Skip to content

FINAL AMENDMENT: CONVOYS, BEADS, UPSTREAM-FIRST CITY INFRASTRUCTURE, AND CROSS-MOUNTAIN RECONCILIATION

Core Law: This amendment governs execution of Mountains 1–40.

The Mountains describe durable missions. They are not independent programs or parallel task queues. Many Mountains intentionally touch the same infrastructure.

Do not create duplicate Beads because the same underlying capability appears in multiple Mountains.

The execution model is:

MOUNTAIN ↓ SHARED CONVOY ↓ BEAD GRAPH ↓ FORMULA / MOLECULE / GATE ↓ AGENT ↓ SESSION ↓ EXECUTION ↓ VERIFICATION

Gas City already exists to orchestrate fleet work from six primitives: Agent, Bead, Formula, Rig, Pack, and Event. Packs declare reusable configuration, formulas describe repeatable jobs, Beads survive session failure, and Events expose what the fleet is doing. Bluefly should compose those capabilities, not create a second orchestration layer. (Gas City Docs)

Beads already provides dependency-aware work, Dolt-backed persistence, Formulas, Molecules, Gates, multi-agent coordination, routing, and dependency graphs. Bluefly should use those upstream mechanisms instead of creating Markdown queues, hand-built state machines, or new gate abstractions. (Beads Documentation)


1. Execution Hierarchy

Lock this taxonomy across all agents, documentation, and tooling:

MOUNTAIN = durable mission / outcome
CONVOY   = coordinated multi-Bead delivery objective
BEAD     = smallest durable executable work item
FORMULA  = repeatable execution method
MOLECULE = instantiated multi-step work graph where Beads upstream supports it
GATE     = dependency / asynchronous decision boundary
AGENT    = configured worker role
SESSION  = disposable execution process
  • Do not use Mountains as work queues.
  • Do not use Convoys as Bead substitutes.
  • Do not turn Formulas into giant project plans.
  • Do not put current execution state into documentation.

2. Cross-Mountain Deduplication Law

Before creating a Bead:

1. SEARCH EXISTING BEADS
2. SEARCH EXISTING CONVOYS
3. SEARCH EXISTING FORMULAS
4. SEARCH EXISTING ORDERS / EVENTS
5. SEARCH SOURCE
6. SEARCH UPSTREAM
7. IDENTIFY CURRENT OWNER

Then apply the disposition rule:

EXISTING BEAD                                      → CURATE
EXISTING BEAD, WRONG SCOPE                         → UPDATE
TWO BEADS, SAME EFFECT                             → MERGE / CLOSE DUPLICATE
SHARED CAPABILITY NEEDED BY MULTIPLE MOUNTAINS     → ONE BEAD UNDER SHARED CONVOY
REAL NEW BOUNDED WORK                              → CREATE

The Anti-Pattern to Never Repeat:

MOUNTAIN A mentions identity → identity Bead
MOUNTAIN B mentions identity → another identity Bead
MOUNTAIN C mentions identity → third identity Bead

The Required Pattern:

IDENTITY CONVOY (B) → ONE WORK GRAPH → MANY MOUNTAINS DEPEND ON IT

3. Canonical Cross-Mountain Convoys

The 40 Mountains converge into these 15 execution Convoys.

CONVOY A — CITY FOUNDATION

  • Supports: M1, M2, M3, M6, M16, M17, M37, M38, M40
  • Goal: Make one Gas City actually run reliably as the sole Factory orchestration runtime.
  • Seed Beads:
  • city-single-runtime-proof
  • city-current-upstream-version
  • city-config-convergence
  • city-supervisor-health
  • city-pack-import-convergence
  • city-rig-registration
  • city-event-pipeline
  • city-session-lifecycle
  • city-worktree-lifecycle
  • city-dolt-health
  • city-dolt-backup
  • city-dolt-restore-proof
  • city-mail-health
  • city-formula-runtime-proof
  • city-order-runtime-proof
  • city-gate-runtime-proof
  • city-molecule-runtime-proof
  • city-runtime-observability
  • Acceptance:
    ONE_CITY=YES
    CITY_HOST=ORACLE
    SECOND_CITY=NO
    RIGS_DISCOVERABLE=YES
    BEADS_DURABLE=YES
    FORMULAS_EXECUTE=YES
    EVENTS_EMIT=YES
    SESSIONS_ROTATE=YES
    WORK_SURVIVES_SESSION=YES
    DOLT_RECOVERY_PROVEN=YES
    

