Bluefly.io Rebuild Planning — Historical Record (2026-03 to 2026-06)¶
Status: SUPERSEDED. Retained for provenance only.
Recon bead: bc-vb5z
This file merges three planning documents that previously lived as separate,
overlapping files under products/Agent-Factory/ (formerly products/Site-Factory/):
- BLUEFLY.IO AI-Powered Website Architecture — v3.0, dated 2026-03-30. Content-automation angle: Drupal AI Automators/Agents/Generation applied to bluefly.io's marketing content.
- bluefly.io — Drupal CMS 2.0 Rebuild Plan — prepared 2026-03-21, updated 2026-04-10. Full infrastructure/module-stack/DUADP/OSSA/Cedar/StateMesh execution plan for rebuilding bluefly.io.
- Bluefly Site Factory — Product Architecture — dated 2026-06-20, status DRAFT (never approved). Gas-City-pack-based proposal for a multi-tenant Drupal site-provisioning product ("Site Factory").
All three predate, and have since been superseded by, two later, actively governed product directories:
products/AMCS/Architecture.md— canonical Governed Drupal CMS AI Ecosystem architecture (module stack, Drupal AI, DUADP/OSSA, Gas City factory authority). Verified 2026-09-02, last reviewed 2026-09-10. Its own replacement notice already names document #2 above (01-BLUEFLY-CMS-REBUILD.md, at its pre-rename pathproducts/Site-Factory/BlueflyAgents.com/) and the rescued Manus CMS 2.0 app as "historical inputs, not current architecture" under this same recon bead (bc-vb5z). This merge extends that same classification to documents #1 and #3, which were not explicitly named in that notice but are contemporaneous drafts of the same superseded planning arc.products/Bluefly.io/— canonical, APPROVED (2026-09-11) bluefly.io product index: content model contract (13 editorial bundles, no Paragraphs) and the approved CMS 2.0 site-convergence directive. This is where the bluefly.io content model and migration plan now live.Engineering-Standard/operating-model/factory-operating-contract.md— canonical operating model for building software factories on Gas City/Gas City. This is where the "factory" concept from document #3 has since been formalized.
Do not treat any module install order, DUADP/OSSA/StateMesh/Cedar specification, Gas
City pack taxonomy, or content-automation prescription below as current. Read it as dated
planning history only. The one exception is the bluefly.io site audit captured in
Document II §Part 1 (live content types, taxonomies, webforms, navigation as observed in
March 2026) — that is a factual snapshot, not architecture, and may still have reference
value; cross-check it against products/Bluefly.io/content-model-contract.md before relying
on it, since the site has since changed.
Historical Document I — BLUEFLY.IO AI-Powered Website Architecture¶
Original path: products/Agent-Factory/BlueflyAgents.com/bluefly-ai-powered-architecture.md. Version 3.0, dated 2026-03-30.
BLUEFLY.IO AI-POWERED WEBSITE ARCHITECTURE¶
Leveraging Drupal AI 1.3.0+ Ecosystem for Automated Content Management¶
Version: 3.0 - AI-Enhanced
Date: March 30, 2026
Revolutionary Shift: From manual content creation to AI-automated, self-maintaining website
EXECUTIVE SUMMARY¶
The Drupal AI ecosystem has matured dramatically. With the Drupal AI module (1.3.0+), AI Agents, AI Automators, AI Generation, and 48+ provider integrations, we can build a website that:
- Auto-generates content using AI Automators triggered on save
- Self-configures using AI Agents to create content types, fields, taxonomies via natural language
- Auto-optimizes SEO, accessibility, translations, and image alt text
- Generates code using AI Generation module to scaffold custom functionality
- Maintains itself through intelligent monitoring and suggestions
This transforms the redesign from "manual content creation" to "AI-orchestrated content architecture."
KEY DRUPAL AI MODULES TO LEVERAGE¶
Core AI Infrastructure¶
- AI (Drupal AI) - Unified framework, vendor-agnostic (OpenAI, Anthropic, Google, AWS, etc.)
- AI Core - Base API and provider connections
- AI Providers - OpenAI, Anthropic Claude, Google Gemini, AWS Bedrock, Hugging Face, etc.
Content Automation¶
- AI Automators - Auto-populate fields on entity save with LLM-generated content
- AI Content - Tone adjustment, summarization, taxonomy suggestion, moderation
- AI CKEditor - In-editor AI assistant for grammar, translation, content generation
- AI Image Alt Text - Auto-generate accessibility-compliant alt text on image upload
- AI Media Image - Generate images from text prompts directly to media library
Site Configuration & Development¶
- AI Agents - Text-to-action agents that create/modify Drupal config via natural language
- AI Generation - Generate entire modules, content types, views, webforms from prompts
Search & Discovery¶
- AI Search - Semantic search with RAG (Retrieval-Augmented Generation)
- AI Assistants & Chatbot - Configurable chatbots with access to your content
Multilingual & Translation¶
- AI Translate - One-click AI-powered translation for multilingual sites
- AI TMGMT Integration - Use AI as translation provider
Quality & Compliance¶
- AI External Moderation - Content moderation before publishing
- AI Validations - Field validation using AI/LLM prompts
- AI Logging - Log all AI requests/responses for audit
Advanced Features¶
- AI Search (with Vector DBs) - Pinecone, Milvus, Zilliz for RAG
- ECA Integration - Create complex AI workflows with Event-Condition-Action
- llmstxt - Provide context to LLMs at inference time
REVISED CONTENT ARCHITECTURE APPROACH¶
PHASE 1: AI-ASSISTED DEVELOPMENT (Weeks 1-2)¶
Using AI Generation Module to Scaffold Site Structure¶
What AI Generation Can Do: - Generate content types with fields from natural language prompts - Create views, taxonomies, webforms, roles, permissions - Generate custom modules and themes - Output Drupal-ready files (config YAML, PHP code)
Implementation:
# Install AI Generation module
composer require drupal/ai_generation
# Configure API key and provider (OpenAI GPT-4 or Anthropic Claude)
# Generate content types via Drush
drush aigen "Create a Service Page content type with fields:
- title (required)
- service_description (formatted long text)
- key_benefits (multi-value text list)
- approach_steps (entity reference to Process Step paragraph type)
- related_services (entity reference to other Service pages)
- hero_image (media image)
- meta fields for SEO"
# Generate taxonomy vocabularies
drush aigen "Create taxonomies:
- Service Categories (Custom Development, AI Services, Strategy, Support)
- Technologies (Drupal, AI/ML, Cloud, Security)
- Industries (Government, Education, Enterprise, Mid-Market)
- Content Types (Case Study, Blog, Tutorial, News)"
# Generate views
drush aigen "Create a view displaying Service pages in grid format with filters by category, exposed filter for search, display 12 per page"
# Generate paragraph types for components
drush aigen "Create paragraph types for:
- Hero Section (headline, subheadline, CTA buttons, background media)
- Value Proposition Card (icon, title, description, link)
- Stats Bar (stat number, label, icon - repeatable)
- Testimonial (quote, client name, title, company, logo, photo)
- Process Step (step number, title, description, icon)"
Outcome: In 1-2 days, AI generates 80% of the site's content architecture, eliminating weeks of manual Drupal configuration.
PHASE 2: AI AGENT-DRIVEN CONFIGURATION (Weeks 2-3)¶
Using AI Agents to Refine Structure¶
What AI Agents Can Do: - Create and modify field configurations - Answer questions about content types - Create taxonomy terms and vocabularies - Adjust field settings, displays, form modes
Implementation via Chatbot UI:
User: "Add a 'Project Timeline' field to Case Study content type, should be a date range with start and end dates"
Agent: [Creates field_project_timeline with daterange type, adds to Case Study]
User: "Create taxonomy terms under Service Categories:
- Drupal Professional Services
- AI & Innovation Services
- Strategy & Branding
- Support & Maintenance"
Agent: [Creates all terms with proper hierarchy]
User: "Add a 'Featured' boolean field to all content types, should display as checkbox in edit form"
Agent: [Adds field_featured to Article, Service Page, Case Study, Team Member, etc.]
Outcome: Natural language configuration eliminates need for clicking through Drupal admin forms.
