Production Deployment Law & Provenance Standard¶
1. Core Invariant & Authority Rule¶
STOP TREATING ORACLE (OR ANY PRODUCTION RUNTIME) AS A DEVELOPMENT CHECKOUT.
PROHIBITED ON PRODUCTION:
❌ ssh → git pull
❌ ssh → git checkout branch
❌ ssh → edit configuration/source
❌ ssh → docker compose pull / restart
❌ Production-local source mutation
REQUIRED PRODUCTION PATHWAY:
GITLAB (Source Authority: main)
│
▼
CI / TEST (Quality Gate)
│
▼
APPROVED RELEASE / PROMOTION TAG
│
▼
IMMUTABLE ARTIFACT (Locked Container Digest / Release Package)
│
▼
IAC / AGENT-DOCKER (Host & Runtime Projection)
│
▼
ORACLE RUNTIME (Disposable Execution Layer)
│
▼
VERIFICATION (MAYOR / WITNESS Acceptance)
Oracle consumes RELEASED OUTPUT — never developer branches, release/v0.1.x, MR branches, or local checkouts.
2. Allowed Production Inputs¶
Production deployments may be derived ONLY from:
1. main commit (promoted from tested release).
2. An approved, immutable release tag.
3. An immutable GitLab artifact/package in the GitLab Package Registry.
4. An immutable container digest (registry.gitlab.com/...@sha256:<digest>) produced by approved GitLab CI.
Final Runtime Identity:¶
$$\text{Runtime Identity} = \text{TAG} + \text{ARTIFACT VERSION} + \text{CONTAINER DIGEST}$$
Strictly Prohibited Sources:¶
feature/*release/v0.1.x(Integration branch only; NOT a production source)- MR branches
- Developer worktrees
- Local workstation checkouts
- Oracle-local checkouts
- Detached arbitrary commits not represented by a governed release
3. Branch Promotion & Release Sequence¶
DEVELOPMENT:
feature/* ──► MR ──► release/v0.1.x (Integration & Testing)
PROMOTION:
release/v0.1.x ──► Promotion MR ──► main (Human Gate / Approval)
PRODUCTION:
main
│
▼
GitLab CI Tag & Build
│
├── Container Registry ──► OCI image @ sha256:<digest>
├── Package Registry ──► Versioned Release Bundle / Binary
└── Generic Registry ──► Configuration / Systemd Manifests
│
▼
IaC / agent-docker Deployment
│
▼
Oracle Execution Layer
│
▼
MAYOR & WITNESS Independent Verification
4. Responsibility Boundaries¶
| Layer | Repository / Authority | Responsibilities |
|---|---|---|
| Orchestration | BLU / Gas City |
Cross-fleet coordination, work tracking (bd), priority routing |
| CI & Release | REFINERY / GitLab CI |
Building, testing, tagging, publishing immutable packages & digests |
| Runtime Def | agent-docker |
Container manifests, locked image digests, healthchecks, systemd projections, volumes, resource limits |
| Host Infra | IaC (Terraform/Cloud-Init) |
VM provisioning, network, storage, dependencies, bootstrap, deployment invocation, drift detection |
| Runtime Obs | MAYOR |
Oracle production observation, fact board, deploy acceptance |
| Audit & Proof | WITNESS |
Independent verification of commit, tag, artifact, and digest provenance |
5. Deployment & Rollback Contract¶
Deployment Receipt Requirement:¶
Every production deployment must record:
PROJECT=
SOURCE_COMMIT=
SOURCE_BRANCH=main
SOURCE_TAG=
PIPELINE_ID=
DEPLOY_JOB=
ARTIFACT=
ARTIFACT_VERSION=
ARTIFACT_DIGEST=
CONTAINER_IMAGE=
CONTAINER_DIGEST=
IAC_COMMIT=
AGENT_DOCKER_COMMIT=
TARGET_HOST=
DEPLOYED_AT=
PREVIOUS_VERSION=
NEW_VERSION=
HEALTHCHECK=
FUNCTIONAL_CHECK=
ROLLBACK_ARTIFACT=
DRIFT_AFTER_DEPLOY=0
Rollback Contract:¶
Rollback means selecting the previous known-good immutable artifact/digest and executing a governed deployment. Rollback is NEVER git reset, git checkout, git stash, or manual file manipulation on the production host.
6. Client vs Gateway Architecture (e.g. OpenClaw)¶
Workstations (Mac, iPad, Phone) are clients: $$\text{Mac / iPad / Phone} \longrightarrow \text{wss://claw.copaw.us} \longrightarrow \text{Oracle OpenClaw Gateway} \longrightarrow \text{NAS Workspace}$$
Workstations MUST NOT run local docker exec wrappers or impersonate the Oracle gateway. All client tooling connects through the authorized remote gateway endpoint (OPENCLAW_GATEWAY_URL).