CONVOY B — IDENTITY, AUTHORITY, AND POLICY

  • Supports: M1, M4, M6, M7, M21, M22, M30, M32, M33
  • Goal: Every action has an explicit machine identity, bounded authority, policy decision, attribution, and customer scope.
  • Seed Beads:
  • identity-team-service-account-map
  • identity-role-to-ossa-map
  • identity-role-to-gitlab-map
  • identity-personal-credential-eviction
  • identity-machine-git-config
  • identity-package-publish-auth
  • identity-runtime-service-bindings
  • authority-factory-gate
  • authority-customer-delegation-model
  • authority-platform-permission-model
  • authority-bluefly-policy-model
  • authority-customer-policy-model
  • policy-cedar-owner
  • policy-contractplane-owner
  • policy-binding-contract
  • policy-decision-receipt
  • policy-denial-proof
  • scope-organization
  • scope-team
  • scope-project
  • scope-estate
  • scope-operation
  • Canonical Authorization Equation:
    EFFECTIVE_AUTHORITY = CUSTOMER_DELEGATED_SCOPE ∩ PLATFORM_PERMISSIONS ∩ CUSTOMER_POLICY ∩ BLUEFLY_POLICY
    
  • Rules:
  • No impersonation.
  • No Thomas credential reuse.
  • No agent-created permission escalation.

CONVOY C — SOURCE, CI, MERGE, AND RELEASE FABRIC

  • Supports: M4, M18, M19, M20, M21, M25, M39, M40
  • Goal: Source travels through one predictable automated path from branch to verified artifact.
  • Seed Beads:
  • gitlab-project-baseline
  • gitlab-mr-contract
  • gitlab-mr-pipelines
  • gitlab-merged-results
  • gitlab-merge-train-classification
  • gitlab-merge-train-enable-selected
  • gitlab-auto-merge-contract
  • gitlab-source-branch-cleanup
  • gitlab-webhook-repair
  • ci-shared-component-baseline
  • ci-required-job-proof
  • ci-false-green-elimination
  • ci-drupal-quality-gate
  • ci-npm-release-component
  • ci-pypi-release-component
  • ci-drupal-release-component
  • ci-composer-release-component
  • ci-container-release-component
  • ci-pack-release-component
  • release-version-contract
  • release-tag-contract
  • release-provenance
  • release-clean-consumer-proof
  • Merge Trains Policy: GitLab merge trains should be used where multiple concurrent MRs target the same release branch and their combined state must stay green. GitLab's own model requires merge-request pipelines and merged-results pipelines before merge trains can safely operate. (GitLab Docs)
    MERGE_TRAINS=SELECTIVE (not EVERYWHERE)
    
    Candidate repositories for trains:
  • BluCity
  • BluCity-Packs
  • DrupalWorks
  • gitlab_components
  • contextcontrol-ai
  • bluefly.io
  • High-concurrency shared libraries

CONVOY D — PACKAGE AND REGISTRY PUBLICATION

  • Supports: M5, M18, M19, M25, M39
  • Goal: Every reusable artifact has one canonical package identity and one intentional registry strategy.
  • Seed Beads:
  • package-estate-inventory
  • package-registry-matrix
  • package-duadp-npm
  • package-duadp-pypi
  • package-ossa-npm
  • package-ossa-pypi
  • package-ossa-studio-npm
  • package-drupal-contrib-inventory
  • package-drupal-org-readiness
  • package-private-composer-inventory
  • package-container-inventory
  • package-gascity-pack-inventory
  • package-version-source-standard
  • package-release-provenance
  • package-clean-consumer-test
  • Rule: Do not assume all projects need every registry.
    SOURCE PROJECT → LANGUAGE / PACKAGE TYPE → REAL CONSUMERS → CORRECT REGISTRY
    
