Configuration compiler, NAS operational model, private factory build guide, Terraform operational model.

Platform (4 documents) Platform boundaries, platform reset standard, platform reset v1 (superseded redirect), repository classification.

Operating Model (2 documents) Blu execution model (supersedes 4 prior docs), Blu identity constitution (supersedes 5 prior docs).

Verification (2 documents) Definition of Done (11-step gate), verification ledger (14 tracked claims).

Reference (8 documents) Upstream architectural reference (architectural spine), Bluefly reference architecture, CLI resources, DDEV reference, workspace layout, terminology migration, addon reference catalog, Ralph Wiggum reference (execution runtime).

Indexes (1 document) BLU-BIBLE — constitutional navigation hub.

Glossary (1 document) Platform glossary — normative vocabulary with 3-plane architecture.

Integration (0 documents) Directory exists. Empty.


3. Canonical Document Index

3.1 Governance

Document Standard ID Status Purpose Dependencies Supersedes
governance/constitution.md — Canonical Root authority. Composition axiom. Standards Retention Rule. None (root) —
governance/canonical-index.md — Canonical Master TOC linking 4 corpus sections. constitution.md —
governance/lanes-governance/README.md — Canonical Governance plan lifecycle: draft → proposed → accepted → implementing → implemented → superseded → rejected. constitution.md —
governance/platform-governance/bluefly-lane-control-standing-instruction.md — BINDING (2026-05-18) 4 product lanes, 10 global rules, 12-field BOUNDARY_CHECK, 6 failure codes. Most operationally detailed governance doc. constitution.md, canonical-index.md —
governance/platform-governance/Cloudflare Tunnel Route Inventory.md — Informational 8+ tunnel domains, ~96 routes, ~50 port mappings, fail-closed 404. — —
governance/platform-governance/gitlab-env-split-runbook.md — ready_for_operator 1Password env split for broken COMPOSER_AUTH. tools-standard.md —

Empty placeholders: archive-index.md, engineering-standard-index.md, folder-ownership-matrix.md, ownership-matrix.md

3.2 Rules

Document Standard ID Status Purpose Dependencies Supersedes
rules/artifact-production-rule.md ES-APR BINDING v2.0.0 (2026-07-19) 4-field gate (Owner/Consumer/Lifetime/Replacement). 3 gate questions. constitution.md v1.0.0
rules/deployment-contract.md ES-DEPLOY BINDING Immutable deployment axiom. 6 prohibited actions. Destroy-and-reprovision on violation. constitution.md —
rules/deployment-rule.md ES-DEPLOY BINDING (2026-07-21) Near-identical to deployment-contract.md but adds artifact metadata block. constitution.md Should supersede deployment-contract.md
rules/documentation-production-rule.md — BINDING 3-layer hierarchy: BluCity-Docs → .agents/context → Task Context. constitution.md, artifact-production-rule.md —
rules/git-completion-contract.md ES-GITCC BINDING (updated 2026-09-10) Hard completion law: implemented + tested + committed + pushed + MR to release/v0.1.x + CI + merged + verified + worktree cleaned + bead reconciled. BLOCKED on push/MR/merge failure. git-discipline.md weaker “push = complete” reading

3.3 Architecture

Document Standard ID Status Purpose Dependencies Supersedes
architecture/bluefly-factory-operating-contract.md — REVIEW (freeze_ready: false) Master governance contract. 11 platform authorities. 4 state classes. 3 freeze gates (none met). constitution.md, ES-0001 —
architecture/gas-city-master-spec.md — Authoritative Gas City SDK spec. PackV2 layout. Production evidence: 8 rigs, gc doctor passing. — —
architecture/oracle-architecture.md — Authoritative Oracle = artifact consumer only. 2 permitted git checkouts. RTO < 15min. deployment-contract.md —
architecture/capability-convergence.md — Canonical Central convergence invariant. 6-level ownership resolution. ES-0001 —
architecture/inference-topology.md — Proposed LiteLLM routing. All replacement decisions UNKNOWN. Inference broken. — —

