NAS-Archivist design¶
Recovered from workstation Scratch on 2026-08-27. Catalog status in catalog/tools.md is Operating. This document is the design the tool was registered from. Logs do not live in Scratch; operator workstation logs stay off-tree.
NAS-Archivist Design & Implementation Plan¶
Status: Design Phase (Blocked by Bead requirement)
Author: NAS-Archivist persona
Date: 2026-08-10
Authority: Bluefly Engineering Standard, AGENTS.md
Executive Summary¶
NAS-Archivist is a governed agent and CLI tool that stewards the Synology NAS as the authoritative repository store. It audits Git estate health, verifies backups independently, enables safe repository reconciliation, and prevents destructive mutations through explicit governance gates.
Core mission: NAS = authoritative storage. Never hide, discard, or destroy work.
Problem Statement¶
Current state: - NAS stores canonical project repositories but lacks stewardship - No systematic audit of Git estate (clean/dirty/ahead/behind/diverged states) - No verification of Hyper Backup snapshots or BTRFS recovery integrity - Manual Git operations risk losing uncommitted work - No audit trail for repository mutations
Required capabilities: 1. Inventory NAS shares without exposing private contents 2. Classify Git repositories by state (CLEAN, BEHIND, AHEAD, DIRTY, DETACHED, DIVERGED) 3. Safely fetch without auto-merge 4. Fast-forward BEHIND repos only with explicit approval 5. Verify snapshots/backups independently of Git 6. Create worktrees in canonical location for isolated work 7. Generate eight-field execution receipts for all operations 8. Block destructive operations and report blockers
Architecture¶
Components¶
1. CLI Commands (extend blu-cli)¶
Path: /Volumes/AgentPlatform/Applications/__BLU/blu-cli/src/commands/nas.ts
Commands:
- blu nas shares list — enumerate shares
- blu nas repos audit [--detail] — classify all repositories
- blu nas repos fetch [--all] — fetch all remotes
- blu nas repos reconcile <path> [--approve-ff] — fast-forward single repo
- blu nas worktree create <path> <branch> — create isolated worktree
- blu nas backup verify [--snapshot <date>] — verify backup integrity
- blu nas receipt show <id> — emit execution receipt
2. Agent Definition (OSSA v0.4)¶
Path: Canonical agent source (TBD: BluTown or platform-agents)
apiVersion: ossa/v0.4
kind: Agent
metadata:
name: nas-archivist
version: "1.0.0"
description: NAS repository steward and backup verifier
spec:
role: NAS repository maintenance and governance authority
capabilities:
- name: share_inventory
description: List NAS shares without exposing private contents
- name: git_estate_audit
description: Classify repositories by state (CLEAN/BEHIND/AHEAD/DIRTY/DETACHED/DIVERGED)
- name: safe_fetch
description: Fetch remotes without auto-merge or push
- name: reconciliation
description: Fast-forward BEHIND repositories with explicit approval
- name: backup_verification
description: Verify Hyper Backup snapshots and BTRFS recovery
- name: worktree_management
description: Create isolated worktrees in canonical location
- name: governance_receipts
description: Emit eight-field execution receipts
3. Skill Definition¶
Path: Engineering-Standard/tools/nas-archivist/skill.md
Teaches agent to:
- Use blu nas commands
- Interpret state classifications
- Apply Bluefly governance model
- Generate execution receipts
- Stop on blockers
4. Automation (workstation scheduler)¶
Path: ~/.config/launchd/com.bluefly.nas-archivist.plist
Runs daily NAS audit + backup verification:
- 0200 UTC: full Git estate audit
- 0400 UTC: backup snapshot verification
- Never auto-pushes or auto-merges
- Logs off-tree on the operator workstation (not Scratch, not the Git tree)
5. Documentation¶
Locations:
- Engineering-Standard/catalog/tools.md — register NAS-Archivist as a tool
- Engineering-Standard/reference/NAS-Operations.md — operational procedures
- Engineering-Standard/infrastructure/NAS-Governance.md — governance model
NAS Share Inventory¶
Current Mounts (verified 2026-08-10)¶
| Share | Mount | Authority | Type | Status |
|---|---|---|---|---|
| AgentPlatform | /Volumes/AgentPlatform |
Engineering Platform | Docs, runtime, config | ACTIVE |
| web | /Volumes/web |
Web Authority | Published web apps | ACTIVE |
| web_packages | /Volumes/web_packages |
Package Registry | npm, packages | ACTIVE |
| docker | /Volumes/docker |
Docker Authority | Services, volumes | ACTIVE |
| chat | /Volumes/chat |
Chat Authority | Chat services | ACTIVE |
| home | /Volumes/home |
User Authority | User homes | ACTIVE |
| homes | /Volumes/homes |
User Authority | User homes | ACTIVE |
| MinimServer | /Volumes/MinimServer |
Media Authority | DLNA media | ACTIVE |
| PlexMediaServer | /Volumes/PlexMediaServer |
Media Authority | Plex media | ACTIVE |
| TimeMachine | /Volumes/TimeMachine |
Backup Authority | Time Machine | ACTIVE |
AgentPlatform Directory Boundaries¶
| Directory | Authority | Type | Git Repos? |
|---|---|---|---|
| Applications/ | Git | Source Code | YES |
| BluTown/ | Gas Town | Runtime | YES (monitoring) |
| BluCity-Docs/ | Docs Repo | Documentation | YES |
| Evidence/ | Evidence Engine | Generated | NO |
| Config/ | IaC | Configuration | NO |
| Knowledge/ | Knowledge Base | Curated Docs | YES (wiki) |
| Scratch/ | None | Disposable | NO |
| .agents/ | Agent Runtime | Runtime State | YES (OSSA) |
| .beads/ | Beads | Runtime State | NO |
| .openclaw/ | OpenClaw | Runtime State | YES (skills) |
| .codegraph/ | CodeGraph | Runtime State | NO |
Git Estate Audit Results (Preliminary)¶
Audit Date: 2026-08-10 22:03 UTC
Scope: /Volumes/AgentPlatform, max depth 6
Status: RUNNING (background task)
Key repositories found: - BluCity-Docs — Git ACTIVE - BluTown — Git ACTIVE - Knowledge (wiki) — Git ACTIVE - Applications/__BLU/* — Git ACTIVE (multiple) - .agents/gitlab-ossa-agent — Git ACTIVE (Kubernetes agent, NOT platform agent) - .openclaw/skills — Git ACTIVE
Full audit results: see NAS-AUDIT.md and nas-audit-2026-08-05.md.