    Channels to prove:
  • DUADP $\to$ npm (JS library) $\to$ PyPI (Python client)
  • OSSA $\to$ npm (JS tooling) $\to$ PyPI (Python tooling)
  • OSSA Studio $\to$ npm (CLI/application packaging)
  • Drupal contrib-ready projects $\to$ Drupal.org
  • Private reusable Drupal packages $\to$ GitLab Composer / package distribution

CONVOY E — PACK ARCHITECTURE

  • Supports: M3, M5, M6, M8, M26, M27, M28, M29, M38
  • Goal: Make reusable Factory capability live in Packs and Formulas rather than prompts and copied repo-specific automation.
  • Canonical Structure:
    PUBLIC  → DrupalWorks
    PRIVATE → BluCity-Packs
    
  • Seed Beads:
  • pack-core-contract
  • pack-public-private-boundary
  • pack-import-contract
  • pack-schema-validation
  • pack-versioning
  • pack-release-contract
  • pack-drupal-security-release
  • pack-drupal-custom-code
  • pack-drupal-upgrade
  • pack-migration
  • pack-accessibility
  • pack-performance
  • formula-single-purpose-gate
  • formula-input-output-contract
  • formula-authority-contract
  • formula-acceptance-contract
  • formula-failure-contract
  • formula-recovery-contract
  • formula-evidence-contract
  • Deduplication: M8 = umbrella Drupal maintenance mission.
    M26 = security/release operation family.
    M27 = custom-module operation family.
    M28 = upgrade operation family.
    M29 = migration operation family.
    Do not implement M8 separately from M26–29. M8 is portfolio coordination; M26–29 own executable pack capability.

CONVOY F — DRUPAL QUALITY AND UPSTREAM CONVERGENCE

  • Supports: M5, M7, M8, M24, M25, M26, M27, M28, M29
  • Goal: Make Drupal engineering upstream-first, clean, testable, and packageable.
  • Seed Beads:
  • drupal-upstream-inventory
  • drupal-custom-code-inventory
  • drupal-contrib-replacement-analysis
  • drupal-phpcs-baseline
  • drupal-phpstan-baseline
  • drupal-phpunit-baseline
  • drupal-deprecation-baseline
  • drupal-config-schema-baseline
  • drupal-clean-install-proof
  • drupal-enable-disable-proof
  • drupal-update-hook-proof
  • kb-cache-gc-worktree
  • kb-cache-phpcs-convergence
  • kb-cache-upstream-overlap-audit
  • kb-cache-ai-context-boundary
  • kb-cache-openknowledgebase-review
  • kb-cache-intent-review
  • Ownership Order:
    CORE → CONTRIB → CONFIG → RECIPE → CANVAS / SDC → ECA / MODELER / FLOWDROP → DRUPAL AI → TOOL API / MCP → EXISTING BLUEFLY EXTENSION → CUSTOM CODE LAST
    
    For kb_cache, use the Gas City governed worktree lifecycle. No random clones; no patching generated consumer projections.

