Skip to content

Oracle Production Delivery Convergence Program

Ultimate Outcome: ORACLE_REPLACEABLE=YES. If the host dies, you must be able to recreate it from GitLab + registries + IaC, reconnect the durable Beads authority from a proven restore, remount the NAS-backed durable workspace where required, and continue without recovering random local Git state from the dead machine.

NON-NEGOTIABLE INVARIANTS

ORACLE_GASCITY_AUTHORITY=YES
ORACLE_DOLT_AUTHORITY=YES

MAC_IS_OPERATOR_CLIENT=YES
MAC_GASCITY_AUTHORITY=NO
MAC_DOLT_AUTHORITY=NO

NAS_IS_DURABILITY/WORKSPACE=YES
NAS_IS_SCHEDULER=NO

GITLAB_IS_SOURCE_AUTHORITY=YES
BEADS_IS_DURABLE_WORK_AUTHORITY=YES

TARGET_ORACLE_PRODUCTION_SOURCE_CHECKOUTS_REQUIRED=0
CURRENT_ORACLE_SOURCE_CHECKOUTS_REQUIRED=UNKNOWN_UNTIL_DEPENDENCIES_REMOVED

ORACLE_MANUAL_DEPLOYMENT=NO

THE RECOVERY FINDING (Why P0A exists)

The current Beads backup is not recoverable.

BACKUP_EXISTS=YES
RESTORE=FAIL

FAILURE_1=
required custom Beads types are not packaged with the export

FAILURE_2=
export is not referentially closed

ORPHAN_CHILDREN=6

Goal: BEADS_DISASTER_RECOVERY_PROVEN=YES The restore must work on a fresh host or isolated target: 1. Restore package loaded. 2. Config/schema recognized. 3. Referential integrity valid. 4. Known records present. 5. Semantic counts sane. 6. Gas City can use restored authority.

CONVOY DIRECTIVE & GRAPH

P0A Beads Restore Contract ───────────────┐
                                         │
P0B Disk Runway ─────────────────────────┤
                                         │
Seed 1 Estate Classification ────────────┤
                                         ↓
Seed 2 Artifact / Provenance Contract
                ↓
Seed 3 OpenClaw Reference Implementation
                ↓
Seed 4 Marketplace + LiteLLM
                ↓
Seed 5 Bluefly Platform Services
                ↓
Seed 6 Third-Party Infrastructure
                ↓
Seed 7 Remove Checkout Dependencies
                ↓
Seed 8 Production Deployment Gate
                ↓
Seed 9 Immutable Rollback Proof
                ↓
Seed 10 Witness Estate Acceptance

(Note: P0A/P0B do not wait for Seed 1; recovery continues in parallel with delivery convergence.)

ACCEPTANCE GATES

Gate 1 — No Checkout Deletion

CHECKOUT_REMOVAL_ALLOWED=YES
only if:

RUNTIME_DEPENDENCY_REMOVED=YES
IMMUTABLE_ARTIFACT_DEPLOYED=YES
ROLLBACK_PROVEN=YES
WITNESS_VERIFIED=YES

Gate 2 — No Production Claim Without Runtime Equivalence

DEPLOYMENT_COMPLETE=YES
only if:

SOURCE_COMMIT_KNOWN=YES
ARTIFACT_DIGEST_KNOWN=YES
EXPECTED_RUNTIME_DIGEST=<expected>
OBSERVED_RUNTIME_DIGEST=<actual>
EXPECTED==OBSERVED
FUNCTIONAL_CHECK=PASS
WITNESS_PASS=YES

AUTHORITY SEPARATION

  • GitLab = source
  • main/tag = approved production provenance
  • registry = immutable artifact
  • IaC = host/deployment projection
  • agent-docker = runtime definition
  • Oracle = execution
  • Mayor = runtime observation
  • Witness = independent verification

PROHIBITED ACTIONS

NO: - git pull on Oracle - git stash on Oracle - git checkout on Oracle - git reset on Oracle - manual Docker pull - manual compose pull - manual config edit - manual container restart as deployment - manual source mutation - checkout deletion before dependency removal