Skip to content

STD-IDENTITY-001 — Agent Identity & 1Password Delivery Constitution

STATUS

AUTHORITY=ENGINEERING_STANDARD
SCOPE=ALL_BLUEFLY_AGENTS_AND_DELIVERY_PATHS
SECRET_AUTHORITY=1PASSWORD
SOURCE_AUTHORITY=GITLAB
WORK_AUTHORITY=GAS_CITY + BEADS

PRIME DIRECTIVE

AUTHENTICATE ONCE.
REFERENCE SECRETS.
REUSE AUTHORITY.
PREFER UPSTREAM.
EXECUTE THROUGH THE OWNING SYSTEM.

And:

1PASSWORD AUTHENTICATES.
BLUEFLY AUTHORIZES.
BLUEFLY EXECUTES.

1. EVERY PRIMARY AGENT HAS ITS OWN IDENTITY

Primary durable agent roles:

BLU
DRUPAL
FORGE
FOUNDRY
HARBORMASTER
MAYOR
REFINERY
SENTINEL
WITNESS

Each primary Agent MUST map to exactly one durable GitLab service identity.

Required:

GAS_CITY_AGENT
→ AGENT_ID
→ GITLAB_SERVICE_ACCOUNT
→ 1PASSWORD IDENTITY MATERIAL

Forbidden:

AGENT USES THOMAS GITLAB IDENTITY
AGENT USES SHARED @bluefly-bot IDENTITY
AGENT BORROWS ANOTHER AGENT'S TOKEN
AGENT COPIES PERSONAL PAT

2. CANONICAL AGENT DEFINITIONS

Agent definitions live under:

.agents/agents

Related reusable material:

.agents/skills
.agents/plugins

Do not create another identity registry.

OSSA remains the portable authoritative agent definition where applicable.

DUADP handles discovery/federation.

Gas City owns execution/admission.

3. IDENTITY TRACEABILITY

Every delivery must be attributable through:

AGENT
→ GITLAB SERVICE ACCOUNT
→ BEAD
→ SESSION
→ WORKTREE
→ SIGNED COMMIT
→ MERGE REQUEST
→ CI
→ WITNESS
→ RELEASE
→ ARTIFACT
→ DEPLOYMENT
→ RECEIPT

Required:

WHO DID THE WORK=ESTABLISHED
WHAT WORK AUTHORIZED IT=ESTABLISHED
WHAT SESSION EXECUTED IT=ESTABLISHED
WHAT COMMIT DELIVERED IT=ESTABLISHED
WHAT MR REVIEWED IT=ESTABLISHED
WHAT CI VERIFIED IT=ESTABLISHED
WHAT WITNESS VERIFIED IT=ESTABLISHED

4. 1PASSWORD IS THE SECRET AUTHORITY

Secret material belongs in:

1PASSWORD

not:

git
yaml
json
.env committed to source
chat
prompt
logs
CI output
shell history
agent memory
Bead descriptions

Rule:

REFERENCE SECRET
NEVER DUPLICATE SECRET VALUE

5. SSH IDENTITY

Preferred Git transport:

SSH

Agent signing/auth flow:

AGENT IDENTITY
→ 1PASSWORD SSH AGENT
→ SSH AUTHORIZATION
→ GITLAB

Private keys MUST NOT be exported to files merely so an agent can use them.

1Password SSH Agent should perform signing/authentication without exposing private key material to the agent.

6. SIGNED COMMITS

Agent commits must be attributable to the agent's GitLab identity and signed through the approved SSH signing mechanism.

Required per worktree/session:

user.name=<agent identity>
user.email=<agent GitLab identity email>
gpg.format=ssh
user.signingkey=<1Password-backed SSH public key/reference>
commit.gpgsign=true

Do not rewrite old pushed history merely to cosmetically alter identity.

Preserve evidence.

Correct identity going forward.

7. GITLAB SERVICE ACCOUNTS

One GitLab service account per primary agent.