CONVOY G — CUSTOMER CONTROL PLANE

  • Supports: M7, M30, M31, M32, M33, M34, M35, M36
  • Goal: ContextControl becomes the customer-facing governed interface to the Factory without becoming another orchestrator.
  • Reconciliation: M7 = integration architecture | M30 = customer product surfaces | M31 = AGUI presentation | M32 = isolation | M33 = context model | M34 = proof model | M35 = reusable learning | M36 = economics.
    One product lane. Not seven independent implementations.
  • Seed Beads:
  • contextcontrol-group-organization
  • contextcontrol-group-team
  • contextcontrol-project
  • contextcontrol-estate
  • contextcontrol-signal
  • contextcontrol-operation
  • contextcontrol-approval
  • contextcontrol-decision
  • contextcontrol-finding
  • contextcontrol-evidence
  • contextcontrol-receipt
  • contextcontrol-capability
  • contextcontrol-authority-view
  • contextcontrol-operation-view
  • contextcontrol-proof-view
  • contextcontrol-economics-view
  • contextcontrol-agui-contract
  • contextcontrol-chat-scope
  • contextcontrol-dynamic-dashboard
  • contextcontrol-data-isolation
  • contextcontrol-entity-access-proof
  • contextcontrol-cross-group-denial-proof
  • contextcontrol-gascity-read-model
  • contextcontrol-gitlab-read-model
  • contextcontrol-contractplane-read-model
  • contextcontrol-ottermon-read-model
  • Rule: Do not create another scheduler, Bead store, policy engine, or agent runtime inside Drupal.

CONVOY H — VERIFIED SECURITY & RELEASE OPERATION

  • Supports: M8, M25, M26, M34, M35, M36, M40
  • Goal: Finish the first commercially meaningful Factory operation end-to-end.
  • Target: ESTATE=bluefly.io, OPERATION=Drupal Security & Release
  • Seed Beads:
  • security-estate-inventory
  • security-detector-coverage
  • security-advisory-detect
  • security-release-detect
  • security-dependency-impact
  • security-custom-code-impact
  • security-capability-match
  • security-authority-check
  • security-update-branch
  • security-composer-update
  • security-db-update
  • security-config-impact
  • security-ci-proof
  • security-render-proof
  • security-release
  • security-deploy
  • security-runtime-proof
  • security-operational-receipt
  • security-run1-freeze
  • security-run2
  • security-second-estate
  • Run 1 Acceptance:
    DETECT=PASS UNDERSTAND=PASS MATCH=PASS AUTHORIZE=PASS ACT=PASS VERIFY=PASS PROVE=PASS IMPROVE=PASS
    
    Then Run 2. Then second estate.

CONVOY I — CUSTOM MODULE ASSURANCE

  • Supports: M8, M27, M35
  • Goal: Audit and reduce custom code footprint across the estate.
  • Seed Beads:
  • custom-module-inventory
  • custom-module-purpose
  • custom-module-contrib-match
  • custom-module-core-match
  • custom-module-security
  • custom-module-permissions
  • custom-module-routes
  • custom-module-deprecations
  • custom-module-phpstan
  • custom-module-phpcs
  • custom-module-cacheability
  • custom-module-performance
  • custom-module-query
  • custom-module-tests
  • custom-module-decision
  • Decision Result:
    KEEP | HARDEN | OPTIMIZE | MODERNIZE | REPLACE | CONSOLIDATE | DELETE
    

CONVOY J — UPGRADE AND MIGRATION

  • Supports: M28, M29
  • Shared Beads:
  • estate-source-inventory
  • estate-target-baseline
  • estate-dependency-map
  • estate-content-model-map
  • estate-custom-code-map
  • estate-theme-map
  • estate-integration-map
  • estate-test-baseline
  • estate-cutover-plan
  • estate-verification
  • Upgrade-Specific Beads:
  • upgrade-core-major
  • upgrade-php
  • upgrade-contrib
  • upgrade-deprecations
  • upgrade-custom-code
  • Migration-Specific Beads:
  • migration-source-adapter
  • migration-field-map
  • migration-transform
  • migration-delta
  • migration-cutover
  • migration-post-cutover-proof
  • Rule: Do not duplicate discovery, test, or evidence work between upgrade and migration.

CONVOY K — FACTORY OBSERVABILITY, EVIDENCE, AND ECONOMICS

  • Supports: M2, M34, M35, M36, M37
  • Goal: Make the Factory measurable without using agents as monitoring daemons.
  • Seed Beads:
  • telemetry-gascity-events
  • telemetry-bead-state
  • telemetry-session-state
  • telemetry-gitlab-state
  • telemetry-ci-state
  • telemetry-release-state
  • telemetry-deployment-state
  • telemetry-ottermon-boundary
  • telemetry-operation-receipt
  • telemetry-model-usage
  • telemetry-model-cost
  • telemetry-infra-cost
  • telemetry-human-time
  • telemetry-reuse
  • telemetry-rederived
  • telemetry-failure-rate
  • telemetry-cost-per-outcome
  • Rule: Models interpret anomalies; they do not poll systems.

