Skip to content

STD-EXEC-001: Execution Environment Constitution

Field Value
Status Frozen (vocabulary correction 2026-09-09: Gas Town / Molecule are not platform layers)
Version 1.1
Document ID STD-EXEC-001
Date 2026-09-09
Scope Execution authority, capability ownership, and compliance governance.
Out of Scope Authentication policy, Git policy, Runtime operations, Architecture, Coding standards, Security.

Purpose

Execution location is determined by capability ownership, not by where an agent session begins.

The originating machine is never authoritative by default.

Agents MUST execute work on the host that owns the required capability.


1. Platform Execution Order of Precedence

Before writing custom code, engineers and agents MUST evaluate the platform in this strict order:

Upstream
    ↓
Gas City
    ↓
Pack
    ↓
Formula
    ↓
Order
    ↓
Existing Agent (pack-configured)
    ↓
Contract
    ↓
Schema
    ↓
MCP
    ↓
AG-UI
    ↓
Thin Adapter
    ↓
Custom Code (LAST RESORT ONLY)

Gas Town and Molecule are not layers. Gas Town is an importable Pack configuration of Gas City. Repeatable method is a Formula; automated triggering is an Order. See factory-operating-contract.md.

If YES to any layer, reuse it. Custom implementations without prior layer evaluation evidence are prohibited.


2. Mandatory Execution Sequence

Every engineering task SHALL execute in this order:

1. Identify requested operation.
2. Identify required capability.
3. Search for an existing platform implementation (Upstream, Gas City, Pack, Formula, Order, existing Agent).
4. Determine capability owner.
5. Resolve authenticated execution channel (ssh -G blueflyNAS, ssh -G blueflyoracle).
6. Translate host-native paths.
7. Verify repository or runtime identity.
8. Verify current operational state.
9. Execute within ownership boundary.
10. Produce an evidence receipt.

Execution stops immediately when ownership cannot be established. Do not substitute another implementation.


3. Capability Ownership Matrix

Capability Authority Current Projection
Business Logic Repository Git repositories (agent-docker, contractplane-sdk, blu)
Build GitLab CI gitlab_components/build-docker
Artifact Publication GitLab Registry OCI Container Registry (registry.gitlab.com)
Deployment Reconciliation Gas City Invoked today through oracle-deploy CI runner
Runtime Orchestration Gas City Docker Compose (deployments/oracle/docker-compose.yml)
Engineering Workflow Gas City gc CLI, Pack-supplied Agents, Formulas, Orders. gt is temporary legacy plane only.
Policy Cedar / Policy Library Gas City policy evaluation
Reusable Capability PackV2 Formula Packs
Secrets 1Password In-memory resolution via op run --env-file=.env.template
Runtime State Oracle Persistent volumes & running containers

4. Host Path Translation

Engineers and agents MUST translate paths for the target capability host:

macOS Workstation:  /Volumes/AgentPlatform/...
blueflyNAS:         /volume1/AgentPlatform/...
blueflyOracle:      /opt/bluefly/...
  • Never report Repository not found until host path translation has been attempted.
  • Authority is determined by capability ownership, never by host visibility.

5. Engineering Authority Chain & Lifecycle

ENGINEERING AUTHORITY CHAIN

Repository (Owner: Repository)
    ↓
Git (Owner: Git)
    ↓
GitLab (Owner: GitLab)
    ↓
GitLab CI (Owner: GitLab CI)
    ↓
GitLab Registry (Owner: GitLab Registry)
    ↓
Gas City (Owner: Gas City)
    ↓
Oracle Runtime (Owner: Oracle)
    ↓
Gas City Verification (Owner: Gas City)
    ↓
Engineering Receipt (Owner: Governance)

6. Machine-Readable Compliance Audit Template

Every task execution audit concludes with this standardized compliance block:

STD-EXEC-001 COMPLIANCE

Capability Resolution: PASS | FAIL | N/A
Owner Selection:       PASS | FAIL | N/A
Execution Host:        PASS | FAIL | N/A
Reuse Check:           PASS | FAIL | N/A
Evidence Standard:     PASS | FAIL | N/A
Stopping Condition:    PASS | FAIL | N/A
Receipt Structure:     PASS | FAIL | N/A

Overall:
COMPLIANT | NON-COMPLIANT

7. Execution Receipt Specification

EXECUTION HOST
Host: <host>
Execution Method: <channel>
Capability: <capability>
Repository or Runtime: <target>

VERIFIED
<Command-proven facts only>

CHANGED
<Exactly what changed>

PIPELINE
<Pipeline state if applicable>

BLOCKERS
<Verified blockers only>

NEXT READY WORK
<Exactly one executable next step>

8. Inference Execution Authority

Oracle remains the agent execution and orchestration authority.

External model providers MAY include: - Anthropic - OpenAI - Google - LiteLLM-routed providers - UM790-hosted Ollama/local models

Remote inference does not confer work authority.

MODEL_HOST != AGENT_HOST
MODEL_HOST != GAS_CITY_AUTHORITY
MODEL_HOST != BEADS_AUTHORITY

Gas City Agents execute entirely within the Oracle execution authority. Inference requests are strictly routed compute queries, not a transfer of operational control or orchestrator status to the inference machine.

Example topology:

Gas City Agent on Oracle
       │
       │ requests inference
       ▼
     LiteLLM
       │
       ├── Anthropic
       ├── OpenAI
       ├── Gemini
       └── UM790/Ollama


9. Workstation Authority Constraint

The human terminal (e.g., mac-m4, blu, or any other human endpoint) is a strictly ephemeral client.

It holds ZERO authority over source, runtime, orchestration, or inference.

Factory infrastructure (Gateways, Runners, Proxies, Gas City, Beads, routing) MUST NEVER be configured to depend on a human workstation being awake, reachable, or active. If a human terminal drops off Tailscale, the Factory must not notice or care.


Amendment history

Version Date Change
1.0 2026-07-24 Initial Frozen constitution.
1.1 2026-09-09 Execution precedence and ownership aligned to current docs.gascity.com six primitives. Engineering Workflow authority is Gas City (gc, Packs, Formulas, Orders). gt is temporary Oracle legacy plane, not an execution owner. Verification is Beads under the city Dolt topology, not a Gas Town platform layer.
1.2 2026-09-23 Added §8 Inference Execution Authority (MODEL_HOST != AGENT_HOST) and §9 Workstation Authority Constraint (human terminals hold zero factory authority).