Oracle Production Delivery Convergence Program¶
Ultimate Outcome: ORACLE_REPLACEABLE=YES. If the host dies, you must be able to recreate it from GitLab + registries + IaC, reconnect the durable Beads authority from a proven restore, remount the NAS-backed durable workspace where required, and continue without recovering random local Git state from the dead machine.
NON-NEGOTIABLE INVARIANTS¶
ORACLE_GASCITY_AUTHORITY=YES
ORACLE_DOLT_AUTHORITY=YES
MAC_IS_OPERATOR_CLIENT=YES
MAC_GASCITY_AUTHORITY=NO
MAC_DOLT_AUTHORITY=NO
NAS_IS_DURABILITY/WORKSPACE=YES
NAS_IS_SCHEDULER=NO
GITLAB_IS_SOURCE_AUTHORITY=YES
BEADS_IS_DURABLE_WORK_AUTHORITY=YES
TARGET_ORACLE_PRODUCTION_SOURCE_CHECKOUTS_REQUIRED=0
CURRENT_ORACLE_SOURCE_CHECKOUTS_REQUIRED=UNKNOWN_UNTIL_DEPENDENCIES_REMOVED
ORACLE_MANUAL_DEPLOYMENT=NO
THE RECOVERY FINDING (Why P0A exists)¶
The current Beads backup is not recoverable.
BACKUP_EXISTS=YES
RESTORE=FAIL
FAILURE_1=
required custom Beads types are not packaged with the export
FAILURE_2=
export is not referentially closed
ORPHAN_CHILDREN=6
Goal: BEADS_DISASTER_RECOVERY_PROVEN=YES
The restore must work on a fresh host or isolated target:
1. Restore package loaded.
2. Config/schema recognized.
3. Referential integrity valid.
4. Known records present.
5. Semantic counts sane.
6. Gas City can use restored authority.
CONVOY DIRECTIVE & GRAPH¶
P0A Beads Restore Contract ───────────────┐
│
P0B Disk Runway ─────────────────────────┤
│
Seed 1 Estate Classification ────────────┤
↓
Seed 2 Artifact / Provenance Contract
↓
Seed 3 OpenClaw Reference Implementation
↓
Seed 4 Marketplace + LiteLLM
↓
Seed 5 Bluefly Platform Services
↓
Seed 6 Third-Party Infrastructure
↓
Seed 7 Remove Checkout Dependencies
↓
Seed 8 Production Deployment Gate
↓
Seed 9 Immutable Rollback Proof
↓
Seed 10 Witness Estate Acceptance
(Note: P0A/P0B do not wait for Seed 1; recovery continues in parallel with delivery convergence.)
ACCEPTANCE GATES¶
Gate 1 — No Checkout Deletion¶
CHECKOUT_REMOVAL_ALLOWED=YES
only if:
RUNTIME_DEPENDENCY_REMOVED=YES
IMMUTABLE_ARTIFACT_DEPLOYED=YES
ROLLBACK_PROVEN=YES
WITNESS_VERIFIED=YES
Gate 2 — No Production Claim Without Runtime Equivalence¶
DEPLOYMENT_COMPLETE=YES
only if:
SOURCE_COMMIT_KNOWN=YES
ARTIFACT_DIGEST_KNOWN=YES
EXPECTED_RUNTIME_DIGEST=<expected>
OBSERVED_RUNTIME_DIGEST=<actual>
EXPECTED==OBSERVED
FUNCTIONAL_CHECK=PASS
WITNESS_PASS=YES
AUTHORITY SEPARATION¶
- GitLab = source
- main/tag = approved production provenance
- registry = immutable artifact
- IaC = host/deployment projection
- agent-docker = runtime definition
- Oracle = execution
- Mayor = runtime observation
- Witness = independent verification
PROHIBITED ACTIONS¶
NO: - git pull on Oracle - git stash on Oracle - git checkout on Oracle - git reset on Oracle - manual Docker pull - manual compose pull - manual config edit - manual container restart as deployment - manual source mutation - checkout deletion before dependency removal