CONVOY L — INFRASTRUCTURE AS CODE AND EXECUTION SURFACES

  • Supports: M14, M15, M16, M17, M21, M23, M37
  • Goal: Make every execution surface reproducible, disposable, observable, and governed. Primary infrastructure Convoy.
  • Seed Beads:
  • infra-topology-authority
  • infra-oracle-baseline
  • infra-oracle-iac
  • infra-runner-iac
  • infra-agent-docker
  • infra-networking
  • infra-tailscale
  • infra-cloudflare
  • infra-dns
  • infra-gascity-runtime
  • infra-dolt-runtime
  • infra-dolt-backup
  • infra-dolt-restore
  • infra-agent-image
  • infra-drupal-agent-image
  • infra-refinery-image
  • infra-witness-image
  • infra-model-routing
  • infra-litellm
  • infra-model-cache
  • infra-provider-fallback
  • infra-nas-backup
  • infra-nas-artifacts
  • infra-nas-models
  • infra-workstation-bootstrap
  • infra-workspace-image
  • Surfaces:
    ORACLE | MAC | NAS | DDEV | GITLAB WORKSPACE | AGENT CONTAINER
    
  • Service Contract for Every Service:
    SOURCE_OWNER= DEPLOY_OWNER= VERSION= IMAGE= CONFIG= SECRET_REFERENCE=
    HEALTHCHECK= PORT= NETWORK= VOLUME= BACKUP= OBSERVABILITY= UPGRADE= ROLLBACK=
    
    No hand-installed production services.

CONVOY M — MOSHI / OMO / UPSTREAM TOOLCHAIN

  • Supports: M14, M15, M23
  • Goal: Adopt useful upstream developer/agent tooling without turning upstream products into Bluefly-owned forks.
  • Candidate Upstreams: Moshi, OMO, QMD, CodeGraph, Orbit, Claudex, OpenClaw, GitLab Workspaces, GitLab Duo Agent Platform.
  • Per-Tool Beads:
  • upstream-<tool>-evaluate
  • upstream-<tool>-security
  • upstream-<tool>-integration
  • upstream-<tool>-package
  • upstream-<tool>-deploy
  • upstream-<tool>-verify
  • Disposition:
    ADOPT | ADOPT_WITH_CONFIG | ADOPT_WITH_THIN_ADAPTER | DEFER | REJECT (Not FORK)
    

CONVOY N — DOCUMENTATION, SCHEMA, AND AUTHORITY CONVERGENCE

  • Supports: M1, M9, M10, M11, M12, M13
  • Goal: Define doctrine once, reference it everywhere, and enforce structure automatically.
  • Seed Beads:
  • docs-authority-map
  • docs-team-contract
  • docs-project-agents-contract
  • docs-project-docs-contract
  • docs-product-doc-contract
  • docs-engineering-standard-contract
  • schema-authority
  • schema-project-context
  • schema-agent-contract
  • schema-pack-contract
  • schema-receipt
  • schema-capability
  • ci-doc-authority
  • ci-doc-duplicates
  • ci-doc-local-path
  • ci-doc-stale-status
  • ci-agent-duplicate
  • ci-skill-duplicate
  • ci-policy-duplicate
  • Result: Replaces repeated mandates with machine-enforced contracts.

