Skip to content

STD-PACK-001: Public/Private Pack Boundaries, Agent Teams & Decision Vocabulary

Status: Approved Governing Standard Owner: Bluefly Platform Architecture / DrupalWorks Beads: bc-6m1b, bc-qysf, bc-5o48


1. Pack Domain Boundaries

Gas City packs follow strict public/private separation of duties:

Pack / Monorepo Visibility Location Scope
DrupalWorks (drupal) Public $ESTATE_ROOT/DrupalWorks Generic Drupal agent definitions, generic formulas (mol-drupal-*), orders (drupal-*), open skills, public recipes. ZERO secrets or private paths.
BluCity-Packs (blucity-packs) Private $ESTATE_ROOT/BluCity-Packs Bluefly monorepo for private overlay packs (blucity, amcs, platform). Dark team agents, internal formulas, 1Password reference wiring, Oracle deployment topologies.

2. Agent Teams Taxonomy

Agents are categorized into two explicit operational teams:

Light Team (Public / Contrib Builders)

Defined in public pack DrupalWorks: - drupal-architect: High-level Drupal CMS 2.x & SDC/Canvas architecture design. - drupal-builder: Module, recipe, and Tool API implementation. - drupal-auditor: Read-only security, drift, and quality verification. - drupal-migrator: Content & structure migration orchestration.

Dark Team (Private / Infrastructure & Governance Ops)

Defined in private pack monorepo BluCity-Packs: - polecat: Autonomous background task execution and liveness patrolling. - sentinel: Security boundary enforcement, secret reference auditing, and credential containment. - refinery: Branch hygiene, MR convergence, and release train merging. - harbormaster: Oracle container/service deployment & DDEV environment isolation.


3. Decision Vocabulary

All Gas City evaluation procedures and formulas must report standardized decision vocabulary:

  • PERMITTED: Operation conforms to security & governance standards.
  • DENIED: Operation violates governance/security policy.
  • CONVERGED: Configuration/code matches the canonical baseline.
  • REJECTED: Unapproved drift or unverified change.
  • UPSTREAM_FIRST: Capability is owned by core/contrib; custom implementation rejected.

4. Oracle & IaC Registration Flow

Public pack updates in DrupalWorks trigger automated registration on Oracle via GitLab CI:

DrupalWorks (release/v0.1.x)
  ──[promote-release-to-main]──► GitLab CI
  ──[infra/iac trigger]─────────► Oracle Gas City (/opt/bluefly/blucity)
  ──[gc pack fetch drupal]─────► Dolt hq database (127.0.0.1:3308/hq)