STD-IDENTITY-001 — Agent Identity & 1Password Delivery Constitution¶
STATUS¶
AUTHORITY=ENGINEERING_STANDARD
SCOPE=ALL_BLUEFLY_AGENTS_AND_DELIVERY_PATHS
SECRET_AUTHORITY=1PASSWORD
SOURCE_AUTHORITY=GITLAB
WORK_AUTHORITY=GAS_CITY + BEADS
PRIME DIRECTIVE¶
AUTHENTICATE ONCE.
REFERENCE SECRETS.
REUSE AUTHORITY.
PREFER UPSTREAM.
EXECUTE THROUGH THE OWNING SYSTEM.
And:
1PASSWORD AUTHENTICATES.
BLUEFLY AUTHORIZES.
BLUEFLY EXECUTES.
1. EVERY PRIMARY AGENT HAS ITS OWN IDENTITY¶
Primary durable agent roles:
BLU
DRUPAL
FORGE
FOUNDRY
HARBORMASTER
MAYOR
REFINERY
SENTINEL
WITNESS
Each primary Agent MUST map to exactly one durable GitLab service identity.
Required:
GAS_CITY_AGENT
→ AGENT_ID
→ GITLAB_SERVICE_ACCOUNT
→ 1PASSWORD IDENTITY MATERIAL
Forbidden:
AGENT USES THOMAS GITLAB IDENTITY
AGENT USES SHARED @bluefly-bot IDENTITY
AGENT BORROWS ANOTHER AGENT'S TOKEN
AGENT COPIES PERSONAL PAT
2. CANONICAL AGENT DEFINITIONS¶
Agent definitions live under:
.agents/agents
Related reusable material:
.agents/skills
.agents/plugins
Do not create another identity registry.
OSSA remains the portable authoritative agent definition where applicable.
DUADP handles discovery/federation.
Gas City owns execution/admission.
3. IDENTITY TRACEABILITY¶
Every delivery must be attributable through:
AGENT
→ GITLAB SERVICE ACCOUNT
→ BEAD
→ SESSION
→ WORKTREE
→ SIGNED COMMIT
→ MERGE REQUEST
→ CI
→ WITNESS
→ RELEASE
→ ARTIFACT
→ DEPLOYMENT
→ RECEIPT
Required:
WHO DID THE WORK=ESTABLISHED
WHAT WORK AUTHORIZED IT=ESTABLISHED
WHAT SESSION EXECUTED IT=ESTABLISHED
WHAT COMMIT DELIVERED IT=ESTABLISHED
WHAT MR REVIEWED IT=ESTABLISHED
WHAT CI VERIFIED IT=ESTABLISHED
WHAT WITNESS VERIFIED IT=ESTABLISHED
4. 1PASSWORD IS THE SECRET AUTHORITY¶
Secret material belongs in:
1PASSWORD
not:
git
yaml
json
.env committed to source
chat
prompt
logs
CI output
shell history
agent memory
Bead descriptions
Rule:
REFERENCE SECRET
NEVER DUPLICATE SECRET VALUE
5. SSH IDENTITY¶
Preferred Git transport:
SSH
Agent signing/auth flow:
AGENT IDENTITY
→ 1PASSWORD SSH AGENT
→ SSH AUTHORIZATION
→ GITLAB
Private keys MUST NOT be exported to files merely so an agent can use them.
1Password SSH Agent should perform signing/authentication without exposing private key material to the agent.
6. SIGNED COMMITS¶
Agent commits must be attributable to the agent's GitLab identity and signed through the approved SSH signing mechanism.
Required per worktree/session:
user.name=<agent identity>
user.email=<agent GitLab identity email>
gpg.format=ssh
user.signingkey=<1Password-backed SSH public key/reference>
commit.gpgsign=true
Do not rewrite old pushed history merely to cosmetically alter identity.
Preserve evidence.
Correct identity going forward.
7. GITLAB SERVICE ACCOUNTS¶
One GitLab service account per primary agent.