PHASE 3: AI AUTOMATOR WORKFLOWS (Weeks 3-4)¶
Setting Up Intelligent Content Population¶
What AI Automators Can Do: - Auto-generate field content when entity is saved - Chain multiple prompts together - Use context from other fields - Scrape content, extract from files (OCR) - Generate summaries, descriptions, meta data
Key Automator Workflows to Implement:
A. Service Pages¶
Automator 1: Meta Description Generator - Trigger: On Service Page save - Input: Service title + service_description - Prompt: "Write a compelling 150-character meta description for SEO promoting this Drupal service: [title]. Key benefits: [first 100 words of description]" - Output: field_meta_description
Automator 2: Service Summary - Trigger: On Service Page save - Input: service_description (full text) - Prompt: "Summarize this service description in 2-3 sentences highlighting the main value proposition and outcomes. Be concise and results-focused." - Output: field_service_summary
Automator 3: Related Service Suggestions - Trigger: On Service Page save - Input: Service title + categories + description - Prompt: "Based on this service '[title]' in category [category], which 3 other services from [list all service titles] would naturally complement it? Return only the service titles, comma-separated." - Output: Suggests entity references (requires custom integration)
Automator 4: FAQ Generation - Trigger: Manual or on-demand - Input: Full service description + benefits + approach - Prompt: "Generate 5 frequently asked questions and answers about this service. Format as Q: question A: answer" - Output: field_faqs (multi-value text)
B. Case Studies¶
Automator 1: Executive Summary - Trigger: On Case Study save - Input: Challenge + solution + results sections - Prompt: "Create a 3-sentence executive summary capturing the client challenge, solution provided, and key quantitative result." - Output: field_executive_summary
Automator 2: Key Metrics Extraction - Trigger: On Case Study save - Input: Results section text - Prompt: "Extract all quantitative metrics from this text (percentages, time savings, cost reductions, etc.). Format as: 'metric: value - description'. Return up to 4 most impressive metrics." - Output: field_key_metrics (multi-value)
Automator 3: Technology Tags - Trigger: On Case Study save - Input: Solution description + technologies mentioned - Prompt: "Identify all technologies, platforms, and tools mentioned in this case study. Return only technology names from this list: [taxonomy terms from Technologies vocabulary]" - Output: field_technologies (taxonomy term references)
Automator 4: Related Case Studies - Trigger: On Case Study save - Input: Industry + services used + technologies - Prompt: "Find 3 similar case studies from: [list of all case studies with their industries/services]. Match by industry or technology similarity." - Output: field_related_case_studies
C. Blog Posts¶
Automator 1: Reading Time Calculator - Trigger: On Article save - Input: Body field word count - Prompt: "Calculate reading time for [word_count] words at 200 words per minute. Return just the number of minutes rounded up." - Output: field_reading_time
Automator 2: Content Classification - Trigger: On Article save - Input: Title + body (first 500 words) - Prompt: "Classify this article into one of these categories: [list of Content Types taxonomy]. Analyze the main topic and return only the category name." - Output: field_content_type (taxonomy)
Automator 3: Tag Suggestion - Trigger: On Article save - Input: Title + body - Prompt: "Suggest 5-7 relevant tags for this article from existing tags: [list current tags]. If new tags are needed, suggest them. Return comma-separated list." - Output: field_tags (taxonomy)
Automator 4: Social Media Snippets - Trigger: On Article save - Input: Title + summary/body excerpt - Prompt: "Create 3 social media post variations for this article: 1. LinkedIn (professional, 100-120 chars) 2. Twitter/X (punchy, under 280 chars with emoji) 3. Facebook (engaging, conversational, 80-100 chars)" - Output: field_social_snippets (multi-value)
D. Team Member Pages¶
Automator 1: Bio Refinement - Trigger: On Team Member save (optional - could be on-demand) - Input: Raw bio text - Prompt: "Refine this team member bio to be professional yet approachable, highlighting expertise and achievements. Keep to 100-150 words." - Output: field_bio_refined
Automator 2: Expertise Extraction - Trigger: On Team Member save - Input: Bio + resume/experience text - Prompt: "Extract 5-7 key expertise areas or specialties from this bio. Return single words or short phrases (e.g., 'Drupal Architecture', 'AI Integration', 'DevSecOps'). Match to existing specialties: [list]" - Output: field_specialties (taxonomy)
Automator 3: Community Contributions Summary - Trigger: Manual/on-demand - Input: Drupal.org username - Prompt: "Scrape Drupal.org profile for [username] and summarize: modules maintained, core contributions, issue credits, and community roles. Format as bullet points." - Output: field_community_contributions - Note: Requires AI Automator web scraping capability
E. Image Management (Automated)¶
Automator: Alt Text Generation - Module: AI Image Alt Text - Trigger: On media image upload - Process: Vision AI analyzes image content - Prompt: "Describe this image for accessibility. Be concise (under 125 chars), focus on relevant content, don't start with 'Image of' or 'Photo of'." - Output: alt_text field
Additional Image Automation: - Smart cropping for responsive image styles - Content tagging - identify objects, people, settings - Copyright detection - scan for watermarks or stock photo identifiers
PHASE 4: AUTOMATED CONTENT QUALITY (Ongoing)¶
Implementing AI Content Module Features¶
1. Tone Adjustment - Select any text field - AI rewrites in different tones: Professional, Casual, Technical, Marketing-focused - Maintains facts while adjusting style
2. Content Moderation - AI External Moderation: Screen content before publishing - Check for: inappropriate language, bias, factual concerns, compliance issues - Flag for human review or auto-moderate
3. Accessibility Compliance - Auto-check reading level (target: 8th grade for government content) - Suggest simplifications for complex sentences - Verify inclusive language - Check heading hierarchy
4. SEO Optimization - Analyze keyword density - Suggest related keywords - Optimize meta descriptions - Check internal linking opportunities
PHASE 5: INTELLIGENT SEARCH & CHATBOT (Weeks 5-6)¶
Implementing AI Search with RAG¶
What This Provides: - Semantic search (understands intent, not just keywords) - Vector database integration (Pinecone, Milvus, or Zilliz) - Retrieval-Augmented Generation (RAG) - LLM answers using YOUR content - Reduces AI hallucinations by grounding responses in actual site content
Implementation:
-
Install AI Search + Vector DB Provider
composer require drupal/ai_search drupal/ai_vdb_provider_pinecone # Or: drupal/ai_vdb_provider_milvus -
Configure Vector Database
- Create embeddings for all site content
- Index: Service pages, case studies, blog posts, team bios
-
Update embeddings on content save
-
Set Up Chatbot
- AI Assistants & Chatbot module
- Configure system prompts with Bluefly brand voice
- Connect to vector DB for RAG
- Enable multi-turn conversations
Chatbot Capabilities: - "What services do you offer for government agencies?" - "Show me case studies about AI integration" - "How do I migrate from Drupal 7?" - "Connect me with someone who knows about accessibility compliance"
Advanced: Chatbot can route to contact forms, book consultations, or hand off to human when needed.
PHASE 6: MULTILINGUAL AUTOMATION (Weeks 6-7)¶
AI-Powered Translation¶
AI Translate Module: - One-click translation of any node - Creates actual translated nodes (not just frontend translation) - Maintains field structure and formatting - SEO-optimized for each language
Implementation:
- Enable AI Translate
- Configure Languages (e.g., English, Spanish, French)
- Set Translation Rules:
- Auto-translate: Blog posts, service descriptions
- Human review required: Legal pages, contracts, case studies
- Translation Workflow:
- Editor creates content in English
- Clicks "Translate" → AI generates Spanish + French versions
- Reviewer approves or edits
- Publish all versions simultaneously
Quality Control: - Use Claude or GPT-4 for better quality than Google Translate - Post-editing by native speakers for critical content - Terminology management (consistent translation of technical terms)
COMPONENT LIBRARY 2.0 - AI-ENHANCED¶
Smart Components with AI Automators¶
All components now have AI-powered features:
Hero Component¶
Standard Fields: - Headline, subheadline, CTA buttons, background media
AI-Enhanced: - Auto-generated A/B test variations - AI creates 3 headline alternatives - Automatic image selection - AI suggests best hero image from media library based on page context - CTA optimization - AI recommends button text based on conversion data
Value Proposition Grid¶
Standard Fields: - Icon, title, description, link (repeatable)
AI-Enhanced: - Consistency checker - AI ensures all cards have similar length/tone - Icon suggestion - Based on title/description, suggests appropriate icon - Readability optimization - Ensures descriptions are scan-friendly (under 100 chars)
Testimonial Component¶
Standard Fields: - Quote, client name, title, company, logo, photo
AI-Enhanced: - Quote extraction - Paste full client email/feedback, AI extracts best 2-3 sentence quote - Sentiment scoring - AI rates testimonial strength (1-10) - Related service tagging - AI identifies which services this testimonial supports
Case Study Preview Card¶
Standard Fields: - Challenge, solution, key metric, client logo
AI-Enhanced: - Auto-summary - Generates card text from full case study - Metric highlight - AI identifies most impressive stat to feature - Industry/service tags - Auto-categorizes for filtering
CONTENT WORKFLOW WITH AI¶
Traditional Workflow (Without AI):¶
- Content strategist outlines page → 2 hours
- Writer drafts content → 4 hours
- Editor reviews and revises → 2 hours
- SEO specialist optimizes → 1 hour
- Accessibility review → 1 hour
- Developer formats in Drupal → 1 hour
- QA and revisions → 2 hours
Total: 13 hours per page
AI-Enhanced Workflow:¶
- Strategist creates outline + provides source material → 30 minutes
- AI Automator generates first draft on save → 30 seconds
- Editor reviews AI content, makes adjustments → 1 hour
- AI automatically handles:
- Meta descriptions (instant)
- Alt text for images (instant)
- Related content suggestions (instant)
- Taxonomy tagging (instant)
- Readability optimization (instant)
- QA review → 30 minutes
Total: 2 hours per page (84% time savings)
Example: Service Page Creation¶
Step 1: Create Service Page node with just: - Title: "AI Strategy & Integration" - Service Description: 500 words of basic info about the service - Upload 1-2 related images
Step 2: Click Save
What Happens Automatically:
✅ Meta description generated and populated ✅ Service summary (2-3 sentences) created ✅ Related services suggested (entity references added) ✅ FAQ section generated with 5 Q&As ✅ Images get descriptive alt text ✅ Taxonomy terms auto-selected (Service Category, Technologies) ✅ Social media snippets created for LinkedIn/Twitter/Facebook ✅ Reading level analyzed and optimized ✅ SEO keywords suggested based on content
Step 3: Editor reviews, adjusts tone if needed, approves
Result: Comprehensive service page completed in 30 minutes instead of 4+ hours
AUTOMATED MAINTENANCE & OPTIMIZATION¶
Content Freshness Monitoring¶
AI Agent Task: "Check all case studies and identify ones with outdated metrics (more than 18 months old). Flag for review."