3.4 Decision Records

ADR Title Status Key Decision Blockers/Notes
ADR-0001 Establish governance repo Proposed — —
ADR-0002 Runtime capability baseline Proposed N unmeasurable blu work current fails
ADR-0003 Logical authorities over path coupling Accepted Portable identifiers, not filesystem paths —
ADR-0004 Consume ContractPlane as service Proposed GOVERNANCE DECISION REQUIRED Blocked on decision
ADR-0005 Evaluator pattern (read-only governance) Accepted — —
ADR-0006 Mac laptop purge / NAS-centric layout Proposed — —
ADR-0007 Operational work system of record Candidate Beads+Dolt Decision UNKNOWN — significant gap
ADR-0008 Upstream authority location Candidate — OPEN
ADR-0010 Repository governance authority Accepted blu repos receipt-chain 147 repos require processing
ADR-0011 Oracle upstream convergence Proposed Gas City live on 20+ rigs CONFLICTS with adr-0001
ADR-0012 Adopt OpenTofu for IaC Accepted — —
ADR-0013 Repository reset state machine Proposed — —
ADR-0014 Gas City IaC deployment Proposed — ~234 lines
ADR-0015 Skills dissolution into PackV2 Accepted (direction) Most thoroughly evidenced ADR 1,152 gitleaks findings block Stage 4+
ADR-0016 SSHless deployment architecture Proposed Aspirational No receipt gates
ADR-0017 Repository capability convergence audit Proposed 33 Drupal modules dispositioned —
adr-0001 Gas City foundation Accepted Gas City = optional peer CONTRADICTED by ADR-0011
adr-0002 Repository authority model (4 authorities) Accepted Dev/Source/Deploy/Recovery —

3.5 Standards

Document Standard ID Status Purpose Dependencies
es-0001-bluefly-engineering-standard.md ES-0001 Active Root standard. 4-layer runtime. Domain compilation table. 4 Repository Authorities. constitution.md
agent-contract-standard.md — Implicit Canonical .agents/ directory contract. ES-0001
Evidence-Contract.md — Proposed 5-section evidence discipline. 8 core rules. None (foundational)
decision-vocabulary.md — Proposed Closed terminal-state vocabulary. Evidence-Contract.md
deployment-standard.md — BINDING Release Bundle as sole artifact. 41 lines. ES-DEPLOY
documentation-governance-standard.md — Implicit Canonical 6 permitted doc locations. 11 lifecycle states. documentation-production-rule.md
drupal-standard.md — Implicit Canonical Drupal as AI orchestration layer. Contrib-first. ES-0001
ddev-standard.md — REQUIRED DDEV conventions. drupal-standard.md
execution-receipt-specification.md — Proposed v1.0 17-section receipt structure. 11-item quality gate. Evidence-Contract.md
gascity-worker-contract.md — Implicit Canonical OpenClaw worker execution contract. bd prime recovers context; session work discovery is gc hook. beads-work-ownership-contract.md, gas-city-master-spec.md
git-standard.md — Canonical Repository model. Rebase-first. SemVer. ES-0001
investigation-methodology.md — Proposed Gate order. 6-phase execution. Evidence-Contract.md
lockdown-standard.md — Implicit Canonical Claude Code 5-priority governance stack. P0 managed-settings.json → P4 Delivery Pressure Hooks. —
runtime-dependency-investigation.md — Canonical Evidence classification. Decision tree. Evidence-Contract.md
std-exec-001-execution-environment-constitution.md — Frozen v1.0 14-level execution order of precedence. constitution.md
tools-standard.md — Canonical Tool Authority Index. 1Password P0 rules. ES-0001
upstream-synchronization-standard.md — Implicit Canonical 6-phase Upstream Capability Admission Gate. capability-convergence.md

3.6 Infrastructure

Document Status Purpose
configuration-compiler-v1.0.md Implicit Canonical 5-stage deterministic pipeline. Immutable lockfiles.
nas-operational-model.md Authoritative NAS mirrors GitLab. NEVER git over SMB.
private-factory-build-guide.md Draft Home AI box spec. Not yet implemented.
terraform-operational-model.md Candidate Local plan only. Apply via pipeline.

3.7 Platform

Document Status Purpose
platform-boundaries.md Implicit Canonical Per-repo boundary table (Owns/Consumes/Produces/Layer).
platform-reset-standard.md Active Repository Context Model. Knowledge Ownership Hierarchy.
platform-reset-v1.md Superseded Redirect stub → platform-reset-standard.md
repository-classification.md Implicit Canonical 7 repo categories. Composition map.

