STD-INFRA-001: Multi-Cloud Infrastructure & Configuration as Code Standard¶
Status: Canonical & Binding
Standard ID: STD-INFRA-001
Owner: Blu (kingstown-core.blu) — Director
Target Environments: AWS, GCP, Azure, OCI, Bare-Metal, Customer Cloud Enclaves
1. Prime Directive¶
The Bluefly Factory (Gas City ↔ ContextControl ↔ Drupal) is pure Infrastructure as Code (IaC) and Configuration as Code (CaC). It must deploy deterministically to any customer cloud (AWS, GCP, Azure, Oracle, or private enclaves) without host-specific hardcoding, ad-hoc shell patches, or manual configuration.
PORTABLE_CITY_CONFIG (city.toml) = ENVIRONMENT_AGNOSTIC
MACHINE_LOCAL_BINDING (site.toml) = GENERATED_BY_IAC
HOST_PATH_HARDCODING = PROHIBITED
MANUAL_HOST_MUTATION = PROHIBITED
CLOUD_DEPLOYMENT_METHOD = TERRAFORM_OR_OPENTOFU + CLOUD_INIT
CONTAINER_RUNTIME = OCI_COMPLIANT (DOCKER_COMPOSE / K8S / HELM)
2. The Four Portability Pillars¶
┌─────────────────────────────────────────────────────────────────────────────┐
│ PORTABLE CITY CONFIG (city.toml) │
│ Rigs (names only), Packs, Formulas, Orders, Webhook Rules │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ MACHINE-LOCAL SITE BINDING (.gc/site.toml) │
│ Rig File System Paths, Service Ports, Endpoint Binding │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ PROVIDER-NEUTRAL IA C (Terraform / OpenTofu) │
│ Compute (AWS EC2/EKS, GCP Compute/GKE, OCI Instance), Network │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────────────────┐
│ PRIVATE EDGE SECURITY BOUNDARY │
│ Loopback API (127.0.0.1:8372) + Private Edge Proxy (Tailscale / CF) │
└─────────────────────────────────────────────────────────────────────────────┘
Pillar 1: Declarative City Portability (city.toml)¶
city.tomldefines portable rig names, pack imports, orders, and webhook routing.- NO host-specific paths (e.g.
/opt/bluefly/...or~) belong incity.toml.
Pillar 2: Machine-Local Site Generation (.gc/site.toml)¶
- Machine-local rig filesystem paths belong exclusively in
.gc/site.toml. - Site bindings are generated deterministically during cloud provision via
deploy/<provider>/site-rigs.tomltemplates.
Pillar 3: Provider-Neutral Infrastructure Modules¶
- Infrastructure is defined using modular Terraform / OpenTofu under
deploy/<provider>/(AWS, GCP, OCI, Azure). - Provisioning installs the standard Gas City supervisor (
gc), Dolt SQL server (127.0.0.1:3308), and Drupal ContextControl container stack in a single automated step.
Pillar 4: Hardened Edge Security & Endpoint Provenance¶
- Gas City API (
127.0.0.1:8372) remains loopback-bound. - Access routes through a trusted private edge (
factory.<customer-domain>) via Tailscale MagicDNS, Cloudflare Access, AWS ALB with OIDC, or GCP IAP. - Inbound external webhooks route via rate-limited edge (
hooks.<customer-domain>).
3. Supported Cloud Provider Matrix¶
| Cloud Provider | IaC Module Path | Runtime Compute | Network / Security Boundary |
|---|---|---|---|
| AWS | deploy/aws/ |
EC2 / EKS | AWS VPC + ALB OIDC / Tailscale Subnet Router |
| GCP | deploy/gcp/ |
Compute Engine / GKE | GCP VPC + IAP / Cloudflare Tunnel |
| Oracle (OCI) | deploy/oracle/ |
Compute Instance | OCI VCN + Tailscale |
| Bare-Metal / Hybrid | deploy/common/ |
Docker Compose / K3s | Private Network / Tailscale |
4. Multi-Cloud Deployment Lifecycle¶
1. TERRAFORM / OPENTOFU PROVISIONING
└── Provision VPC, Compute, Storage, Security Groups, IAM Roles.
2. CLOUD-INIT CA C BOOTSTRAP
└── Install Docker, Gas City CLI (gc), Dolt SQL server.
└── Clone canonical source repos (BluCity, BluCity-Packs, BluCity-Docs).
└── Render machine-local .gc/site.toml from deploy/<provider>/site-rigs.toml.
3. GOVERNED SITE BINDING
└── Run `gc beads city use-external --host 127.0.0.1 --port 3308 --database hq`.
└── Execute `gc doctor managed_city origin`.
4. CONTAINER STACK STARTUP
└── Launch Docker Compose stack (`deploy/common/docker-compose.factory-runtime.yml`).
└── Start Gas City supervisor (`gc start`).
5. PRIVATE EDGE ACTIVATION
└── Connect Private Edge Proxy (factory.<customer-domain>).
└── Register ContextControl ECA event subscriber endpoints.
5. Compliance & Audit Verification¶
Every customer cloud deployment MUST pass validation via gc doctor:
gc doctor # Verify pack loader, agent definitions, and orders
gc doctor managed_city origin # Verify managed city endpoint provenance
bd info # Confirm central Dolt SQL server binding (127.0.0.1:3308/hq)