AI Automator: Quarterly content audit - Scans all blog posts for outdated information - Checks broken links - Suggests content updates - Identifies low-performing pages for refresh
SEO Continuous Improvement¶
AI Automator: Monthly SEO optimization - Analyzes top-performing pages - Identifies content gaps (topics not covered) - Suggests internal linking opportunities - Updates meta descriptions based on performance
Accessibility Audits¶
AI Agent: Weekly accessibility checks - Scans new content for WCAG 2.1 AA compliance - Checks alt text quality - Verifies heading hierarchy - Flags color contrast issues
DRUPAL AI MODULE INTEGRATION ARCHITECTURE¶
Provider Configuration¶
Primary Providers: 1. Anthropic Claude (Sonnet/Opus) - Long context, nuanced content 2. OpenAI GPT-4 - General purpose, reliable 3. Google Gemini - Multi-modal, vision tasks
Use Case Mapping: - Content generation: Claude Opus (best writing quality) - Structured data extraction: GPT-4 (reliable JSON output) - Image analysis/alt text: Google Gemini or GPT-4 Vision - Code generation: Claude Sonnet or GPT-4 - Translation: GPT-4 or Claude (better than Google Translate) - Moderation: OpenAI Moderation API
API Key Management¶
- Key Module: Securely store API keys
- Environment Variables: Production keys stored outside database
- Rate Limiting: Implement quotas per provider
- Fallback: If primary provider fails, switch to backup
- Cost Tracking: Log all API calls with cost attribution
AI GOVERNANCE & QUALITY CONTROL¶
Human-in-the-Loop Workflows¶
Content Types Requiring Human Approval: 1. Case studies (client-facing) 2. Legal/compliance pages 3. Pricing information 4. Team member bios (personal content) 5. Press releases
Content Types That Can Auto-Publish: 1. Meta descriptions 2. Alt text 3. Taxonomy tagging 4. Related content suggestions 5. Social media snippets
Quality Assurance Process¶
AI-Generated Content Review Checklist: - [ ] Factual accuracy (AI can hallucinate) - [ ] Brand voice consistency - [ ] No sensitive information disclosed - [ ] Links and references valid - [ ] Tone appropriate for audience - [ ] No bias or inappropriate language
Moderation & Compliance¶
AI External Moderation Module: - Screens all AI-generated content before save - Checks for: - Offensive language - Bias (gender, race, age, etc.) - Competitor mentions - Confidential information patterns - Flags suspicious content for human review
COST-BENEFIT ANALYSIS¶
Traditional Development Costs¶
Content Creation: - 30 pages × 13 hours = 390 hours - @ $100/hour = $39,000
Ongoing Maintenance: - Content updates: 40 hours/month - SEO optimization: 20 hours/month - Accessibility audits: 10 hours/month - Total: 70 hours/month × $100 = $7,000/month
Annual Content Cost: $84,000 + initial $39,000 = $123,000 first year
AI-Enhanced Development Costs¶
Initial Setup: - AI module configuration: 40 hours - Automator creation: 60 hours - AI Agent setup: 20 hours - Testing and refinement: 30 hours - Total: 150 hours @ $150/hour = $22,500
Content Creation: - 30 pages × 2 hours = 60 hours - @ $100/hour = $6,000
Ongoing Maintenance:
- Content updates (AI-assisted): 10 hours/month
- SEO optimization (automated): 5 hours/month
- Accessibility audits (automated): 2 hours/month
- AI monitoring: 8 hours/month
- Total: 25 hours/month × $100 = $2,500/month
AI API Costs: - Estimated: $500-800/month for moderate usage - Content generation: ~$200/month - Image analysis: ~$100/month - Search/embeddings: ~$200/month
Annual AI-Enhanced Cost: - Setup: $22,500 (one-time) - Content creation: $6,000 - Maintenance: $2,500 × 12 = $30,000 - API costs: $700 × 12 = $8,400 - Total: $66,900 first year
Savings: $56,100 first year (46% reduction) Ongoing annual savings: $46,200 (65% reduction)
IMPLEMENTATION ROADMAP¶
Week 1-2: Foundation¶
- [ ] Install Drupal AI ecosystem (AI, AI Agents, AI Generation, AI Automators)
- [ ] Configure API keys for Anthropic, OpenAI, Google
- [ ] Use AI Generation to scaffold all content types
- [ ] Use AI Agents to create taxonomies and initial terms
Week 3-4: Automator Development¶
- [ ] Create automators for service pages (meta, summary, FAQ)
- [ ] Create automators for case studies (executive summary, metrics, tags)
- [ ] Create automators for blog posts (reading time, tags, social snippets)
- [ ] Create automators for team pages (expertise extraction)
- [ ] Configure AI Image Alt Text for all media
Week 5-6: Search & Discovery¶
- [ ] Set up vector database (Pinecone or Milvus)
- [ ] Configure AI Search with RAG
- [ ] Implement chatbot with AI Assistants
- [ ] Train chatbot on site content
Week 7-8: Content Migration & Creation¶
- [ ] Migrate existing content with AI assistance
- [ ] Create new pages using AI-enhanced workflow
- [ ] Generate initial blog post backlog
- [ ] Create case studies with AI content generation
Week 9-10: Multilingual & Advanced Features¶
- [ ] Enable AI Translate for Spanish and French
- [ ] Set up automated translation workflows
- [ ] Configure ECA for complex AI workflows
- [ ] Implement AI moderation pipeline
Week 11-12: Testing & Optimization¶
- [ ] QA all AI-generated content
- [ ] Fine-tune automator prompts
- [ ] Test chatbot responses
- [ ] Optimize API costs
- [ ] Document governance processes
Week 13-14: Launch & Monitoring¶
- [ ] Soft launch with monitoring
- [ ] Collect user feedback on AI features
- [ ] Adjust chatbot behavior based on interactions
- [ ] Launch full site
- [ ] Set up automated monitoring and maintenance schedules
SHOWCASE BLUEFLY'S AI EXPERTISE¶
The Meta Advantage¶
This website should demonstrate our AI capabilities:
- Transparent AI Usage
- Add "AI-Enhanced Content" badges where appropriate
- Blog post: "How We Built This Site Using Drupal AI"
-
Case study: "Our Own Website: An AI Implementation Case Study"
-
Interactive Demonstrations
- Live chatbot showing RAG capabilities
- "Ask About Our Services" AI assistant
-
Content generation demo (e.g., "Generate a case study outline")
-
Developer Resources
- Document our AI automator prompts (open source them)
- Share our AI Agent configurations
-
Publish our AI governance policies
-
Client Trust Building
- Show AI decision-making transparency
- Explain when humans review vs. auto-publish
- Demonstrate quality control processes
RISKS & MITIGATIONS¶
Risk 1: AI Hallucinations¶
Mitigation: - Always use RAG for chatbot (ground in real content) - Human review for client-facing content - Validation rules to catch nonsensical output - A/B test AI vs. human content performance
Risk 2: Brand Voice Drift¶
Mitigation: - Detailed system prompts with brand voice guidelines - Regular audits of AI-generated content - Fine-tune prompts based on editor feedback - Maintain style guide as reference for AI
Risk 3: API Costs Spiraling¶
Mitigation: - Set monthly budget alerts - Cache AI responses where appropriate - Use cheaper models for simple tasks (GPT-3.5 vs. GPT-4) - Batch processing instead of real-time where possible
Risk 4: Over-Reliance on AI¶
Mitigation: - Maintain human oversight for strategic decisions - Editors approve all public-facing content - Regular content quality reviews - Preserve institutional knowledge (don't lose human writing skills)
Risk 5: Privacy & Data Concerns¶
Mitigation: - Never send confidential client data to AI APIs - Use on-premise models (Ollama) for sensitive content - Clear data handling policies - Comply with GDPR/privacy regulations
SUCCESS METRICS¶
Measure AI Impact:¶
Efficiency Metrics: - Time to create new page (target: 80% reduction) - Hours spent on content maintenance (target: 70% reduction) - Content updates per month (target: 3x increase)
Quality Metrics: - SEO performance (organic traffic growth) - Accessibility compliance rate (target: 100%) - User engagement (time on site, bounce rate) - Content consistency scores
Cost Metrics: - Total content budget vs. previous year - API costs as % of total budget - ROI on AI implementation (payback period)
Innovation Metrics: - Number of new AI features implemented - Client inquiries about AI capabilities - Case studies generated from AI work
FUTURE ENHANCEMENTS¶
Phase 2 Features (6-12 months post-launch)¶
- Predictive Content Strategy
- AI analyzes which content performs best
- Suggests new topics based on search trends
-
Identifies content gaps in our coverage
-
Automated A/B Testing
- AI generates headline variations
- Auto-tests and selects winners
-
Continuous optimization without manual effort
-
Personalization Engine
- AI adapts content based on user behavior
- Shows relevant case studies by industry
-
Customizes service recommendations
-
Voice/Video Integration
- AI-generated video scripts from blog posts
- Text-to-speech for audio versions
-
Auto-generated video captions
-
Advanced Analytics
- AI-powered insights dashboard
- Predictive analytics for user behavior
- Automated reporting on content performance
CONCLUSION¶
The Drupal AI ecosystem transforms website development from manual content creation to AI-orchestrated intelligence. By leveraging:
- AI Generation for rapid site scaffolding
- AI Agents for natural language configuration
- AI Automators for intelligent content population
- AI Search & RAG for semantic discovery
- AI Translation for global reach
- AI Moderation for quality control
...we can build a website that is: - Faster to build (50-70% time savings) - Cheaper to maintain (65% cost reduction) - Better quality (automated SEO, accessibility, consistency) - More dynamic (continuous optimization) - Future-proof (easily extensible with new AI capabilities)
Most importantly: This website becomes a living demonstration of Bluefly's AI expertise, showing prospects exactly what we can build for them.
The question isn't "Should we use AI?" but "How quickly can we implement it?"
Next Steps: 1. Approve this AI-first architecture approach 2. Set up development environment with Drupal AI modules 3. Experiment with AI Generation to scaffold first content types 4. Create proof-of-concept automators for one content type 5. Validate AI output quality and iterate on prompts
End of AI-Powered Architecture Document
Historical Document II — bluefly.io — Drupal CMS 2.0 Rebuild Plan¶
Original path: products/Agent-Factory/BlueflyAgents.com/01-BLUEFLY-CMS-REBUILD.md. Prepared 2026-03-21, updated 2026-04-10. Already carried its own supersession notice (2026-09-10) prior to this merge; that notice is preserved below as written.
bluefly.io — Drupal CMS 2.0 Rebuild Plan¶
SUPERSEDED as product architecture (2026-09-10). Current AMCS / governed Drupal CMS architecture is
products/AMCS/Architecture.md. This file remains historical input for site-specific bluefly.io migration/content notes only. Do not install its module stack, StateMesh (agent_state_*), or OSSA/DUADP federation as AMCS MVP prerequisites. Do not resurrect__FINAL-PLAN-TO-UPDATE.mdorMASTER-PROMPT.md. Recon bead:bc-vb5z.Document Role: Historical site rebuild execution plan — bluefly.io Drupal CMS 2.0 content model, module strategy, DUADP import pipeline, Canvas/Orchestration/FlowDrop integration, migration approach Precedence:
products/AMCS/Architecture.mdwins for product/factory/runtime ownership. This document must not override it.Classification: Internal Working Document Prepared: 2026-03-21 | Updated: 2026-04-10 Audience: Claude Code, senior engineers, and Thomas Scola
Executive Summary¶
bluefly.io is currently running Drupal 10 (confirmed via x-generator: Drupal 10 response header) on a Cloudflare-proxied host with no active Cloudflare Tunnel route — bluefly.io and www.bluefly.io are P1 missing tunnel entries relative to the canonical registry in .agents/context/domains.yaml (tunnel config must be generated from that file; historical tunnel notes may appear under plans/CONTENT-CONSOLIDATION/**/04-TUNNEL-CONFIG.md). The site is a traditional agency marketing site: 30 service nodes, 12 focus-area nodes, 5 content types (page, service, focus_area, resource, testimonials), and 10 taxonomy vocabularies. It has no AI modules, no agent infrastructure, no DUADP integration, and no Canvas or Orchestration layer.
The rebuild goal is to transform bluefly.io into the flagship demonstration of the Bluefly AI platform — a Drupal CMS 2.0 site that uses Canvas for page composition, Orchestration for multi-agent workflows, the Tool API for 29+ discovered tools, Flow Drop for visual pipeline building, and DUADP for importing and publishing agents, skills, and policies. The site must also serve as a Drupal Silver Certified Partner marketing presence and a live proof-of-concept for every service bluefly.io sells.
This document provides: (1) a full audit of the existing site, (2) the updated service and content architecture, (3) the DUADP import pipeline, (4) the module install order, and (5) the exact Claude Code task sequence with file-level specificity.
Part 1 — Current Site Audit¶
1.1 Technical Stack (Confirmed via Live Probes)¶
| Dimension | Current State | Target State |
|---|---|---|
| Drupal version | 10.x | CMS 2.0 (Drupal 11.x-based) |
| Hosting | Cloudflare-proxied, no tunnel | Oracle VM via cloudflared tunnel, bluefly.io P1 route |
| Cache | x-drupal-dynamic-cache: HIT, x-drupal-cache: UNCACHEABLE |
BigPipe + CDN edge caching via Cloudflare |
| JSON:API | Enabled, public read, 40+ resource types exposed | Locked down per OWNERSHIP; duadp_client reads via service account |
| AI modules | None | Full stack (see §2.2) |
| Canvas | Not installed | drupal/canvas — primary page composition layer |
| Orchestration | Not installed | drupal/orchestration — multi-agent DAG execution |
| Tool API | Not installed | drupal/tool — 29+ Tool plugins discovered |
| Flow Drop | Not installed | drupal/flowdrop — visual pipeline builder |
| DUADP | Not installed | duadp_client module + @bluefly/duadp SDK |
| OSSA | Not installed | ai_agents_ossa + @bluefly/openstandardagents CLI |
| Cedar | Not installed | cedar_policy module, wired to compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) |
| StateMesh | Not installed | agent_state_plane + agent_state_policy + agent_state_attestation |
| Theme | Custom Drupal 10 theme | Rebuilt using @bluefly/studio-ui design tokens + SDC components |
| Node.js | None | @bluefly/openstandardagents + @bluefly/duadp via Drush scripts |
1.2 Existing Content Model¶
The live site exposes the following via JSON:API (confirmed):
Content Types
| Type | Count | Purpose | Migration Decision |
|---|---|---|---|
page |
~10 | Static marketing pages (About, Team, Company Overview) | Migrate → Canvas pages |
service |
30 | Individual service offerings | Migrate + Extend → add field_agent_manifest, field_cedar_policy_id |
focus_area |
12 | Service category groupings | Migrate → taxonomy term or landing page |
resource |
~20 | Blog/articles/resources | Migrate → keep as resource content type |
testimonials |
unknown | Client testimonials | Migrate → keep |
Taxonomy Vocabularies (confirmed from JSON:API)
faq_category, font_classification, font_designer, font_foundry, font_tags, industries_served, languages_supported, resources, tags, team, team_role
Note: The font-related vocabularies (font_classification, font_designer, font_foundry, font_tags) suggest a legacy font/design tool feature that is no longer in the site navigation. These should be audited for active use before migration.