3.8 Operating Model

Document Status Purpose Supersedes
blu-execution-model.md Authoritative (2026-07-23) 3-stage lifecycle. 7 Platform Authorities Matrix. 4 prior docs
blu-identity-constitution.md Authoritative (2026-07-23) 3 prime directives: Net Negative Ownership, Evidence-First, No Unauthorized Mutations. 5 prior docs

3.9 Verification

Document Status Purpose
Definition-of-Done.md Canonical 11-step lifecycle gate.
verification-ledger.md Living document 14 claims tracked. 2 at "Planned" (V10, V14).

3.10 Reference

Document ID Purpose
upstream-architectural-reference.md REF-UPSTREAM Architectural spine. 5-layer authority hierarchy. 6 platform ledgers. 3 operational modes. PackV2 layout. "Never Build This Again" classification. 431 lines.
bluefly-reference-architecture.md ES-REF-ARCH Factory runtime topology. 6 authorities mapped to infrastructure.
cli-resources-reference.md REF-CLI CLI authority index. Anti-duplication policy.
ralph-wiggum-reference.md REF-RALPH Bluefly Execution Runtime (BER). Deterministic agent runtime. Self-flagged for rewrite.
addon-reference-catalog.md — DDEV add-on classification (~200 add-ons). Governance disguised as catalog.
terminology-migration-list.md — Stale terminology tracker. 26+ unscanned sources acknowledged.
workspace-layout-reference.md — Non-normative OSSA workspace examples.
official-ddev-reference.md — Upstream-only link catalog. Minimal.

3.11 Indexes & Glossary

Document Status Purpose
authority/agent-team.md Canonical Constitutional index. Master navigation hub.
glossary/platform-glossary.md Canonical by usage Normative vocabulary. 3-plane architecture.

4. Duplicate or Conflicting Standards

4.1 CRITICAL — Standard ID Collision

deployment-contract.md and deployment-rule.md both carry Standard ID ES-DEPLOY.

This violates the single-document principle. Content is near-identical, but deployment-rule.md (2026-07-21) adds an artifact metadata block and is newer. deployment-rule.md should supersede deployment-contract.md under the Standards Retention Rule.

Resolution: Supersede deployment-contract.md. Update all references to point to deployment-rule.md.

4.2 CRITICAL — Gas City Dependency Contradiction

adr-0001 (lowercase, Accepted): Gas City is an "optional peer" — Gas City stands alone. ADR-0011 (uppercase, Proposed): Gas City is "operationally live on 20+ rigs" while Gas City data plane is dead.

These are irreconcilable. Production reality (ADR-0011) contradicts the foundational architecture decision (adr-0001). This needs a governance decision: either Gas City's operational status elevates it from "optional" to "required" (superseding adr-0001), or the 20+ rigs are running in a non-canonical configuration.

4.3 HIGH — ADR Numbering Collision

ADR-0001 and adr-0001 are different documents with different content. Same for ADR-0002 and adr-0002. The naming scheme does not disambiguate. One set should be renumbered or the lowercase series should be given a distinct prefix.

4.4 HIGH — Upstream Capability Gate Duplication

upstream-synchronization-standard.md defines a 6-phase Upstream Capability Admission Gate. architecture/capability-convergence.md defines a 6-level ownership resolution with overlapping scope. Both govern how upstream capabilities are evaluated and admitted. The boundary between them is unclear.

Resolution: Determine which document is authoritative for upstream admission decisions. Supersede the other or narrow its scope to a distinct concern.

4.5 MEDIUM — Documentation vs Repository Context Overlap

documentation-governance-standard.md (6 permitted doc locations, 11 lifecycle states) and platform-reset-standard.md (Repository Context Model, Knowledge Ownership Hierarchy) both govern where and how documentation lives. Their scopes overlap in the area of repository-level documentation placement.

4.6 MEDIUM — Supersession Claims Without Formal Markers

blu-execution-model.md claims to supersede 4 prior documents. blu-identity-constitution.md claims to supersede 5 prior documents. Neither lists the specific document identifiers of what they supersede. Under the Standards Retention Rule, superseded documents should be marked, not deleted — but without explicit identifiers, the supersession chain is unverifiable.


