Portability Sweep & Personal Path Governance Directive¶
Status: ACTIVE Enforcement: STRICT
This document codifies the directive for sweeping and eliminating personal workstation paths (e.g., ~) from tracked source, and defines the remediation ownership.
1. Scope of the Sweep¶
The 1,122,945 filesystem result is invalid as a planning denominator.
Do NOT inspect:
- node_modules/
- vendor/
- .git/
- build caches
- .gc/worktrees/
- generated install output
Measure TRACKED SOURCE ONLY.
For each canonical repo/ref, measure tracked files containing:
- ~
- $ESTATE_ROOT
2. Pre-Resolved Architectural Owners¶
A. The kb_cache / QDRANT Decision¶
This is already resolved in canonical tracked evidence.
Current kb_cache owns duplicated configuration:
- src/Service/QdrantClient.php
- config/schema: qdrant_base_url, qdrant_collection, qdrant_timeout
- config/install: qdrant_base_url, qdrant_collection, qdrant_timeout
Directive:
- KB_CACHE_CUSTOM_QDRANT_CLIENT=DELETE_TARGET
- KB_CACHE_QDRANT_SETTINGS=DELETE_TARGET
- BLUEFLY_VECTOR_STORAGE_IMPLEMENTATION=NO
Retrieval/storage should use the established Drupal AI / ai_search / ai_vdb owner. Do not create a replacement provider. Do not write another Qdrant client. Do not fork Qdrant.
B. Personal Workstation Paths Lint¶
gitlab_components already owns no-personal-workstation-paths and its checker: assets/scripts/check-no-personal-workstation-paths.mjs.
Directive:
- Wire the existing shared component if absent.
- Parameterize/delete the actual tracked path.
- Do not duplicate the checker.
- Do not add custom CI.
C. Cedar Path Defect¶
A workstation-specific protected path cannot be canonical policy. Directive: Parameterize using an existing estate-root/runtime-root input if one exists; otherwise use the logical resource identifier the Cedar policy is meant to protect. Do not merely substitute another machine path. Do not create a second Cedar framework.
D. 1Password Wrapper Defect¶
op run --account blueflyiollc --env-file=$ESTATE_ROOT/.op-env -- <command> violates portability and authenticate-once models.
Directive: Find the existing secret-execution owner and consume it. Do not replace it with another hardcoded local path.
3. Prioritization & Execution¶
Classify every tracked-path violation: - P0 = security / authorization / secret execution - P1 = runtime/build break or portability blocker - P2 = stale docs/examples - P3 = harmless historical/evidence material
Execution Flow:
Return one compact inventory of scanned repos and P0-P3 counts.
Then immediately execute the P0/P1 fixes through:
Bead → worktree → branch → MR to release/v0.1.x → CI → merge