Example conceptual mapping:

BLU          → GitLab Blu identity
DRUPAL       → GitLab Drupal identity
FORGE        → GitLab Forge identity
FOUNDRY      → GitLab Foundry identity
HARBORMASTER → GitLab HarborMaster identity
MAYOR        → GitLab Mayor identity
REFINERY     → GitLab Refinery identity
SENTINEL     → GitLab Sentinel identity
WITNESS      → GitLab Witness identity

GitLab owns:

account
authorization
repository permissions
token lifecycle
revocation
rotation policy

1Password owns:

secret storage
secret delivery
SSH private key custody
service-account bootstrap material

Do not confuse the two authorities.

8. SECRET DELIVERY

Preferred hierarchy:

NATIVE WORKLOAD IDENTITY
→ 1PASSWORD SERVICE ACCOUNT
→ 1PASSWORD CONNECT / SUPPORTED INTEGRATION
→ TARGET CREDENTIAL

Use the narrowest supported mechanism.

Interactive humans may authenticate once and reuse the authenticated session.

Automation should use scoped machine/service identity.

No repeated:

op signin
op read
op run

for every operation where a reusable authenticated mechanism exists.

9. SERVICE ACCOUNTS

Long-lived automation should use scoped 1Password Service Accounts where appropriate.

Requirements:

LEAST PRIVILEGE
PURPOSE-SPECIFIC
VAULT-SCOPED
ROTATABLE
AUDITABLE

Do not use a personal human session as permanent machine identity.

10. ORACLE SERVICES

Long-running Oracle services should use supported non-interactive 1Password delivery.

Approved patterns may include:

1PASSWORD Service Account
1PASSWORD Connect
official 1Password SDK/integration

depending on the workload.

Do not export a vault-wide credential into arbitrary containers.

11. CI

CI should use a dedicated CI identity and narrow vault scope.

Target pattern:

DEDICATED CI VAULT
→ READ-ONLY 1PASSWORD CI SERVICE ACCOUNT
→ PROTECTED CI BOOTSTRAP
→ RUNTIME SECRET RESOLUTION

Do not inject Oracle's broad service account into CI.

12. CREDENTIAL BROKER

Do NOT build a new Bluefly secret manager.

Do NOT build:

custom token cache
custom secret database
custom credential replication system
plaintext broker cache

Where a credential abstraction is required, it should remain backend-agnostic and use supported upstream providers.

Target architecture where supported:

TRUST / WORKLOAD IDENTITY
→ CREDENTIAL PROVIDER
→ 1PASSWORD DELIVERY
→ TARGET SYSTEM

Treat newer broker/workload-identity capabilities according to actual production maturity.

Do not pretend preview functionality is stable production infrastructure.

13. GITLAB TOKEN LIFECYCLE

GitLab remains authoritative for GitLab token state.

Rotation:

GitLab creates/revokes/rotates
→ 1Password stores replacement
→ consuming identity reloads reference
→ verification
→ old credential revoked

Do not create parallel Bluefly token lifecycle logic.

14. SEMANTIC REFERENCES

Source/config should reference semantic identity names.

Good:

GITLAB_AGENT_IDENTITY=forge
SSH_IDENTITY=forge
SECRET_REF=op://Agent-Identity/FORGE/...

Bad:

raw token value
private key value
physical secret copied into YAML
Thomas PAT
shared bot credential

Physical IDs should be avoided in portable source where semantic references can be resolved.

15. SESSION ADMISSION

A Claude window is not automatically a Gas City Agent.

Required before canonical mutation:

AGENT_ID=
GC_SESSION_ID=
BEAD=
CLAIM=
RIG=
WORKTREE=
MAIL_READBACK=
GIT_IDENTITY=

Then:

ADMITTED=YES

Without that:

SESSION=UNADMITTED
WORK=CANDIDATE

Useful candidate work may be preserved and later adopted.

It is not canonical Factory execution until admitted.

16. WORKTREE IDENTITY

Every Gas City-managed worktree must receive the identity of the admitted Agent.

Identity must be scoped to the worktree/session.

Do not globally rewrite Thomas's local Git identity to solve agent attribution.

Target:

WORKTREE
→ AGENT_ID
→ GITLAB_IDENTITY
→ SIGNING_IDENTITY

17. DELIVERY ENFORCEMENT

Delivery law:

BEAD
→ CLAIM
→ GAS CITY WORKTREE
→ AGENT IDENTITY
→ SIGNED COMMIT
→ PUSH
→ MR
→ CI
→ WITNESS
→ MERGE
→ RELEASE

Forbidden:

direct push to release
direct push to main
Thomas identity borrowed by agent
unsigned/unattributed agent work
random tmp clone
canonical checkout implementation

18. WITNESS

WITNESS must independently verify the delivered SHA.