Webforms (confirmed from JSON:API)
book_a_consultation— primary lead capture formcollaborate_with_bluefly_io— partner/collaboration formwelcome_to_bluefly_io— onboarding form
1.3 Current Navigation Structure¶
Confirmed from live page scrape:
- About →
/company-overview - Our Team →
/our-team - Solutions →
/custom-drupal-solutions - Our Focus →
/focus-area - Services →
/expert-drupal-consultation-services - Book A Consultation →
/book-drupal-consultation(webform, CTA button)
1.4 Current Service Catalog (30 Services, 12 Focus Areas)¶
Focus Areas and their services:
| Focus Area | Services |
|---|---|
| Drupal Support and Maintenance | Migration Support, Digital Strategy & Planning, Upgrade Service, D7 Modernization |
| Technical Leadership & Oversight | Performance Enhancements, Support and Maintenance, Analytic Insight, Traffic Insights & Bot Management, TSA, Best Practice Auditing |
| DevSecOps & Operational Strategy | Continuous Deployment Optimization |
| Digital Strategy & Consulting | Custom Web App Builds, Technical Planning & Workshops |
| Collaborative Delivery & Team Enablement | Project & Program Management, Drupal Team Assessment, Collaborative Delivery |
| Compliance & Security Services | Security Assessment, Application Integrity Review, Managed CDN/WAF |
| Innovation & Emerging Technologies | AI Readiness & Strategy |
| Drupal Support & Development | DRXP® & Customer Data Platforms, Replatforming & Migration |
| Drupal Tailored Solutions | Custom Development |
| Branding & User Experience Design | Branding & Accessible Marketing, Design System Theme & Accessibility, Accessible UX Design |
| Content Development & Management | Content Development & Technical Writing, Digital Asset Management, Accessible Report & Section 508 |
| Training & Knowledge Development | Team Enablement and Training |
Critical gap identified: "AI Readiness & Strategy" is a single service under "Innovation & Emerging Technologies" — but the entire platform is now an AI platform. The rebuild must elevate AI/agent services from a single service node to a primary navigation pillar with dedicated focus areas, agent-powered demos, and DUADP-backed capability discovery.
1.5 What Is Missing (Gap Analysis)¶
The following are entirely absent from the current site and must be built from scratch:
- Agent Services section — no pages describing OSSA, DUADP, Canvas agents, or the agent marketplace
- Live demos — no interactive Canvas pages, no agent execution demos, no Flow Drop pipelines
- DUADP peer node —
bluefly.iois not registered as a DUADP peer;/.well-known/duadp.jsonreturns 404 - Drupal AI module stack — zero AI modules installed
- Acquia/partner positioning — Drupal Silver Certified badge exists in assets but is not prominently featured
- Case studies — no case study content type or content
- Blog/thought leadership —
resourcetype exists but appears sparsely populated - IdeaLedger integration — per uploaded spec, bluefly.io should be a PAIT-aware node
- StateMesh evidence — no governance evidence layer
Part 2 — Target Architecture¶
2.1 Site Identity¶
bluefly.io in CMS 2.0 serves three simultaneous roles:
- Agency marketing site — Drupal Silver Certified Partner, service catalog, team, case studies, lead capture
- AI platform showcase — live Canvas pages built by agents, DUADP discovery, Flow Drop pipelines running in-browser
- DUADP peer node — publishes bluefly.io agents and services to the federated registry; imports agents from
discover.duadp.orgto power the showcase
These three roles must coexist without architectural compromise. The marketing content uses Canvas for layout; the AI showcase uses Orchestration and Flow Drop for live execution; the DUADP peer node uses duadp_client for bidirectional sync.
2.2 Module Stack — Install Order¶
The install order is non-negotiable. Schema dependencies cascade; installing out of order causes entity type conflicts.
Phase 0 — Drupal CMS 2.0 Core Recipe
composer require drupal/cms
drush recipe web/core/recipes/drupal-cms-2.0
This installs the CMS 2.0 base: Layout Builder, Media, Metatag, Pathauto, Simple Sitemap, Search API, and the CMS experience builder.
Phase 1 — AI Foundation
composer require drupal/ai drupal/ai_provider_anthropic drupal/ai_provider_openai
drush en ai ai_provider_anthropic ai_provider_openai
drupal/ai is the base module. It must be enabled before any AI-dependent module. Configure ai.settings.yml with default providers before proceeding.
Phase 2 — Tool API and Orchestration
composer require drupal/tool drupal/api_normalization drupal/orchestration
drush en tool api_normalization orchestration
drupal/tool replaces any custom code_executor — it provides the #[Tool] plugin attribute and the Tool plugin manager. drupal/api_normalization handles OpenAPI import and exposes 29 Tool plugins from external APIs. drupal/orchestration provides the DAG execution engine for multi-agent workflows. Install in this exact order: tool → api_normalization → orchestration.
Phase 3 — Canvas and Flow Drop
composer require drupal/canvas drupal/flowdrop
drush en canvas flowdrop
Canvas provides the page composition layer with SDC component placement. Flow Drop provides the visual pipeline builder. Both depend on the Tool API being available.
Phase 4 — OSSA and DUADP
composer require drupal/ai_agents drupal/ai_agents_ossa
composer require blueflyio/duadp_client:dev-main
drush en ai_agents ai_agents_ossa duadp_client
drupal/ai_agents is the contrib agent registry — it replaces any bespoke agent registry. ai_agents_ossa is the Bluefly custom module that adds OSSA manifest validation, trust tier enforcement, and the RegistrySyncTool. duadp_client handles bidirectional sync with discover.duadp.org.
Phase 5 — Cedar Governance
composer require blueflyio/cedar_policy:dev-main
drush en cedar_policy
Cedar policy module wires to compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) via http_client_manager. Must be installed after ai_agents_ossa because it gates agent execution via PolicyEvaluatorInterface.
Phase 6 — StateMesh
composer require blueflyio/agent_state_plane blueflyio/agent_state_policy blueflyio/agent_state_attestation
drush en agent_state_plane agent_state_policy agent_state_attestation
StateMesh modules must be installed last because they depend on entity types defined by ai_agents, orchestration, and cedar_policy.
Phase 7 — ContractPlane Client
composer require blueflyio/contractplane_client:dev-main
drush en contractplane_client
Wires evidence recording to contractplane.ai. Optional for initial launch but required for governance-critical workflows.
2.3 Complete Module List¶
| Module | Source | Purpose | Required By |
|---|---|---|---|
drupal/cms |
drupal.org | CMS 2.0 base recipe | — |
drupal/ai |
drupal.org | AI base module, provider abstraction | Everything AI |
drupal/ai_provider_anthropic |
drupal.org | Claude models | drupal/ai |
drupal/ai_provider_openai |
drupal.org | GPT-4o models | drupal/ai |
drupal/tool |
drupal.org | Tool plugin system | orchestration, ai_agents |
drupal/api_normalization |
drupal.org | OpenAPI → Tool plugins (29 tools) | tool |
drupal/orchestration |
drupal.org | DAG multi-agent execution | tool |
drupal/canvas |
drupal.org | AI-assisted page composition | drupal/ai |
drupal/flowdrop |
drupal.org | Visual pipeline builder | orchestration |
drupal/ai_agents |
drupal.org | Agent registry (replaces bespoke registry) | drupal/ai |
ai_agents_ossa |
gitlab.com/blueflyio | OSSA manifest validation, trust tiers, RegistrySyncTool |
drupal/ai_agents |
duadp_client |
gitlab.com/blueflyio | DUADP bidirectional sync | ai_agents_ossa |
cedar_policy |
gitlab.com/blueflyio | Cedar PDP client, 7 default policies | ai_agents_ossa |
agent_state_plane |
gitlab.com/blueflyio | StateClaim entity type, REST endpoint | drupal/ai_agents |
agent_state_policy |
gitlab.com/blueflyio | Cedar gates on state transitions | cedar_policy |
agent_state_attestation |
gitlab.com/blueflyio | JWS signing of StateClaims | agent_state_plane |
contractplane_client |
gitlab.com/blueflyio | Evidence recording to ContractPlane | agent_state_attestation |
dita_ccms |
gitlab.com/blueflyio | DITA-based technical content management | optional |
2.4 Updated Content Model¶
The rebuild extends the existing content model with new types and fields. Existing content is migrated, not deleted.
New Content Types
| Type | Purpose | Key Fields |
|---|---|---|
agent_showcase |
Live demo of a DUADP agent running on the site | field_agent_gaid, field_canvas_page_ref, field_ossa_manifest, field_trust_tier |
case_study |
Client success story | field_client, field_industry, field_services_used, field_outcome_metrics, field_agent_used |
ai_service |
New AI/agent-specific services (separate from legacy service) |
field_agent_capability, field_duadp_skill_ref, field_demo_pipeline_ref |
flow_pipeline |
Saved Flow Drop pipeline | field_flowdrop_config, field_cedar_policy_id, field_statemesh_enabled |
Extended Existing Types
| Type | New Fields | Purpose |
|---|---|---|
service |
field_agent_manifest (YAML), field_cedar_policy_id, field_ai_enhanced (boolean) |
Link services to OSSA agents; mark AI-enhanced services |
page |
field_canvas_enabled (boolean), field_orchestration_dag_id |
Enable Canvas composition and agent-driven page generation |
focus_area |
field_duadp_category, field_agent_count (computed) |
Map focus areas to DUADP agent categories |
New Taxonomy Vocabularies
| Vocabulary | Terms | Purpose |
|---|---|---|
agent_category |
orchestration, security, content, code, infrastructure, communications | Maps to DUADP metadata.category |
trust_tier |
official, verified, self-declared, community, audited | Maps to DUADP metadata.trust_tier |
ossa_kind |
Agent, Task, Workflow, Skill | Maps to OSSA manifest kind |
Config Entities Required (StateMesh)
config/sync/
statemesh.settings.yml
statemesh.claim_types.yml
statemesh.challenge_routing.yml
2.5 DUADP Peer Node Configuration¶
bluefly.io must publish /.well-known/duadp.json to register as a DUADP peer. The duadp_client module handles this automatically once configured.