5. Missing Areas — No Documented Standard

5.1 CRITICAL

Integration contracts. The integration/ directory exists and is empty. There are no formalized standards for how Bluefly components integrate with each other or with external systems. Given that the platform axiom is "composition, not implementation," the absence of integration standards is the single largest structural gap in the corpus.

Ownership matrix. governance/ownership-matrix.md and governance/folder-ownership-matrix.md are empty placeholders. The corpus repeatedly references ownership as a governing concept (4-field artifact gate, Repository Authorities, capability convergence) but has no canonical ownership registry. Individual documents contain per-repo boundary tables, but there is no master.

Operational work system of record. ADR-0007 (Beads+Dolt) is at "Candidate" with decision UNKNOWN. The entire execution receipt system depends on a functioning work system of record. Without this decision, receipts have no canonical persistence layer.

5.2 HIGH

Epistemological foundation status. Evidence-Contract.md, decision-vocabulary.md, execution-receipt-specification.md, and investigation-methodology.md form a closed reasoning system that the rest of the corpus depends on. All four remain "Proposed." They should be the first documents formally accepted — other canonical standards cite them as dependencies.

Inference routing. inference-topology.md documents LiteLLM routing but all replacement decisions are UNKNOWN and inference is broken. There is no standard for how the platform routes LLM requests, which is a critical runtime capability for an AI agent platform.

Archive index and engineering-standard-index. Both are empty. The corpus has no machine-readable catalog of itself. governance/documentation-inventory.md was auto-generated on 2026-07-23 but is static and will drift.

5.3 MEDIUM

Testing standard. No document governs testing methodology, coverage requirements, or test infrastructure. The Definition-of-Done references testing but doesn't specify how.

Monitoring and observability standard. No document governs metrics, logging, alerting, or SLO definitions despite the platform running production services.

Secret management standard. tools-standard.md covers 1Password P0 rules and lockdown-standard.md covers Claude Code governance, but there is no unified secret management standard covering rotation, emergency procedures, and cross-system secret lifecycle.

Incident response. No documented incident response procedure or escalation framework.

Onboarding procedure. No documented process for bringing a new engineer (human or agent) into the platform with appropriate authority and context.


6. Cross-Reference Map

6.1 Authority Chain (top-down)

constitution.md
├── canonical-index.md
├── bluefly-lane-control-standing-instruction.md
├── es-0001-bluefly-engineering-standard.md
│   ├── git-standard.md
│   │   └── git-completion-contract.md (ES-GITCC)
│   ├── tools-standard.md
│   ├── drupal-standard.md
│   │   └── ddev-standard.md
│   ├── platform-boundaries.md
│   ├── repository-classification.md
│   └── agent-contract-standard.md
├── artifact-production-rule.md (ES-APR)
│   └── documentation-production-rule.md
│       └── documentation-governance-standard.md
├── deployment-contract.md / deployment-rule.md (ES-DEPLOY) ← COLLISION
│   ├── deployment-standard.md
│   └── oracle-architecture.md
└── std-exec-001-execution-environment-constitution.md (Frozen)
    └── lockdown-standard.md

6.2 Epistemological Chain (closed reasoning system)

Evidence-Contract.md (Proposed — should be Canonical)
├── decision-vocabulary.md (Proposed)
├── investigation-methodology.md (Proposed)
├── runtime-dependency-investigation.md (Canonical)
└── execution-receipt-specification.md (Proposed v1.0)
    └── verification-ledger.md (Living)
        └── Definition-of-Done.md (Canonical)

6.3 Architecture Dependencies

gas-city-master-spec.md
├── gascity-worker-contract.md
├── capability-convergence.md ←→ upstream-synchronization-standard.md (OVERLAP)
└── configuration-compiler-v1.0.md

bluefly-factory-operating-contract.md
├── 11 platform authorities (references ES-0001, constitution)
└── 3 freeze gates (none met)

oracle-architecture.md
├── deployment-contract.md
├── nas-operational-model.md
└── terraform-operational-model.md

