Skip to content

Portability Sweep & Personal Path Governance Directive

Status: ACTIVE Enforcement: STRICT

This document codifies the directive for sweeping and eliminating personal workstation paths (e.g., ~) from tracked source, and defines the remediation ownership.

1. Scope of the Sweep

The 1,122,945 filesystem result is invalid as a planning denominator. Do NOT inspect: - node_modules/ - vendor/ - .git/ - build caches - .gc/worktrees/ - generated install output

Measure TRACKED SOURCE ONLY.

For each canonical repo/ref, measure tracked files containing: - ~ - $ESTATE_ROOT

2. Pre-Resolved Architectural Owners

A. The kb_cache / QDRANT Decision

This is already resolved in canonical tracked evidence. Current kb_cache owns duplicated configuration: - src/Service/QdrantClient.php - config/schema: qdrant_base_url, qdrant_collection, qdrant_timeout - config/install: qdrant_base_url, qdrant_collection, qdrant_timeout

Directive: - KB_CACHE_CUSTOM_QDRANT_CLIENT=DELETE_TARGET - KB_CACHE_QDRANT_SETTINGS=DELETE_TARGET - BLUEFLY_VECTOR_STORAGE_IMPLEMENTATION=NO

Retrieval/storage should use the established Drupal AI / ai_search / ai_vdb owner. Do not create a replacement provider. Do not write another Qdrant client. Do not fork Qdrant.

B. Personal Workstation Paths Lint

gitlab_components already owns no-personal-workstation-paths and its checker: assets/scripts/check-no-personal-workstation-paths.mjs. Directive: - Wire the existing shared component if absent. - Parameterize/delete the actual tracked path. - Do not duplicate the checker. - Do not add custom CI.

C. Cedar Path Defect

A workstation-specific protected path cannot be canonical policy. Directive: Parameterize using an existing estate-root/runtime-root input if one exists; otherwise use the logical resource identifier the Cedar policy is meant to protect. Do not merely substitute another machine path. Do not create a second Cedar framework.

D. 1Password Wrapper Defect

op run --account blueflyiollc --env-file=$ESTATE_ROOT/.op-env -- <command> violates portability and authenticate-once models. Directive: Find the existing secret-execution owner and consume it. Do not replace it with another hardcoded local path.

3. Prioritization & Execution

Classify every tracked-path violation: - P0 = security / authorization / secret execution - P1 = runtime/build break or portability blocker - P2 = stale docs/examples - P3 = harmless historical/evidence material

Execution Flow: Return one compact inventory of scanned repos and P0-P3 counts. Then immediately execute the P0/P1 fixes through: Bead → worktree → branch → MR to release/v0.1.x → CI → merge