duadp_client.settings.yml (place in config/sync/):
node_id: bluefly.io
tenant_id: blueflyio
site_id: bluefly-cms
canonical_url: https://bluefly.io
discovery_endpoint: https://discover.duadp.org
federation_key_ref: key[REDACTED]
sync_interval: 3600
import_filters:
trust_tier: [official, verified]
limit: 60
publish_namespace: blueflyio
The federation_key_ref must point to an Ed25519 keypair stored in Drupal's key management system (Key module). Generate with:
openssl genpkey -algorithm ed25519 -out Scratch/bluefly_federation.pem
openssl pkey -in Scratch/bluefly_federation.pem -pubout -out Scratch/bluefly_federation_pub.pem
drush key-save bluefly_federation_ed25519 --key-type=authentication --key-provider=file --key-file-path=/path/to/bluefly_federation.pem
Part 3 — DUADP Import Pipeline¶
3.1 What Gets Imported¶
From discover.duadp.org (confirmed live data):
| Resource Type | Count | Import Target |
|---|---|---|
| Agents | 60 (all trust_tier: official) |
ai_agents entity type via RegistrySyncTool |
| Skills | 5 | duadp_skill config entity |
| Policies | 20 (14 agent-authorization, 6 claude-code) |
cedar_policy config entities |
3.2 Agent Import Drush Command¶
The RegistrySyncTool in ai_agents_ossa exposes a Drush command:
# Import all official agents from discover.duadp.org
drush ossa:sync-registry --source=https://discover.duadp.org --trust-tier=official --limit=60
# Import by category (for selective showcase)
drush ossa:sync-registry --source=https://discover.duadp.org --category=orchestration
drush ossa:sync-registry --source=https://discover.duadp.org --category=content
drush ossa:sync-registry --source=https://discover.duadp.org --category=security
Each imported agent becomes a Drupal ai_agent entity with:
field_ossa_manifest— the full YAML manifest stored as textfield_gaid— the DUADP GAID URI (e.g.,agent://agents/orchestrator)field_trust_tier— taxonomy term referencefield_agent_uri— canonicalagent://<tenant>@<site>/<authority>/<path>per identity specfield_cedar_policy_ids— Cedar policy IDs that govern this agent
3.3 Skill Import¶
Skills are imported as Drupal config entities:
drush duadp:sync-skills --source=https://discover.duadp.org
The 5 confirmed skills (web-search, code-review, text-summarizer, data-analyzer, image-classifier) become duadp_skill config entities. Each skill's spec.inputs and spec.outputs are stored as typed field data for use in Flow Drop pipeline configuration.
3.4 Policy Import¶
Cedar policies are imported and activated:
drush cedar:sync-policies --source=https://discover.duadp.org --pack=agent-authorization
drush cedar:sync-policies --source=https://discover.duadp.org --pack=claude-code
The 20 policies (confirmed: 14 agent-authorization-* + 6 claude-code-*) are imported as cedar_policy config entities. The cedar_policy module's CedarEngine.php evaluates them against compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) before any agent execution.
Critical: The compliance engine at compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) must be reachable from the Oracle host. This is confirmed healthy per __FINAL-PLAN-TO-UPDATE.md but must be verified at deploy time.
3.5 OSSA Agent URI Assignment¶
Per agent-duadp-identity-spec.md, every imported agent must be assigned a canonical agent_uri:
agent://blueflyio@bluefly-cms/bluefly.io/<agent-name>
The duadp_client module handles this automatically during import, using the tenant_id and site_id from duadp_client.settings.yml.
3.6 npm Package Integration¶
Both @bluefly/openstandardagents and @bluefly/duadp are used in Drush scripts and custom module code — not in the Drupal PHP runtime directly. They are installed in a scripts/ directory at the site root:
cd /path/to/bluefly.io/scripts
npm install @bluefly/openstandardagents @bluefly/duadp
scripts/sync-agents.mjs — called by Drush hook or cron:
import { DuadpClient } from "@bluefly/duadp/client";
import { validateManifest } from "@bluefly/openstandardagents";
const client = new DuadpClient({ baseUrl: "https://discover.duadp.org" });
// Fetch all official agents
const { data: agents } = await client.agents.list({
trust_tier: "official",
limit: 60,
});
for (const agent of agents) {
// Validate manifest before import
const manifest = agent.spec?.manifest;
if (manifest) {
const result = await validateManifest(manifest);
if (!result.valid) {
console.warn(`Skipping ${agent.metadata.name}: ${result.errors}`);
continue;
}
}
// POST to Drupal JSON:API for entity creation
// (handled by duadp_client Drupal module — this script is for CLI/cron use)
console.log(
`Validated: ${agent.metadata.name} (${agent.metadata.trust_tier})`,
);
}
scripts/publish-agent.mjs — publish a bluefly.io agent to DUADP:
import { DuadpClient } from "@bluefly/duadp/client";
import { signManifest } from "@bluefly/duadp/crypto";
const client = new DuadpClient({
baseUrl: "https://discover.duadp.org",
auth: { token: process.env.DUADP_AUTH_TOKEN },
});
const manifest = JSON.parse(process.argv[2]);
const signed = await signManifest(manifest, process.env.FEDERATION_PRIVATE_KEY);
await client.publish(signed);
Part 4 — Canvas, Orchestration, Tool API, and Flow Drop Integration¶
4.1 Canvas — AI-Assisted Page Composition¶
Canvas is the primary page composition layer for bluefly.io CMS 2.0. Every marketing page is a Canvas page, meaning its layout is defined by SDC component placement that can be modified by the Easel agent (see agent.ossa.yaml in uploaded files).
Canvas page setup for the homepage:
# config/sync/canvas_page.homepage.yml
uuid: <uuid>
langcode: en
status: true
id: homepage
label: "bluefly.io Homepage"
canvas_regions:
hero:
component: bluefly:hero-section
props:
headline: "Transforming Your Goals with Bluefly.io Expertise"
subtext: "Drupal Silver Certified Partner. AI-native agency."
cta_primary:
{ label: "Book a Consultation", url: "/book-drupal-consultation" }
cta_secondary: { label: "Explore AI Services", url: "/ai-services" }
services_grid:
component: bluefly:agent-service-grid
props:
source: duadp
category: all
limit: 6
live_demo:
component: bluefly:flow-drop-embed
props:
pipeline_id: content-guardian-demo
partner_badge:
component: bluefly:certification-badge
props:
badge: drupal-silver-certified
The Easel agent (ai_agents_ossa_canvas:easel) can regenerate any Canvas page from a natural language prompt. This is the live demo: visitors can watch the agent rebuild a page section in real time.
4.2 Orchestration — Multi-Agent DAG Execution¶
The drupal/orchestration module executes multi-agent workflows as directed acyclic graphs. bluefly.io uses two primary orchestration DAGs:
DAG 1: Content Guardian Pipeline — runs on every new resource node publish:
# config/sync/orchestration_dag.content_guardian.yml
id: content_guardian
label: "Content Guardian Pipeline"
trigger: node_presave
trigger_bundle: resource
steps:
- id: quality_check
agent: agent://agents/content-guardian
tool: content_guardian:check_quality
on_fail: block_publish
- id: seo_enhance
agent: agent://agents/communications-manager
tool: communications_manager:seo_optimize
depends_on: [quality_check]
on_fail: warn_only
- id: statemesh_record
agent: agent://agents/orchestrator
tool: orchestrator:emit_state_claim
depends_on: [quality_check, seo_enhance]
cedar_policy: content::publish_resource
DAG 2: Service Page Generator — triggered from the admin UI to regenerate a service page using Canvas:
# config/sync/orchestration_dag.service_page_generator.yml
id: service_page_generator
label: "Service Page Generator"
trigger: manual
steps:
- id: research
agent: agent://agents/orchestrator
tool: orchestrator:coordinate
- id: content_draft
agent: agent://agents/content-guardian
tool: content_guardian:draft_content
depends_on: [research]
- id: canvas_build
agent: agent://agents/easel
tool: ai_agents_ossa_canvas:generate_from_prompt
depends_on: [content_draft]
- id: publish
agent: agent://agents/easel
tool: ai_agents_ossa_canvas:publish_page
depends_on: [canvas_build]
requires_human_approval: true
cedar_policy: canvas::publish_page
4.3 Tool API — 29 Discovered Tools¶
drupal/api_normalization imports the OpenAPI spec from mcp.blueflyagents.com (port 4005, 99 tools confirmed) and exposes them as Drupal Tool plugins. For bluefly.io, the relevant tool groups are:
| Tool Group | Count | Used By |
|---|---|---|
| Content tools | ~8 | Content Guardian DAG |
| Canvas tools | 6 | Easel agent (from agent.ossa.yaml) |
| Orchestration tools | ~5 | Service Page Generator DAG |
| Security/compliance tools | ~4 | Cedar policy evaluation |
| Code quality tools | ~6 | CI pipeline integration |
Configure api_normalization to import from the MCP endpoint:
# config/sync/api_normalization.source.mcp_blueflyagents.yml
id: mcp_blueflyagents
label: "Bluefly MCP Tools"
source_url: https://mcp.blueflyagents.com/openapi.json
auth_type: none
tool_prefix: bluefly
auto_sync: true
sync_interval: 86400
4.4 Flow Drop — Visual Pipeline Builder¶
Flow Drop provides a drag-and-drop pipeline builder that site editors can use to create agent workflows without code. For bluefly.io, Flow Drop serves two purposes:
- Internal editorial workflows — editors build content pipelines (draft → review → publish) using imported DUADP agents as pipeline nodes
- Live demo embed — a read-only Flow Drop canvas is embedded on the AI Services page showing a live content pipeline execution
Flow Drop demo pipeline config (field_flowdrop_config on flow_pipeline node):
{
"nodes": [
{ "id": "input", "type": "trigger", "label": "New Service Request" },
{
"id": "research",
"type": "agent",
"agent_gaid": "agent://agents/orchestrator",
"tool": "orchestrator:coordinate"
},
{
"id": "draft",
"type": "agent",
"agent_gaid": "agent://agents/content-guardian",
"tool": "content_guardian:draft_content"
},
{
"id": "canvas",
"type": "agent",
"agent_gaid": "agent://agents/easel",
"tool": "ai_agents_ossa_canvas:generate_from_prompt"
},
{ "id": "approve", "type": "human_gate", "label": "Human Review" },
{
"id": "publish",
"type": "agent",
"agent_gaid": "agent://agents/easel",
"tool": "ai_agents_ossa_canvas:publish_page"
}
],
"edges": [
{ "from": "input", "to": "research" },
{ "from": "research", "to": "draft" },
{ "from": "draft", "to": "canvas" },
{ "from": "canvas", "to": "approve" },
{ "from": "approve", "to": "publish" }
]
}
Part 5 — Updated Service Architecture¶
5.1 New Navigation Structure¶
The rebuild requires a fundamental restructuring of the site navigation to reflect the AI platform positioning:
| Current | New | Reason |
|---|---|---|
| About | About | Keep |
| Our Team | Our Team | Keep |
| Solutions | Solutions | Keep, expand with AI solutions |
| Our Focus | Focus Areas | Keep, add AI/Agent category |
| Services | Services | Keep, add AI Services sub-section |
| — | AI Platform | New — DUADP discovery, agent showcase, live demos |
| — | Case Studies | New — client success stories |
| Book A Consultation | Book A Consultation | Keep as primary CTA |
5.2 New AI Services (to be created as ai_service nodes)¶
These are net-new service offerings that the rebuild must create, distinct from the legacy service content type:
| Service | Agent Used | DUADP Skill | Description |
|---|---|---|---|
| AI-Powered Content Operations | content-guardian |
text-summarizer |
Automated content quality, SEO, and governance pipelines |
| Agentic Site Building | easel (Bluefly custom) |
— | Canvas-based page generation from natural language |
| Agent Marketplace Integration | orchestrator |
— | Connecting client Drupal sites to DUADP agent registry |
| Governed AI Workflows | orchestrator + Cedar |
— | Multi-agent DAGs with Cedar policy enforcement |
| AI Readiness Assessment | security-auditor |
code-review |
Audit existing Drupal site for AI readiness |
| OSSA Compliance Consulting | — | — | Help clients achieve OSSA manifest compliance |
| ContractPlane Evidence Setup | — | — | Deploy StateMesh + ContractPlane for client sites |
5.3 Existing Services — AI Enhancement Mapping¶
The 30 existing services should be enhanced with AI capabilities where applicable:
| Existing Service | AI Enhancement | Agent |
|---|---|---|
| Drupal Migration Support | Automated content migration pipelines | orchestrator |
| Drupal Performance Enhancements | AI-driven performance analysis | code-quality-reviewer |
| Security Assessment & Recommendations | Automated security scanning | security-auditor |
| Content Development & Technical Writing | AI-assisted content drafting | content-guardian |
| Drupal Custom Development | AI-assisted code review | code-reviewer |
| Continuous Deployment Optimization | AI-driven CI pipeline optimization | ci-fixer-worker |
| Best Practice Auditing | Automated audit reports | code-quality-reviewer |
5.4 Drupal Silver Certified Partner Positioning¶
The Drupal Silver Certified Partner badge (association_certified_silver_badge.svg, confirmed uploaded) must be prominently displayed. Recommended placement:
- Hero section — alongside the headline, with a link to the Acquia certification registry
- Footer — persistent across all pages
- About page — with context about what certification means
- Services pages — as a trust signal next to service descriptions
The badge SVG is already available in the upload; it should be served via the CDN (upload via manus-upload-file --webdev) and referenced in the Canvas hero component.