CONVOY O — DURABILITY AND DISASTER RECOVERY

  • Supports: M16, M17, M34, M37
  • Goal: Important Factory state survives loss of Oracle, an agent session, a workstation, or the NAS.
  • Seed Beads:
  • dr-gitlab-source-recovery
  • dr-dolt-offhost-copy
  • dr-dolt-restore
  • dr-contextcontrol-backup
  • dr-contextcontrol-restore
  • dr-oracle-rebuild
  • dr-nas-integrity
  • dr-agent-image-rebuild
  • dr-receipt-preservation
  • dr-recovery-rehearsal
  • Proof Chain:
    BACKUP → OFF-HOST COPY → INTEGRITY → ISOLATED RESTORE → EXPECTED STATE → WITNESS
    

4. Cross-Mountain Duplicates to Remove

The following must no longer exist as separate work streams:

  1. GitLab Overlap: Merge M4, M20, M21, M22 into Convoys B, C, D.
  2. Release Overlap: Merge M18, M19, M39 into Convoys C, D. (M39 becomes inventory/reporting).
  3. Drupal Factory Overlap: Do not implement M8 separately from M26–29. Merge into Convoys E, F, H, I, J.
  4. ContextControl Overlap: Reconcile M7, M30, M31, M32, M33, M34, M35, M36 into Convoys B, G, K.
  5. Pack Overlap: Reconcile M3, M5, M6, M38 into Convoy E.
  6. Infrastructure Overlap: Reconcile M14, M15, M16, M17, M23, M37 into Convoys L, M, O.
  7. Governance Overlap: Reconcile M1, M9, M10, M11, M12, M13 into Convoy N.

5. Native Upstream First Order

Evaluate capabilities in strict order:

1. GAS CITY NATIVE
2. BEADS NATIVE
3. GITLAB NATIVE
4. DRUPAL CORE
5. DRUPAL CONTRIB
6. CEDAR
7. EXISTING OPEN STANDARD
8. EXISTING BLUEFLY OWNER
9. THIN ADAPTER
10. NEW BLUEFLY CAPABILITY

Examples: - Need dependency graph? $\to$ Beads - Need repeatable workflow? $\to$ Formula - Need instantiated workflow graph? $\to$ Molecule where applicable - Need async dependency? $\to$ Gate - Need project execution scope? $\to$ Rig - Need reusable Factory config? $\to$ Pack - Need event observation? $\to$ Event - Need concurrent merge serialization? $\to$ GitLab Merge Train - Need MR merged-state validation? $\to$ GitLab merged-results pipeline - Need policy decision? $\to$ Cedar - Need Drupal workflow? $\to$ ECA / Modeler / FlowDrop - Need Drupal AI execution? $\to$ Drupal AI Agents - Need external typed tool? $\to$ Tool API / MCP


6. City Infrastructure Target

The minimum real City infrastructure is:

                     GITLAB (source / CI / packages)
                        │
                        ▼
               GAS CITY (Oracle runtime)
                        │
      ┌─────────────────┼─────────────────┐
      ▼                 ▼                 ▼
    BEADS             PACKS            EVENTS
   / DOLT          / FORMULAS
      │                 │                 │
      └────────────┬────┴─────────────────┘
                   ▼
                 AGENTS
                   │
                   ▼
                  RIGS
                   │
                   ▼
      governed worktrees / execution
                   │
                   ▼
            CUSTOMER ESTATES
                   │
                   ▼
                WITNESS
                   │
                   ▼
          OPERATIONAL RECEIPT
                   │
                   ▼
             CONTEXTCONTROL

Infrastructure responsibilities: - ORACLE: City runtime $\to$ supervisor $\to$ agent containers $\to$ Dolt server $\to$ approved control services $\to$ runners. - GITLAB: Source $\to$ MR $\to$ CI $\to$ release $\to$ packages $\to$ provenance. - NAS: Backup $\to$ artifacts $\to$ model storage $\to$ recovery. - MAC: Disposable development / execution. - CONTEXTCONTROL: Human/customer UI $\to$ context $\to$ approvals $\to$ proof. - CEDAR / CONTRACTPLANE: Authorization policy. - OTTERMON: Operational observation where proven.