Required:

FINAL_SHA=
WITNESS_SHA=
SHA_MATCH=YES

WITNESS identity is independent from the implementing agent.

19. EVENTS AND AUDIT

Where available, use 1Password audit/events capabilities and GitLab audit evidence to establish:

WHO ACCESSED
WHAT IDENTITY
WHAT SECRET REFERENCE
WHAT TARGET
WHEN

Do not log secret values.

Watchtower or credential governance tooling may identify risk, but does not replace system-specific authorization.

20. NO HUMAN FALLBACK

Thomas is not the credential courier.

Agents must not ask Thomas to:

copy a token
paste a secret
switch Git identity manually
forward credentials between agents
run normal Git commands on their behalf

Human-only operations include:

credential rotation requiring account-owner consent
new external service authorization
security recovery requiring human authentication

BLU routes all other work to the correct owner.

21. CURRENT FACTORY RECOVERY

The identity problem currently blocks canonical delivery from:

FORGE
FOUNDRY
DRUPAL
other primary agents

Therefore identity provisioning is P0 Factory recovery work.

Required sequence:

1. restore Gas City admission
2. establish each Agent ID
3. establish GitLab service account mapping
4. establish 1Password SSH identity
5. establish signed commit configuration
6. verify push
7. verify MR authorship
8. verify CI
9. verify WITNESS

Do this once as reusable Factory capability.

Do NOT solve each blocked agent independently with ad-hoc credentials.

22. REQUIRED IDENTITY MATRIX

Produce:

AGENT=
AGENT_ID=
GITLAB_USERNAME=
GITLAB_USER_ID=
GIT_EMAIL=

1PASSWORD_ITEM=
SSH_PUBLIC_KEY=
SSH_AUTH_TEST=

COMMIT_SIGNING=
COMMIT_SIGNATURE_TEST=

GITLAB_PUSH_TEST=
MR_AUTHOR_TEST=

GC_SESSION_ID=
CLAIM_TEST=
MAIL_READBACK=

STATUS=

for each primary Agent.

Never include private key or token values in the report.

23. ACCEPTANCE

PRIMARY_AGENTS_WITH_UNIQUE_IDENTITY=9

AGENT_USING_THOMAS_IDENTITY=0
SHARED_AGENT_GITLAB_IDENTITIES=0
PLAINTEXT_AGENT_CREDENTIALS=0
UNSIGNED_CANONICAL_AGENT_COMMITS=0

1PASSWORD_SECRET_AUTHORITY=YES
GITLAB_AUTHORIZATION_AUTHORITY=YES
GAS_CITY_EXECUTION_AUTHORITY=YES

SSH_USES_1PASSWORD_AGENT=YES
SIGNED_COMMITS=YES
SECRETS_BY_REFERENCE=YES

FORGE_CAN_PUSH=YES
FOUNDRY_CAN_PUSH=YES
DRUPAL_CAN_PUSH=YES
MAYOR_CAN_PUSH_WHEN_AUTHORIZED=YES
HARBORMASTER_CAN_PUSH_WHEN_AUTHORIZED=YES
REFINERY_CAN_PUSH_WHEN_AUTHORIZED=YES
SENTINEL_CAN_PUSH_WHEN_AUTHORIZED=YES
WITNESS_CAN_VERIFY_INDEPENDENTLY=YES
BLU_CAN_DIRECT_WITHOUT_BORROWING_THOMAS_IDENTITY=YES

FINAL LAW

ONE PRIMARY AGENT.

ONE DURABLE IDENTITY.

ONE GITLAB SERVICE ACCOUNT.

ONE ATTRIBUTABLE DELIVERY CHAIN.

1PASSWORD HOLDS SECRET MATERIAL.

GITLAB OWNS GITLAB AUTHORIZATION.

GAS CITY OWNS EXECUTION.

BEADS OWN WORK STATE.

WITNESS VERIFIES.

SECRET VALUES DO NOT ENTER SOURCE.

THOMAS'S PERSONAL IDENTITY IS NEVER THE AGENT FALLBACK.