Part 6 — Claude Code Build Plan¶
This section is the executable task sequence for Claude Code. Each task is atomic, has a clear definition of done, and specifies the exact files to create or modify.
Prerequisites (Human Tasks — Cannot Be Automated)¶
| # | Task | Command / Action | Blocks |
|---|---|---|---|
| P1 | Add Cloudflare Tunnel route for bluefly.io |
Cloudflare dashboard → Tunnel drupalai → Add route: bluefly.io → oracle:8083 (new port for bluefly CMS) |
Everything |
| P2 | Add Cloudflare Tunnel route for www.bluefly.io |
Same tunnel, same backend | Everything |
| P3 | Generate Ed25519 federation keypair | openssl genpkey -algorithm ed25519 -out bluefly_federation.pem |
DUADP federation |
| P4 | Verify compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) reachable from Oracle |
curl https://compliance.blueflyagents.com/health |
Cedar enforcement |
| P5 | Create drupal.org projects for kagent and cedar_policy |
Manual browser: drupal.org/node/add/project-module | Module publishing |
Week 1 — Foundation (Days 1–5)¶
Task 1.1: Scaffold new Drupal CMS 2.0 site
# On Oracle VM
composer create-project drupal/cms-project:^2.0 /var/www/bluefly-cms2
cd /var/www/bluefly-cms2
drush recipe web/core/recipes/drupal-cms-2.0
drush site-install --db-url=mysql://user:pass@localhost/bluefly_cms2
Files created: composer.json, web/sites/default/settings.php, config/sync/
Task 1.2: Install AI foundation modules
composer require drupal/ai:^1.0 drupal/ai_provider_anthropic:^1.0 drupal/ai_provider_openai:^1.0
drush en ai ai_provider_anthropic ai_provider_openai
Create config/sync/ai.settings.yml:
default_providers:
chat: anthropic
embeddings: openai
providers:
anthropic:
api_key: "${ANTHROPIC_API_KEY}"
default_model: claude-3-5-sonnet-20241022
openai:
api_key: "${OPENAI_API_KEY}"
default_model: gpt-4o
Task 1.3: Install Tool API, Orchestration, Canvas, Flow Drop
composer require drupal/tool:^1.0 drupal/api_normalization:^1.0 drupal/orchestration:^1.0 drupal/canvas:^1.0 drupal/flowdrop:^1.0
drush en tool api_normalization orchestration canvas flowdrop
Task 1.4: Add custom module VCS references to composer.json
{
"repositories": [
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/ai_agents_ossa.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/duadp_client.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/cedar_policy.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/agent_state_plane.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/agent_state_policy.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/agent_state_attestation.git"
},
{
"type": "vcs",
"url": "[email protected]:blueflyio/agent-platform/drupal/contractplane_client.git"
}
]
}
composer require blueflyio/ai_agents_ossa:dev-main blueflyio/duadp_client:dev-main blueflyio/cedar_policy:dev-main
drush en ai_agents ai_agents_ossa duadp_client cedar_policy
Task 1.5: Install StateMesh modules
composer require blueflyio/agent_state_plane:dev-main blueflyio/agent_state_policy:dev-main blueflyio/agent_state_attestation:dev-main
drush en agent_state_plane agent_state_policy agent_state_attestation
Create required config entities:
config/sync/statemesh.settings.ymlconfig/sync/statemesh.claim_types.ymlconfig/sync/statemesh.challenge_routing.yml
Task 1.6: Install npm packages
mkdir -p /var/www/bluefly-cms2/scripts
cd /var/www/bluefly-cms2/scripts
npm init -y
npm install @bluefly/openstandardagents @bluefly/duadp
Create scripts/sync-agents.mjs, scripts/publish-agent.mjs, scripts/sync-policies.mjs per §3.6.
Definition of Done — Week 1: drush status shows all modules enabled; drush ossa:validate returns version gate pass; curl https://bluefly.io/api/v1/health returns 200 (after tunnel is live).
Week 2 — Content Model and Import (Days 6–10)¶
Task 2.1: Create new content types
Create Drupal config for agent_showcase, case_study, ai_service, flow_pipeline content types. Each requires:
config/sync/node.type.<type>.ymlconfig/sync/field.storage.node.field_<field>.ymlfor each fieldconfig/sync/field.field.node.<type>.field_<field>.ymlfor each fieldconfig/sync/core.entity_form_display.node.<type>.default.ymlconfig/sync/core.entity_view_display.node.<type>.default.yml
Task 2.2: Extend existing content types
Add fields to service and page content types per §2.4.
Task 2.3: Create new taxonomy vocabularies
Create agent_category, trust_tier, ossa_kind vocabularies with their terms.
Task 2.4: Run DUADP agent import
drush ossa:sync-registry --source=https://discover.duadp.org --trust-tier=official --limit=60
drush duadp:sync-skills --source=https://discover.duadp.org
drush cedar:sync-policies --source=https://discover.duadp.org --pack=agent-authorization
drush cedar:sync-policies --source=https://discover.duadp.org --pack=claude-code
Verify: drush entity:query ai_agent --count returns 60.
Task 2.5: Migrate existing content
drush migrate:import bluefly_services
drush migrate:import bluefly_focus_areas
drush migrate:import bluefly_pages
drush migrate:import bluefly_resources
drush migrate:import bluefly_testimonials
Migration plugins must be written in web/modules/custom/bluefly_migrate/ before running.
Task 2.6: Create new AI service nodes
Create the 7 new ai_service nodes defined in §5.2 via Drush or the admin UI.
Definition of Done — Week 2: drush entity:query ai_agent --count = 60; all 30 existing services migrated; 7 new AI services created; all taxonomy terms populated.
Week 3 — Canvas Pages and Theme (Days 11–15)¶
Task 3.1: Build SDC component library
Create Single Directory Components in web/themes/custom/bluefly2/components/:
| Component | Purpose |
|---|---|
bluefly:hero-section |
Homepage hero with headline, subtext, dual CTAs, badge |
bluefly:agent-service-grid |
Grid of service cards with DUADP agent badges |
bluefly:flow-drop-embed |
Read-only Flow Drop pipeline visualization |
bluefly:certification-badge |
Drupal Silver Certified badge display |
bluefly:trust-tier-badge |
DUADP trust tier badge (5 tiers, color-coded) |
bluefly:statemesh-evidence |
Live StateMesh claim viewer |
bluefly:agent-card |
OSSA agent card with GAID, capabilities, trust tier |
bluefly:case-study-card |
Case study card with metrics |
bluefly:service-card |
Service card with AI enhancement indicator |
Design tokens must use @bluefly/studio-ui values: Geist Sans for interface text, Geist Mono for code/IDs/metrics, zinc/neutral/slate palette, one accent color (Bluefly blue: #1B4FD8).
Task 3.2: Build Canvas page configurations
Create Canvas page configs for:
- Homepage
- AI Platform landing page
- Services overview
- Individual AI service pages (7 pages)
- Agent showcase pages (one per imported agent category)
Task 3.3: Configure Orchestration DAGs
Create the two DAG configs defined in §4.2:
config/sync/orchestration_dag.content_guardian.ymlconfig/sync/orchestration_dag.service_page_generator.yml
Task 3.4: Configure API Normalization
Create config/sync/api_normalization.source.mcp_blueflyagents.yml per §4.3.
Run: drush api_normalization:import mcp_blueflyagents
Verify: drush tool:list | grep bluefly | wc -l returns 29+.
Task 3.5: Configure Flow Drop demo pipeline
Create flow_pipeline node with the demo config from §4.4.
Definition of Done — Week 3: Homepage renders via Canvas with all SDC components; agent service grid shows 6 imported agents; Flow Drop demo pipeline is visible and interactive; all 7 AI service pages have Canvas layouts.
Week 4 — Governance, StateMesh, and Launch (Days 16–20)¶
Task 4.1: Configure Cedar policy enforcement
Wire cedar_policy module to compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml):
# config/sync/cedar_policy.settings.yml
compliance_engine_url: https://compliance.blueflyagents.com
evaluation_endpoint: /api/evaluate
fail_open: false
timeout: 5000
Test: drush cedar:evaluate --principal="Role::AgentOwner" --action="read" --resource="agent://agents/orchestrator" returns Allow.
Task 4.2: Configure StateMesh
Create the three StateMesh config entities. Configure agent_state_attestation with the Ed25519 signing key. Wire contractplane_client to contractplane.ai.
Task 4.3: Configure DUADP peer node
Create config/sync/duadp_client.settings.yml per §2.5. Run federation registration:
drush duadp:register-node --federation-url=https://register.duadp.org
Verify: curl https://bluefly.io/.well-known/duadp.json returns the node manifest.