6.4 Operating Model Dependencies

blu-execution-model.md (Authoritative, 2026-07-23)
├── supersedes 4 prior docs (unidentified)
├── references: Evidence-Contract, execution-receipt-specification
└── 7 Platform Authorities Matrix

blu-identity-constitution.md (Authoritative, 2026-07-23)
├── supersedes 5 prior docs (unidentified)
└── 3 prime directives → net-negative-ownership, evidence-first, no unauthorized mutations

6.5 Reference Spine

upstream-architectural-reference.md (REF-UPSTREAM, 431 lines)
├── 5-layer authority hierarchy
├── 6 platform ledgers
├── 3 operational modes
├── PackV2 layout
└── "Never Build This Again" classification

bluefly-reference-architecture.md (ES-REF-ARCH)
└── Factory runtime topology, 6 authorities → infrastructure mapping

agent-team.md (Index)
└── Constitutional navigation hub → all sections

7. Recommendations

All recommendations are derived from observed evidence. No speculative standards are proposed.

7.1 Resolve Immediately

  1. Supersede deployment-contract.md with deployment-rule.md. Both carry ES-DEPLOY. The newer document (2026-07-21) is more complete. Mark the older as superseded per the Standards Retention Rule.

  2. Resolve Gas City dependency status. The adr-0001/ADR-0011 contradiction is load-bearing: it determines whether Gas City is an optional optimization or a required runtime dependency. Production evidence (20+ rigs) suggests the latter. Issue a governance decision and supersede one ADR.

  3. Renumber the lowercase ADR series. adr-0001/adr-0002 collide with ADR-0001/ADR-0002. Assign distinct identifiers to eliminate ambiguity.

7.2 Resolve This Quarter

  1. Accept the epistemological standards. Evidence-Contract.md, decision-vocabulary.md, investigation-methodology.md, and execution-receipt-specification.md are foundational — canonical standards already depend on them. Their "Proposed" status creates an inverted dependency: binding rules cite proposed foundations. Formal acceptance would close this structural gap.

  2. Decide ADR-0007 (operational work system of record). The receipt-driven execution model requires a canonical persistence layer. Beads+Dolt is the candidate. Without this decision, execution receipts have no defined storage.

  3. Populate integration/. The composition axiom demands integration contracts. Start with the highest-traffic integration boundaries: Drupal ↔ ContractPlane, GitLab CI ↔ Gas City, NAS ↔ GitLab mirroring.

  4. Build the ownership matrix. Populate governance/ownership-matrix.md from the per-document boundary tables that already exist in platform-boundaries.md, repository-classification.md, and the operating model. The data exists; it needs consolidation.

  5. Clarify the upstream admission gate boundary. upstream-synchronization-standard.md and capability-convergence.md both govern upstream capability evaluation. Define which is authoritative and narrow the other's scope.

7.3 Track

  1. Add explicit supersession identifiers. blu-execution-model.md and blu-identity-constitution.md claim to supersede 9 combined prior documents without naming them. Add identifiers so the supersession chain is auditable.

  2. Decide ADR-0004 (ContractPlane as service). Flagged as requiring a governance decision. This determines the consumption model for the control plane.

  3. Resolve inference topology. The current document acknowledges all replacement decisions are UNKNOWN and the system is broken. Either issue decisions or mark the document as superseded if the architecture has moved on.

  4. Auto-generate the documentation inventory. governance/documentation-inventory.md is a point-in-time snapshot. Without automated regeneration, it will drift from the corpus. Consider a CI job or bead that regenerates it from the filesystem.


Appendix A: Evidence States Observed

The corpus uses the following evidence states, documented here for reader orientation:

State Meaning
OBSERVED Directly verified in the document corpus
SUPPORTED Supported by multiple corroborating documents
TARGET Design intent, not yet verified as operational

All claims in this knowledge map are OBSERVED unless explicitly marked otherwise.

Appendix B: Document Counts by Directory

Directory Files Empty
governance/ 10 4
rules/ 5 0
architecture/ 5 0
decisions/ ~22 0
standards/ 19 0
infrastructure/ 4 0
platform/ 4 0
operating-model/ 2 0
verification/ 2 0
reference/ 11 3 (redirects)
indexes/ 1 0
glossary/ 1 0
integration/ 0 — (entire directory empty)
Total ~86 7