7. Bead Creation Contract

Every Bead must answer:

REQUESTED_EFFECT=
OWNER=
RIG=
INPUT=
DEPENDENCIES=
AUTHORITY=
ACCEPTANCE=
VERIFICATION=
OUTPUT=

8. Convoy Acceptance Contract

Every Convoy requires:

CONVOY=
MOUNTAINS_SUPPORTED=
CUSTOMER_OR_FACTORY_OUTCOME=
BEADS_TOTAL=
BEADS_OPEN=
BEADS_READY=
BEADS_BLOCKED=
DEPENDENCIES=
ACCEPTANCE=
WITNESS_REQUIRED=

9. Beads Dependency Graph

Use upstream dependency semantics (blocks, parent-child, discovered-from, related, Gate). Agents pull work exclusively via:

bd ready --metadata-field gc.routed_to=<agent>

Thomas is not the dependency resolver.


10. Initial Execution Graph

graph TD
    A["CONVOY A: City Foundation (P0)"]
    B["CONVOY B: Identity & Authority (P0)"]
    C["CONVOY C: Source / CI / Release (P0)"]
    F["CONVOY F: Drupal Quality (P0)"]
    H["CONVOY H: Security & Release (P0)"]
    L["CONVOY L: Infrastructure (P0)"]

    A -->|enables| B
    A -->|enables| C
    A -->|enables| H
    A -->|enables| L
    B -->|blocks unattended mutation in| H
    C -->|blocks source-delivered completion in| H
    F -->|blocks accepted Drupal changes in| H
    L -->|supports runtime & estate execution in| H

Execution sequence:

H RUN 1 → H RUN 2 → H SECOND ESTATE

Only after that expand materially into: - Convoy I: Custom Module Assurance - Convoy J: Upgrade / Migration - Convoy G: Full customer UI - Convoy D: Broad registry publication - Convoy M: Optional upstream tooling


11. First Infrastructure Acceptance Gate

Before calling the City ready:

ONE_CITY=PASS
ORACLE_RUNTIME=PASS
DOLT_HEALTH=PASS
DOLT_OFFHOST_BACKUP=PASS
DOLT_RESTORE=PASS
SERVICE_IDENTITIES=PASS
PERSONAL_CREDENTIALS_IN_AGENT_PATHS=0
RIG_REGISTRATION=PASS
GC_WORKTREE=PASS
FORMULA_EXECUTION=PASS
EVENT_EMISSION=PASS
DEPENDENCY_GATES=PASS
GITLAB_WEBHOOKS=PASS
MR_PIPELINE=PASS
MERGED_RESULTS=PASS
MERGE_TRAIN_SELECTED_REPOS=PASS
PACKAGE_REGISTRY_ACCESS=PASS
CI_SHARED_COMPONENTS=PASS
AGENT_CONTAINER_REPRODUCIBILITY=PASS
IAC_REPRODUCIBILITY=PASS
CONTEXTCONTROL_READ_MODEL=PASS
WITNESS_INDEPENDENCE=PASS

12. Final Operating Law

The Mountains explain why.
The Convoys coordinate what must converge together.
The Beads record what is executable now.
The Formulas encode how repeated work is done.
The Molecules instantiate repeatable multi-step graphs where appropriate.
The Gates hold dependencies and asynchronous decisions.
The Agents execute.
The Sessions are disposable.
The Events wake the Factory.
GitLab delivers source.
Oracle runs the City.
NAS preserves recoverability.
ContextControl gives customers control and visibility.

And:

If upstream Gas City, Beads, GitLab, Drupal, Cedar, or another governed upstream already owns the mechanism, Bluefly configures and composes it rather than rebuilding it.

Final target:

ONE CITY
ONE WORK GRAPH
ONE SOURCE AUTHORITY
ONE POLICY CHAIN
ONE CUSTOMER CONTROL SURFACE
MANY RIGS
MANY PACKS
MANY CUSTOMER ESTATES
MANY VERIFIED OPERATIONS
ZERO PARALLEL ORCHESTRATORS
ZERO DUPLICATE WORK GRAPHS
ZERO MODEL POLLING LOOPS
ZERO PERSONAL CREDENTIAL DEPENDENCIES
ZERO CUSTOMER-INVISIBLE PROOF