Example conceptual mapping:
BLU → GitLab Blu identity
DRUPAL → GitLab Drupal identity
FORGE → GitLab Forge identity
FOUNDRY → GitLab Foundry identity
HARBORMASTER → GitLab HarborMaster identity
MAYOR → GitLab Mayor identity
REFINERY → GitLab Refinery identity
SENTINEL → GitLab Sentinel identity
WITNESS → GitLab Witness identity
GitLab owns:
account
authorization
repository permissions
token lifecycle
revocation
rotation policy
1Password owns:
secret storage
secret delivery
SSH private key custody
service-account bootstrap material
Do not confuse the two authorities.
8. SECRET DELIVERY¶
Preferred hierarchy:
NATIVE WORKLOAD IDENTITY
→ 1PASSWORD SERVICE ACCOUNT
→ 1PASSWORD CONNECT / SUPPORTED INTEGRATION
→ TARGET CREDENTIAL
Use the narrowest supported mechanism.
Interactive humans may authenticate once and reuse the authenticated session.
Automation should use scoped machine/service identity.
No repeated:
op signin
op read
op run
for every operation where a reusable authenticated mechanism exists.
9. SERVICE ACCOUNTS¶
Long-lived automation should use scoped 1Password Service Accounts where appropriate.
Requirements:
LEAST PRIVILEGE
PURPOSE-SPECIFIC
VAULT-SCOPED
ROTATABLE
AUDITABLE
Do not use a personal human session as permanent machine identity.
10. ORACLE SERVICES¶
Long-running Oracle services should use supported non-interactive 1Password delivery.
Approved patterns may include:
1PASSWORD Service Account
1PASSWORD Connect
official 1Password SDK/integration
depending on the workload.
Do not export a vault-wide credential into arbitrary containers.
11. CI¶
CI should use a dedicated CI identity and narrow vault scope.
Target pattern:
DEDICATED CI VAULT
→ READ-ONLY 1PASSWORD CI SERVICE ACCOUNT
→ PROTECTED CI BOOTSTRAP
→ RUNTIME SECRET RESOLUTION
Do not inject Oracle's broad service account into CI.
12. CREDENTIAL BROKER¶
Do NOT build a new Bluefly secret manager.
Do NOT build:
custom token cache
custom secret database
custom credential replication system
plaintext broker cache
Where a credential abstraction is required, it should remain backend-agnostic and use supported upstream providers.
Target architecture where supported:
TRUST / WORKLOAD IDENTITY
→ CREDENTIAL PROVIDER
→ 1PASSWORD DELIVERY
→ TARGET SYSTEM
Treat newer broker/workload-identity capabilities according to actual production maturity.
Do not pretend preview functionality is stable production infrastructure.
13. GITLAB TOKEN LIFECYCLE¶
GitLab remains authoritative for GitLab token state.
Rotation:
GitLab creates/revokes/rotates
→ 1Password stores replacement
→ consuming identity reloads reference
→ verification
→ old credential revoked
Do not create parallel Bluefly token lifecycle logic.
14. SEMANTIC REFERENCES¶
Source/config should reference semantic identity names.
Good:
GITLAB_AGENT_IDENTITY=forge
SSH_IDENTITY=forge
SECRET_REF=op://Agent-Identity/FORGE/...
Bad:
raw token value
private key value
physical secret copied into YAML
Thomas PAT
shared bot credential
Physical IDs should be avoided in portable source where semantic references can be resolved.
15. SESSION ADMISSION¶
A Claude window is not automatically a Gas City Agent.
Required before canonical mutation:
AGENT_ID=
GC_SESSION_ID=
BEAD=
CLAIM=
RIG=
WORKTREE=
MAIL_READBACK=
GIT_IDENTITY=
Then:
ADMITTED=YES
Without that:
SESSION=UNADMITTED
WORK=CANDIDATE
Useful candidate work may be preserved and later adopted.
It is not canonical Factory execution until admitted.
16. WORKTREE IDENTITY¶
Every Gas City-managed worktree must receive the identity of the admitted Agent.
Identity must be scoped to the worktree/session.
Do not globally rewrite Thomas's local Git identity to solve agent attribution.
Target:
WORKTREE
→ AGENT_ID
→ GITLAB_IDENTITY
→ SIGNING_IDENTITY
17. DELIVERY ENFORCEMENT¶
Delivery law:
BEAD
→ CLAIM
→ GAS CITY WORKTREE
→ AGENT IDENTITY
→ SIGNED COMMIT
→ PUSH
→ MR
→ CI
→ WITNESS
→ MERGE
→ RELEASE
Forbidden:
direct push to release
direct push to main
Thomas identity borrowed by agent
unsigned/unattributed agent work
random tmp clone
canonical checkout implementation
18. WITNESS¶
WITNESS must independently verify the delivered SHA.