Blockers & Authority¶
Governance Gate (gt-policy)¶
Local BluCity-Docs clone enforces:
- Requirement: Active Bead for all mutations (Edit/Write/Bash)
- Status: NO ACTIVE BEAD
- Resolution: Create Bead via blu work create (requires Oracle connectivity)
- Workaround: None available (gt-policy fails closed)
Infrastructure Gaps¶
- Cedar policy gate bootstrap —
setGateBaseDir()not called - Dolt server unreachable — Oracle Beads database not local
- buildkit not installed — migrating to blu-cli anyway
Impact: Cannot create Beads locally; must work through Oracle or disable gate.
Implementation Phases¶
Phase 1: Read-Only Audit & Design ✓¶
- [x] NAS share inventory
- [x] Git estate classification (audit in progress)
- [x] Backup verification planning
- [x] Governance model definition
- [x] Skill definition
- [x] Agent design
Status: COMPLETE (pending audit results)
Phase 2: Tool Registration & Documentation¶
- [x] Register NAS-Archivist in
Engineering-Standard/catalog/tools.md - [x] Land skill at
Engineering-Standard/tools/nas-archivist/skill.md - [ ] Create operations documentation
- [ ] Update catalog/capabilities if needed
Phase 3: CLI Implementation (BLOCKED)¶
- [ ] Extend
blu-cliwithnascommand group - [ ] Implement
shares list,repos audit,repos fetch,repos reconcile - [ ] Implement
worktree create,backup verify,receipt show - [ ] Add 1Password Connect auth (no
.op-env, no token copies) - [ ] Add off-tree operator logging
Blocker: Requires Bead + git mutations + TypeScript build
Phase 4: Automation & Scheduling (BLOCKED)¶
- [ ] Create
launchdplist for workstation scheduler - [ ] Wire daily audit + backup verification
- [ ] Configure log rotation
- [ ] Test one complete cycle
Blocker: Requires phase 2 & 3 complete
Phase 5: Verification & Runtime Projection (BLOCKED)¶
- [ ] Test read-only audit against real NAS
- [ ] Test backup verification
- [ ] Test worktree creation
- [ ] Generate OSSA runtime projection
- [ ] Register in OpenClaw
Blocker: Requires phase 2 & 3 complete
Governance Model¶
State Machine (Repositories)¶
CLEAN ↔ BEHIND (safe to FF)
↓
DIRTY ──→ BLOCKER (must resolve)
↓
DETACHED ──→ BLOCKER (must resolve)
↓
DIVERGED ──→ BLOCKER (must resolve)
↓
AHEAD ──→ BLOCKER (must approve push)
↓
NO_UPSTREAM ──→ BLOCKER (must configure)
Execution Boundary¶
NAS-Archivist CAN: - Observe and classify - Fetch remotes - Create worktrees - Verify backups - Stop on blockers - Generate receipts
NAS-Archivist CANNOT: - Commit or push - Merge conflicts - Delete branches - Discard work - Authorize mutations beyond scope
Next Steps (Requires Bead)¶
-
Create Bead
blu work create "Platform: NAS-Archivist agent and governance tooling" -
Update Catalog
- Add to
Engineering-Standard/catalog/tools.md -
Create agent registration in OSSA
-
Implement CLI
- Extend
blu-cliwithnascommands -
TypeScript + Zod validation
-
Create Skill
-
This directory:
Engineering-Standard/tools/nas-archivist/skill.md -
Test & Deploy
- Read-only audit on real NAS
- Backup verification
- Scheduler installation
- Runtime projection
Evidence & Verification¶
This directory is the design home. Historical workstation audit dumps from 2026-08-10 were Scratch session files and are not re-homed here. Live NAS evidence: Engineering-Standard/catalog/NAS-AUDIT.md, ledger/verification/nas-audit-2026-08-05.md.
Terminal State¶
Current: Design and skill landed in this directory. CLI (blu nas) and scheduler remain planned.
Do not treat Scratch as the home for this tool.
Verification Checklist¶
- [ ] NAS shares enumerated without private content exposure
- [ ] Git repositories classified by state (audit complete)
- [ ] Backup snapshots verified independently
- [ ] Skill definition validates
- [ ] Agent definition in canonical source
- [ ] CLI commands implemented and tested
- [ ] Automation scheduled and ran once
- [ ] Eight-field receipts generated for all operations
- [ ] No destructive operations performed
- [ ] All blockers recorded and escalated
- [ ] MR merged and CI passed
- [ ] Runtime projection generated