Gas City Command Execution Trust Boundaries¶
Scope: Every Gas City execution surface Bluefly runs against — city config, imported Packs, exec provider scripts, agent startup commands, hooks, order checks/exec, and gc sling//sling.
Upstream authority: docs.gascity.com/reference/trust-boundaries. This document does not define Gas City's execution or trust model — Gas City owns that contract. The body below is Gas City's own published doctrine, reproduced here verbatim because Bluefly agents author providers, hooks, order exec, and sling commands against these surfaces and need the rules inline, not one click away.
Attribution: Gas City upstream doctrine, not Bluefly-authored. Do not edit the reproduced body to change its substance — only update this file's own frontmatter/cross-link scaffolding. If upstream revises the doctrine, replace the body wholesale and note the source revision, do not hand-patch it out of sync with upstream.
Bluefly's own related, Bluefly-authored constitutions build on top of this doctrine rather than restating it: Authentication & Secrets Constitution (1Password authority, secret reference rules) and Tools Standard (op run vs op read, proving secret state without revealing it). Where those documents and this one overlap on secret hygiene, this document is the Gas City-side execution-surface authority; the Bluefly constitutions are the 1Password/operator-side authority. Also see the Bluefly-side execution-diagnostics rule (SECRET-SAFE HTTP AND SHELL RULE: curl -v/--trace/--include/set -x/bash -x banned for credential-bearing commands) enforced locally in agent tooling — same principle, applied to HTTP/shell diagnostics rather than Gas City exec surfaces.
Cross-referenced from: BluCity Operator Contract §11 Order, §14 Agent, §16 Provider, §17 Hook, §18 Sling; and Gas City Adoption.
Gas City Upstream Doctrine (verbatim)¶
Gas City intentionally runs operator-configured commands. Those commands are a feature, not a sandbox. Treat city config, imported packs, exec provider scripts, and agent startup commands as trusted code with the same review expectations as shell scripts committed to the repository.
Trust model¶
- Maintainer-authored city config and local site config: Trusted operator code. May define shell commands and explicit env. Review before use.
- Imported packs and rig configs: Trusted dependency code. Pin/review packs before importing into a privileged city.
- Bead titles, descriptions, mail, formula vars, PR text, and API request fields: Untrusted data. Do not concatenate into shell commands. Pass as env, JSON, stdin, or argv.
- GitHub Actions
pull_request_targetpayloads: Untrusted data in a privileged workflow. Do not checkout or execute contributor code. Use metadata-only operations. - Ambient process environment: Untrusted for secret propagation. Orchestrator-side shell helpers strip inherited secret-looking env keys by default.
Execution surfaces¶
| Surface | Command source | Actor | Working directory | Env behavior | Log behavior |
|---|---|---|---|---|---|
work_query via gc hook and orchestrator probes |
Agent config | Trusted operator or pack | Agent's canonical city or rig repo | Inherited secrets stripped, Gas City projects explicit store/session env | Errors diagnostic only, avoid secrets in command literals |
scale_check |
Agent config | Trusted operator or pack | Agent's canonical city or rig repo | Inherited secrets stripped, explicit store env | Parse failures include command context, command literals must not contain secrets |
on_boot and on_death |
Agent pool config | Trusted operator or pack | City or rig repo | Inherited secrets stripped, explicit store env may be provided | Hook failures logged, output should not include secrets |
| Order check triggers | Order config | Trusted operator or pack | Order target scope | Inherited secrets stripped, explicit condition env may be provided | Failure reason records exit status not command output |
| Order exec | Order config | Trusted operator or pack | Order target scope | Inherited secrets stripped, explicit order env may be provided | Failure errors and output redacted before logs/events |
gc sling and /sling command runner |
Sling target config | Trusted operator or pack | City or rig repo | Inherited secrets stripped, explicit routing/store env may be provided | Returned command output is caller-visible, do not route untrusted text into shell |
| Agent command | Agent config | Trusted operator or pack | Session work directory | Session env is explicit runtime env plus configured env, secrets may be passed only by intentional config | Agent stdout/stderr is session output, may be visible to operators |
pre_start |
Agent config | Trusted operator or pack | Session work directory | Provider-specific runtime env, intended for setup before session start | Provider warnings should avoid secrets |
session_setup, session_setup_script, session_live |
Agent config | Trusted operator or pack | Running session environment | Provider-specific runtime env, remote providers run inside target container or pod | Provider warnings should avoid secrets |
| exec: session provider | User-supplied provider script | Trusted operator code | Provider-defined | Direct exec not sh -c, start config is JSON on stdin |
Provider stderr may be surfaced in errors, do not print secrets |
| exec: beads, mail, and events providers | User-supplied provider script | Trusted operator code | Provider-defined | Direct exec not sh -c, request data is stdin/argv |
Provider stderr may be surfaced in errors, do not print secrets |
Pack fetch/include, Git probes, Docker, Dolt, tmux, kubectl, bd helpers |
Gas City code plus configured paths/URLs | Maintainer-reviewed code paths | Command-specific | Direct exec with argv except provider setup scripts where documented | Errors surfaced for diagnosis, avoid embedding credentials in URLs |
Secret propagation¶
Orchestrator-side shell helpers remove inherited environment variables whose keys look secret-bearing, including names containing TOKEN, PASSWORD, SECRET, PRIVATE_KEY, API_KEY, ACCESS_KEY, CREDENTIAL, OAUTH, or AUTH_JSON. This prevents ambient CI or maintainer shell secrets from reaching work_query, scale_check, hooks, order checks, order exec commands, and sling helpers by accident. If a command truly needs a secret, pass it explicitly through the relevant city, rig, provider, or workflow configuration. Explicit values are preserved because they represent an operator decision, and failure logs redact known secret values before writing order exec errors or events.
Rules for authors¶
- Do not put secrets directly in command strings. Use env variables or provider credential files.
- Do not interpolate bead content, PR text, mail, formula vars, branch names, or other user-controlled values into
sh -ccommands. - When showing a command for a human to copy, build it from argv and quote each argument with Gas City's shell quoting helper.
- Keep
pull_request_targetworkflows metadata-only. They may label or comment but must not checkout or run contributor code with privileged tokens. - Prefer direct
exec.Command(..., args...)style boundaries for new provider contracts. Usesh -conly for explicitly operator-authored shell snippets.
Why this is in BluCity-Docs and not link-only¶
ADR-0008 and Gas City Adoption establish "one authority, many projections — link, do not rewrite" for Gas City product behavior (CLI, config schema, formulas, troubleshooting), because that behavior changes and a local paraphrase drifts. This document is different in kind: it is a fixed security contract governing how any author — Gas City core, a Pack, or a Bluefly agent — must write exec surfaces. Bluefly agents write provider scripts, order exec, hooks, and sling handlers against these exact surfaces today, so the full rule set is reproduced here rather than left as an external link only. If upstream revises the trust model, this file must be re-synced from source, not hand-patched independently.