Task 4.4: Publish the Easel agent to DUADP
The agent.ossa.yaml (uploaded, for the Easel Canvas agent) must be validated, scored, and published:
ossa validate web/modules/custom/ai_agents_ossa_canvas/agent.ossa.yaml
ossa deploy web/modules/custom/ai_agents_ossa_canvas/agent.ossa.yaml
This opens a GitLab MR to platform-agents and, after merge, publishes to discover.duadp.org.
Task 4.5: Final smoke test
# All modules enabled
drush status | grep -E 'canvas|orchestration|tool|flowdrop|ai_agents|duadp_client|cedar_policy|agent_state'
# DUADP peer node live
curl https://bluefly.io/.well-known/duadp.json | jq .node_id
# 60 agents imported
drush entity:query ai_agent --count
# Cedar evaluation working
drush cedar:evaluate --principal="Role::AgentOwner" --action="read" --resource="agent://agents/orchestrator"
# Canvas homepage rendering
curl -s https://bluefly.io | grep 'canvas-page'
# StateMesh endpoint live
curl https://bluefly.io/api/v1/statemesh/health
Definition of Done — Week 4: All smoke tests pass; bluefly.io/.well-known/duadp.json is live; Easel agent is published to DUADP; Cedar enforcement is active on all agent execution paths; StateMesh is recording claims.
Part 7 — Open Items and Blockers¶
Hard Blockers (Nothing Proceeds Without These)¶
| # | Blocker | Owner | Resolution |
|---|---|---|---|
| B1 | bluefly.io Cloudflare Tunnel route not configured |
Thomas | Add route in Cloudflare dashboard per §P1 |
| B2 | Ed25519 federation keypair not generated | Thomas | Run openssl genpkey per §P3 |
| B3 | compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml) reachability from Oracle not verified for bluefly.io |
Thomas | curl https://compliance.blueflyagents.com/health from Oracle |
Pending Tasks from 03-TASKS-AND-MILESTONES.md That Affect This Build¶
| Task | Status | Impact on Rebuild |
|---|---|---|
Create drupal.org projects for kagent + cedar_policy |
NOT STARTED | cedar_policy must be on drupal.org or VCS-referenced before composer install |
cedar_policy audit + cleanup (427 files, 5 submodules) |
PENDING | Must complete before installing on bluefly.io |
| Demo site Phase 2 — wire DUADP, Cedar ECA | PARTIAL | Patterns from demo site should be replicated on bluefly.io |
| agent-buildkit AI SDK v4→v6 migration | PENDING | Affects any buildkit-generated agents used on bluefly.io |
| OSSA 5-repo critical fixes (GPL relicense, JWT_SECRET, directory traversal) | SOMEDAY | GPL relicense of studio-ui blocks commercial use on bluefly.io |
Architecture Decisions Required¶
| Decision | Options | Recommendation |
|---|---|---|
Should bluefly.io run on the same Oracle VM as the demo sites? |
Shared Oracle VM vs. dedicated host | Separate port (8083) on same Oracle VM; use tunnel routing to isolate |
| Should legacy Drupal 10 content be migrated or rebuilt? | Migrate via migrate_plus vs. rebuild from scratch |
Migrate — 30 services + 12 focus areas have real SEO value; rebuild only the theme and page layouts |
Should font_* taxonomy vocabularies be migrated? |
Migrate all vs. audit first | Audit first — these appear to be from a legacy feature; migrate only if content references exist |
| Should bluefly.io publish its own agents to DUADP or only consume? | Consumer only vs. peer node | Peer node — publishing the Easel agent is the primary live demo value |
| Should IdeaLedger (PAIT) be integrated in this rebuild? | Include vs. defer | Defer to Phase 2 — PAIT schema is defined but the service is not yet live |
Appendix A — File Map for Claude Code¶
The following files must be created or modified. This is the complete file list for the rebuild:
/var/www/bluefly-cms2/
├── composer.json # VCS repos + require entries
├── scripts/
│ ├── package.json # @bluefly/openstandardagents + @bluefly/duadp
│ ├── sync-agents.mjs # DUADP agent import
│ ├── publish-agent.mjs # Publish bluefly agents to DUADP
│ └── sync-policies.mjs # Cedar policy import
├── config/sync/
│ ├── ai.settings.yml
│ ├── api_normalization.source.mcp_blueflyagents.yml
│ ├── canvas_page.homepage.yml
│ ├── canvas_page.ai_platform.yml
│ ├── cedar_policy.settings.yml
│ ├── duadp_client.settings.yml
│ ├── orchestration_dag.content_guardian.yml
│ ├── orchestration_dag.service_page_generator.yml
│ ├── statemesh.settings.yml
│ ├── statemesh.claim_types.yml
│ ├── statemesh.challenge_routing.yml
│ ├── node.type.agent_showcase.yml
│ ├── node.type.case_study.yml
│ ├── node.type.ai_service.yml
│ ├── node.type.flow_pipeline.yml
│ ├── taxonomy.vocabulary.agent_category.yml
│ ├── taxonomy.vocabulary.trust_tier.yml
│ └── taxonomy.vocabulary.ossa_kind.yml
├── web/
│ ├── modules/custom/
│ │ ├── bluefly_migrate/ # Migration plugins for existing content
│ │ │ ├── bluefly_migrate.info.yml
│ │ │ ├── migrations/
│ │ │ │ ├── bluefly_services.yml
│ │ │ │ ├── bluefly_focus_areas.yml
│ │ │ │ ├── bluefly_pages.yml
│ │ │ │ └── bluefly_resources.yml
│ │ └── bluefly_site/ # Site-specific customizations
│ │ ├── bluefly_site.info.yml
│ │ ├── bluefly_site.module
│ │ └── src/
│ │ └── EventSubscriber/
│ │ └── AgentSyncSubscriber.php
│ └── themes/custom/bluefly2/
│ ├── bluefly2.info.yml
│ ├── bluefly2.libraries.yml
│ ├── bluefly2.theme
│ ├── css/
│ │ └── global.css # @bluefly/studio-ui tokens
│ └── components/
│ ├── hero-section/
│ ├── agent-service-grid/
│ ├── flow-drop-embed/
│ ├── certification-badge/
│ ├── trust-tier-badge/
│ ├── statemesh-evidence/
│ ├── agent-card/
│ ├── case-study-card/
│ └── service-card/
Appendix B — DUADP Agent Categories Available for Import¶
From discover.duadp.org (60 agents, all trust_tier: official):
| Category | Agents | Recommended Use on bluefly.io |
|---|---|---|
orchestration |
orchestrator, agent-selector | Service Page Generator DAG, multi-agent coordination |
content |
content-guardian | Content Guardian Pipeline, editorial workflows |
security |
security-auditor | AI Readiness Assessment service |
code |
code-reviewer | Drupal Custom Development service enhancement |
code-quality |
code-quality-reviewer | Best Practice Auditing service enhancement |
communications |
communications-manager | Content Development service, SEO optimization |
infrastructure |
a2a-bridge-worker, cluster-operator | Internal DevSecOps workflows |
gitlab |
ci-fixer-worker | Continuous Deployment Optimization service |
Appendix C — DRY Rules (from OSSA Bible — Enforced on bluefly.io)¶
The following violations will be rejected in code review:
- Any PHP code reimplementing OSSA manifest validation (must delegate to
ossa validate --json) - Any PHP code computing a manifest score (must use
ossa-deploy/src/lifecycle/Scorer.tsvia API) - Any UI component not imported from
@bluefly/studio-ui - Any service opening GitLab MRs to
platform-agentsexceptossa-deploy - Any module reimplementing Cedar evaluation (must call
compliance.<domain>:3010 (per-domain PDP — see FINAL §0b + domains.yaml)) - Any module reimplementing GAID resolution (must call
discover.duadp.org/api/v1/resolve/{gaid}) - Any module generating Agent Cards independently (must use DUADP
/api/v1/agents/{gaid}/card)
Appendix D — Compliance Deadlines¶
| Deadline | Regulation | Technical Requirement |
|---|---|---|
| June 30, 2026 | Colorado AI Act | Cedar policy evaluation on all agent execution paths; StateMesh evidence for all governance-critical decisions |
| August 2, 2026 | EU AI Act | DUADP identity (agent_uri) on all published agents; ContractPlane evidence accessible at contractplane.ai/evidence/{trace_id}; human approval gate in all high-risk DAGs |
| April 2, 2026 | NCCoE concept paper (NIST) | OSSA identity + DUADP discovery → CAISI requirements mapping (tracked in 03-TASKS-AND-MILESTONES.md as at-risk) |
Historical Document III — Bluefly Site Factory — Product Architecture¶
Original path: products/Agent-Factory/FACTORY_PRODUCT_ARCHITECTURE.md. Dated 2026-06-20, status DRAFT — never approved.
Bluefly Site Factory — Product Architecture¶
Date: 2026-06-20 Status: DRAFT — Awaiting Thomas approval before any execution Objective: Define the first Bluefly Factory Pack that generates revenue and deploys repeatedly through GitLab and IaC onto Oracle.
1. BLUEFLY PACK TAXONOMY¶
Six packs. Each is a Gas City pack (pack.toml + agents + formulas + hooks + config). Each can be imported independently. bluefly-core-pack is required by all others.
| Pack | Purpose | Dependencies |
|---|---|---|
bluefly-core-pack |
Identity (GAID), governance (Cedar), observability (tracing), blu-cli integration, receipt pipeline | Gas City core |
bluefly-drupal-pack |
Drupal Site Templates, Recipes, Drush operations, config management, DDEV/Acquia/Oracle targets | bluefly-core-pack |
bluefly-site-factory-pack |
THE REVENUE PACK. Site provisioning formulas, template catalog, customer onboarding, lifecycle management | bluefly-core-pack, bluefly-drupal-pack, bluefly-infrastructure-pack |
bluefly-governance-pack |
Cedar policy evaluation, Dragonfly verification, compliance gates, audit trail, trust posture | bluefly-core-pack |
bluefly-ai-pack |
AI module configuration, provider management, context control, knowledge broker, canvas AI | bluefly-core-pack, bluefly-drupal-pack |
bluefly-infrastructure-pack |
Oracle provisioning, NAS backup, GitLab runner management, Cloudflare tunnels, Tailscale mesh, IaC execution | bluefly-core-pack |
Pack Composition Rules¶
- Every pack is a directory with
pack.tomlat root - Packs import via
gc pack import <source> - Packs compose —
bluefly-site-factory-packimportsbluefly-drupal-packandbluefly-infrastructure-pack - No pack duplicates what Gas City already provides
- No pack contains custom orchestration — formulas only
2. DRUPAL SITE FACTORY — THE FIRST MONETIZABLE FACTORY¶
What It Is¶
A Gas City factory that provisions production-ready Drupal sites in minutes. Customer-facing. Repeatable. Billable.
Customer Outcome¶
"Provision a production-ready Drupal site in minutes."
