STD-GC-004: IAC & AGENT-DOCKER GOVERNED DEPLOYMENT LAW¶
Status: APPROVED & BINDING
Authority: Thomas / Infrastructure as Code Operating Law
Applies To: All Cloud Infrastructure, Traefik Routers, Cloudflare Tunnels, Docker Containers, and Oracle Deployments
1. Prime Directive¶
MANUAL SSH SERVER HACKS = DISALLOWED & ZERO-TOLERANCE FAILURE
GOVERNED IAC PIPELINE:
Source Edit (BluCity-Packs / iac / agent-docker)
↓
Local / CI Validation (gc lint / docker compose config / validation pipeline)
↓
GitLab MR -> release/v0.1.x
↓
Governed Order / Formula Execution on Oracle (gc order / gc formula)
No manual SSH config editing, docker run, or ad-hoc container mutations on production hosts. All infrastructure changes MUST be versioned code in governed repositories.
2. Infrastructure Ownership Map¶
| Layer / Concern | Governing Repository / Pack | Deployment Mechanism |
|---|---|---|
| Traefik Routers & Edge Proxy | BluCity-Packs/platform/docker (iac) |
Governed release pipeline / docker compose |
| Cloudflare Tunnels & DNS | BluCity-Packs/platform/agent-tailscale |
Cloudflare API / IaC token config |
| Agent Container Images | infra/agent-docker |
CI build -> GitLab Container Registry |
| Gas City Rigs & Services | BluCity-Packs (pack.toml, orders/, formulas/) |
gc pack import / gc order dispatch |
| Dolt Topology & Bindings | deploy/oracle/beads-topology.yaml |
gc-site-bind / gc beads city use-external |
3. IaC Workflow for Routing Fixes (e.g. city.blutown.ai)¶
When an edge route returns 502 or requires port/proxy updates:
- Locate IaC Asset:
Identify the Traefik / Nginx dynamic route file or Docker Compose file in
BluCity-Packs/platform/docker/. - Author Code Fix:
Update the router entry (e.g. binding
city.blutown.aiservice upstream tohttp://127.0.0.1:8372or internal container network). - Validate Locally:
Run
gc pack lintanddocker compose configlocally to ensure zero syntax errors. - Submit Governed Change:
Commit to feature branch, push, and open MR against
release/v0.1.x. - Execute Governed Deployment: Merge MR after CI verification; dispatch the deployment formula to apply the change to Oracle.