Skip to content

Production Deployment Law & Provenance Standard

1. Core Invariant & Authority Rule

STOP TREATING ORACLE (OR ANY PRODUCTION RUNTIME) AS A DEVELOPMENT CHECKOUT.

PROHIBITED ON PRODUCTION:
❌ ssh → git pull
❌ ssh → git checkout branch
❌ ssh → edit configuration/source
❌ ssh → docker compose pull / restart
❌ Production-local source mutation

REQUIRED PRODUCTION PATHWAY:
GITLAB (Source Authority: main)
   │
   ▼
CI / TEST (Quality Gate)
   │
   ▼
APPROVED RELEASE / PROMOTION TAG
   │
   ▼
IMMUTABLE ARTIFACT (Locked Container Digest / Release Package)
   │
   ▼
IAC / AGENT-DOCKER (Host & Runtime Projection)
   │
   ▼
ORACLE RUNTIME (Disposable Execution Layer)
   │
   ▼
VERIFICATION (MAYOR / WITNESS Acceptance)

Oracle consumes RELEASED OUTPUT — never developer branches, release/v0.1.x, MR branches, or local checkouts.


2. Allowed Production Inputs

Production deployments may be derived ONLY from: 1. main commit (promoted from tested release). 2. An approved, immutable release tag. 3. An immutable GitLab artifact/package in the GitLab Package Registry. 4. An immutable container digest (registry.gitlab.com/...@sha256:<digest>) produced by approved GitLab CI.

Final Runtime Identity:

$$\text{Runtime Identity} = \text{TAG} + \text{ARTIFACT VERSION} + \text{CONTAINER DIGEST}$$

Strictly Prohibited Sources:

  • feature/*
  • release/v0.1.x (Integration branch only; NOT a production source)
  • MR branches
  • Developer worktrees
  • Local workstation checkouts
  • Oracle-local checkouts
  • Detached arbitrary commits not represented by a governed release

3. Branch Promotion & Release Sequence

DEVELOPMENT:
  feature/* ──► MR ──► release/v0.1.x (Integration & Testing)

PROMOTION:
  release/v0.1.x ──► Promotion MR ──► main (Human Gate / Approval)

PRODUCTION:
  main
   │
   ▼
  GitLab CI Tag & Build
   │
   ├── Container Registry  ──► OCI image @ sha256:<digest>
   ├── Package Registry    ──► Versioned Release Bundle / Binary
   └── Generic Registry    ──► Configuration / Systemd Manifests
   │
   ▼
  IaC / agent-docker Deployment
   │
   ▼
  Oracle Execution Layer
   │
   ▼
  MAYOR & WITNESS Independent Verification

4. Responsibility Boundaries

Layer Repository / Authority Responsibilities
Orchestration BLU / Gas City Cross-fleet coordination, work tracking (bd), priority routing
CI & Release REFINERY / GitLab CI Building, testing, tagging, publishing immutable packages & digests
Runtime Def agent-docker Container manifests, locked image digests, healthchecks, systemd projections, volumes, resource limits
Host Infra IaC (Terraform/Cloud-Init) VM provisioning, network, storage, dependencies, bootstrap, deployment invocation, drift detection
Runtime Obs MAYOR Oracle production observation, fact board, deploy acceptance
Audit & Proof WITNESS Independent verification of commit, tag, artifact, and digest provenance

5. Deployment & Rollback Contract

Deployment Receipt Requirement:

Every production deployment must record:

PROJECT=
SOURCE_COMMIT=
SOURCE_BRANCH=main
SOURCE_TAG=
PIPELINE_ID=
DEPLOY_JOB=
ARTIFACT=
ARTIFACT_VERSION=
ARTIFACT_DIGEST=
CONTAINER_IMAGE=
CONTAINER_DIGEST=
IAC_COMMIT=
AGENT_DOCKER_COMMIT=
TARGET_HOST=
DEPLOYED_AT=
PREVIOUS_VERSION=
NEW_VERSION=
HEALTHCHECK=
FUNCTIONAL_CHECK=
ROLLBACK_ARTIFACT=
DRIFT_AFTER_DEPLOY=0

Rollback Contract:

Rollback means selecting the previous known-good immutable artifact/digest and executing a governed deployment. Rollback is NEVER git reset, git checkout, git stash, or manual file manipulation on the production host.


6. Client vs Gateway Architecture (e.g. OpenClaw)

Workstations (Mac, iPad, Phone) are clients: $$\text{Mac / iPad / Phone} \longrightarrow \text{wss://claw.copaw.us} \longrightarrow \text{Oracle OpenClaw Gateway} \longrightarrow \text{NAS Workspace}$$

Workstations MUST NOT run local docker exec wrappers or impersonate the Oracle gateway. All client tooling connects through the authorized remote gateway endpoint (OPENCLAW_GATEWAY_URL).