Required:
FINAL_SHA=
WITNESS_SHA=
SHA_MATCH=YES
WITNESS identity is independent from the implementing agent.
19. EVENTS AND AUDIT¶
Where available, use 1Password audit/events capabilities and GitLab audit evidence to establish:
WHO ACCESSED
WHAT IDENTITY
WHAT SECRET REFERENCE
WHAT TARGET
WHEN
Do not log secret values.
Watchtower or credential governance tooling may identify risk, but does not replace system-specific authorization.
20. NO HUMAN FALLBACK¶
Thomas is not the credential courier.
Agents must not ask Thomas to:
copy a token
paste a secret
switch Git identity manually
forward credentials between agents
run normal Git commands on their behalf
Human-only operations include:
credential rotation requiring account-owner consent
new external service authorization
security recovery requiring human authentication
BLU routes all other work to the correct owner.
21. CURRENT FACTORY RECOVERY¶
The identity problem currently blocks canonical delivery from:
FORGE
FOUNDRY
DRUPAL
other primary agents
Therefore identity provisioning is P0 Factory recovery work.
Required sequence:
1. restore Gas City admission
2. establish each Agent ID
3. establish GitLab service account mapping
4. establish 1Password SSH identity
5. establish signed commit configuration
6. verify push
7. verify MR authorship
8. verify CI
9. verify WITNESS
Do this once as reusable Factory capability.
Do NOT solve each blocked agent independently with ad-hoc credentials.
22. REQUIRED IDENTITY MATRIX¶
Produce:
AGENT=
AGENT_ID=
GITLAB_USERNAME=
GITLAB_USER_ID=
GIT_EMAIL=
1PASSWORD_ITEM=
SSH_PUBLIC_KEY=
SSH_AUTH_TEST=
COMMIT_SIGNING=
COMMIT_SIGNATURE_TEST=
GITLAB_PUSH_TEST=
MR_AUTHOR_TEST=
GC_SESSION_ID=
CLAIM_TEST=
MAIL_READBACK=
STATUS=
for each primary Agent.
Never include private key or token values in the report.
23. ACCEPTANCE¶
PRIMARY_AGENTS_WITH_UNIQUE_IDENTITY=9
AGENT_USING_THOMAS_IDENTITY=0
SHARED_AGENT_GITLAB_IDENTITIES=0
PLAINTEXT_AGENT_CREDENTIALS=0
UNSIGNED_CANONICAL_AGENT_COMMITS=0
1PASSWORD_SECRET_AUTHORITY=YES
GITLAB_AUTHORIZATION_AUTHORITY=YES
GAS_CITY_EXECUTION_AUTHORITY=YES
SSH_USES_1PASSWORD_AGENT=YES
SIGNED_COMMITS=YES
SECRETS_BY_REFERENCE=YES
FORGE_CAN_PUSH=YES
FOUNDRY_CAN_PUSH=YES
DRUPAL_CAN_PUSH=YES
MAYOR_CAN_PUSH_WHEN_AUTHORIZED=YES
HARBORMASTER_CAN_PUSH_WHEN_AUTHORIZED=YES
REFINERY_CAN_PUSH_WHEN_AUTHORIZED=YES
SENTINEL_CAN_PUSH_WHEN_AUTHORIZED=YES
WITNESS_CAN_VERIFY_INDEPENDENTLY=YES
BLU_CAN_DIRECT_WITHOUT_BORROWING_THOMAS_IDENTITY=YES
FINAL LAW¶
ONE PRIMARY AGENT.
ONE DURABLE IDENTITY.
ONE GITLAB SERVICE ACCOUNT.
ONE ATTRIBUTABLE DELIVERY CHAIN.
1PASSWORD HOLDS SECRET MATERIAL.
GITLAB OWNS GITLAB AUTHORIZATION.
GAS CITY OWNS EXECUTION.
BEADS OWN WORK STATE.
WITNESS VERIFIES.
SECRET VALUES DO NOT ENTER SOURCE.
THOMAS'S PERSONAL IDENTITY IS NEVER THE AGENT FALLBACK.