Not a demo. Not a sandbox. A production site with: - Chosen template applied - Recipes executed - Runtime provisioned (Acquia Cloud / Oracle / AWS) - CI/CD pipeline configured - Monitoring active - Backup scheduled - DNS configured - SSL provisioned
What It Is NOT¶
- Not a custom installer
- Not a Drupal multisite manager
- Not an Acquia Site Factory clone
- Not a hosting company
Revenue Model¶
| Tier | What They Get | Price Signal |
|---|---|---|
| Template License | Site Template + Recipes + Theme + Content Model | One-time |
| Factory Provisioning | Gas City formula execution: template → running site | Per-site |
| Managed Lifecycle | Ongoing: upgrades, backups, security patches, recipe updates | Monthly |
| Custom Template | Bluefly builds a custom template for the customer's vertical | Project SOW |
3. SITE FACTORY FORMULAS¶
These are Gas City v2 formulas. Each is an execution graph with steps, dependencies, variables, retry logic, and failure policy. Agents execute steps. The orchestrator drives completion.
Formula: create-site-from-template¶
The core formula. Everything starts here.
Steps:
1. validate-template
- Input: template_name, customer_id, target_environment
- Action: Verify template exists in catalog, customer authorized, environment available
- Agent: validator
- Fail: ABORT
2. provision-codebase
- Input: template_name, site_name
- Action: Clone template repo, configure composer.json, set site UUID
- Agent: builder
- Depends: validate-template
- Fail: RETRY(2) then ABORT
3. apply-recipes
- Input: recipe_list (from template manifest)
- Action: Execute `drush recipe:apply` for each recipe in order
- Agent: drupal-operator
- Depends: provision-codebase
- Fail: RETRY(1) then ABORT
4. configure-environment
- Input: target_environment, site_name
- Action: Create environment config (config_split), set env variables, configure caching
- Agent: drupal-operator
- Depends: apply-recipes
- Fail: RETRY(1) then ABORT
5. provision-runtime
- Input: target_environment, resource_tier
- Action: Execute IaC (Terraform/Ansible) to provision compute, database, CDN, DNS
- Agent: infra-operator
- Depends: configure-environment
- Fail: ABORT (no partial infra)
6. deploy-site
- Input: site_name, target_environment
- Action: GitLab CI pipeline: build → test → deploy → smoke test
- Agent: deployer
- Depends: provision-runtime
- Fail: ROLLBACK(provision-runtime) then ABORT
7. verify-site
- Input: site_url
- Action: HTTP health check, WCAG audit, security headers check, performance baseline
- Agent: verifier
- Depends: deploy-site
- Fail: FLAG (site deployed but verification failed)
8. emit-receipt
- Input: all outputs from above
- Action: Generate JSON receipt, store in NAS, notify customer
- Agent: recorder
- Depends: verify-site
- Fail: LOG (never block on receipt failure)
Formula: upgrade-site¶
Steps:
1. snapshot-current — Full backup (database + files + config)
2. pull-template-updates — Fetch latest template version
3. apply-recipe-updates — Execute new/updated recipes
4. run-database-updates — drush updatedb
5. deploy-updated-site — GitLab CI pipeline
6. verify-site — Same as create flow
7. emit-receipt
Rollback: restore-from-snapshot at any failure after step 1
Formula: backup-site¶
Steps:
1. export-database — drush sql:dump → NAS
2. export-files — rsync public/private files → NAS
3. export-config — drush config:export → NAS
4. verify-backup — Integrity check on all exports
5. emit-receipt
Formula: recover-site¶
Steps:
1. select-backup — Find most recent verified backup from NAS
2. provision-recovery-runtime — Stand up fresh environment
3. import-database — Restore from backup
4. import-files — Restore from backup
5. import-config — drush config:import
6. verify-site — Full health check
7. dns-cutover — Point DNS to recovery environment
8. emit-receipt
Formula: decommission-site¶
Steps:
1. final-backup — Full backup to NAS with 90-day retention
2. export-content — Content export for customer
3. teardown-runtime — Destroy compute/database/CDN
4. archive-codebase — Archive repo in GitLab
5. revoke-access — Remove customer credentials/keys
6. emit-receipt
4. BLUEFLY SITE TEMPLATES¶
Each template is a product. Each contains everything needed to go from zero to running site.
Template Structure¶
bluefly-templates/
nonprofit/
template.yaml # Manifest: name, version, recipes, theme, content model
recipes/
nonprofit-base/ # Core Drupal recipe
nonprofit-events/ # Events recipe
nonprofit-donors/ # Donor management recipe
nonprofit-blog/ # Blog recipe
theme/
nonprofit-theme/ # Starterkit-based theme with design tokens
content-model/
content_types.yaml # Exported content type definitions
taxonomies.yaml # Vocabulary definitions
media_types.yaml # Media type definitions
config/
config_split/ # Environment-specific config
tests/
cypress/ # E2E tests for this template
deploy/
formula.yaml # Gas City formula override for this template
Template Catalog¶
| Template | Target Market | Recipes Included | Content Types |
|---|---|---|---|
| Nonprofit | 501(c)(3) orgs, foundations, charities | Base, Events, Donors, Blog, Volunteer Management | Event, Campaign, Donor Profile, Impact Report, Grant |
| Higher Education | Universities, colleges, community colleges | Base, Programs, Faculty, Admissions, News, Research | Program, Course, Faculty Profile, Department, Research Project |
| Healthcare | Hospitals, clinics, health systems | Base, Providers, Locations, Services, Patient Resources | Provider, Location, Service, Health Topic, Patient Story |
| SaaS | Software companies, product sites | Base, Pricing, Documentation, Changelog, Blog | Feature, Integration, Pricing Tier, Release Note, Case Study |
| Membership | Associations, unions, professional orgs | Base, Members, Events, Resources, Directory | Member Profile, Resource, Event, Chapter, Benefit |
| Municipality | Cities, towns, counties, state agencies | Base, Services, Departments, News, Public Notices, Meetings | Department, Public Service, Meeting, Public Notice, Elected Official |
Template Quality Bar¶
Every template MUST ship with:
- [ ] WCAG 2.1 AA compliance (automated + manual audit)
- [ ] HTTPS/security headers hardened
- [ ] Performance budget: LCP < 2.5s, CLS < 0.1, FID < 100ms
- [ ] Responsive: mobile, tablet, desktop
- [ ] Content model documentation
- [ ] Editorial workflow (draft → review → publish)
- [ ] Search configured (Search API + Solr/Elasticsearch recipe)
- [ ] Multilingual-ready (i18n recipe optional but composable)
- [ ] Cypress E2E test suite passing
- [ ] Drush commands for content seeding
- [ ] GitLab CI pipeline template (.gitlab-ci.yml)
5. GAS TOWN POSITIONING¶
Gas City is:
- A compatibility pack — operators migrating from Gas City can import gascity pack into their Gas City and retain familiar roles/commands
- A migration pack — gc maps Gas City commands to Gas City primitives
- A reference operating model — Mayor/Deacon/Witness/etc. are role patterns, not platform primitives
Bluefly's relationship to Gas City:
- Import the gascity pack where its role patterns are useful (mayor for planning, reviewer for code review)
- Extend with Bluefly-specific agents (drupal-operator, infra-operator, verifier, recorder)
- Do not build around it — Bluefly agents are Gas City agents with Bluefly pack config, not Gas City roles
6. DEPLOYMENT AUTHORITY¶
The deployment chain is fixed. No manual paths. No SSH-and-pray.
Author (Thomas / Blu / Agent)
→ Git (GitLab, feature branch)
→ agent-buildkit (validation, linting, testing)
→ gitlab_components (reusable CI templates)
→ GitLab Ultimate (CI/CD pipeline execution)
→ IaC (Terraform/Ansible in iac/ repo)
→ Oracle (bluefly-platform.tailcf98b3.ts.net)
→ Gas City (gc supervisor on Oracle)
What Runs Where¶
| Component | Location | How It Gets There |
|---|---|---|
Gas City supervisor (gc) |
Oracle | IaC: Ansible installs gc from Homebrew/tarball |
| Bluefly packs | Oracle, in city directory | GitLab CI: gc pack import from GitLab registry |
| Formulas | Oracle, in city directory | Part of pack, deployed with pack |
| Dolt (beads store) | Oracle | IaC: Ansible installs Dolt |
| Agent sessions (tmux) | Oracle | Gas City manages via tmux provider |
| Site codebases | GitLab repos | Template clone → customer repo |
| Site runtimes | Target environment (Acquia/Oracle/AWS) | Formula step: provision-runtime via IaC |
| Backups | NAS (Synology) | Formula step: backup-site via rsync/NFS |
| Receipts | GitLab job artifacts + Beads metadata | Formula step publishes evidence and records its GitLab reference in the active Bead |
| Cedar policies | Oracle (compliance-engine) | GitLab CI from cedar-policies repo |
| Agent Cards | Oracle (ADS instance) | Published by Agent Card Publisher formula |
What Does NOT Run on Mac¶
- Gas City supervisor
- Agent sessions
- Formula execution
- Dolt database
- Site provisioning
- IaC execution
- Backup operations
Mac is: blu-cli operator console, browser, editor, tmux observer.
7. BLU-CLI AS OPERATOR SURFACE¶
blu-cli wraps gc with Bluefly governance, identity, and operational context. Operators interact with blu, not gc directly.
Command Surface¶
blu pack list # List installed Bluefly packs
blu pack install <pack> # Import and configure a Bluefly pack
blu pack update <pack> # Update pack to latest version
blu formula list # List available formulas
blu formula run <formula> [args] # Execute a formula (triggers gc formula run)
blu formula status <id> # Check formula execution status
blu site create <template> <name> [--env=<target>] # Run create-site-from-template
blu site list # List all managed sites
blu site status <name> # Health check on a managed site
blu site upgrade <name> # Run upgrade-site formula
blu site backup <name> # Run backup-site formula
blu site recover <name> # Run recover-site formula
blu site decommission <name> # Run decommission-site formula
blu deploy <target> # Trigger GitLab CI deployment pipeline
blu deploy status <pipeline_id> # Check deployment status
blu observe # Stream Gas City events (gc events --follow)
blu observe agents # Agent health/status
blu observe formulas # Running formula status
blu observe sites # All managed sites health
blu recover <component> # Recovery runbooks for platform components
What blu-cli Adds Over gc¶
| Concern | gc | blu-cli |
|---|---|---|
| Identity | None | GAID verification, 1Password secret injection |
| Governance | None | Cedar policy pre-check before formula execution |
| Audit | Events log | Receipt generation, NAS persistence |
| Templates | None | Template catalog, version management |
| Observability | gc events |
Unified view across Gas City + GitLab + Drupal |
| Secrets | None | op run integration, never plaintext |
Implementation¶
blu-cliis a Node.js/TypeScript CLI (already exists inblu-cli/repo)- Calls
gcsubprocess for Gas City operations - Calls GitLab API for pipeline operations
- Calls Oracle via SSH/Tailscale for remote operations
- All commands emit structured JSON receipts
8. FIRST FACTORY DEPLOYMENT — THE SEQUENCE¶
This is the execution plan to go from "we have repos" to "we have a running factory on Oracle."
Pre-requisites (already exist)¶
- [x] Oracle server accessible via Tailscale
- [x] GitLab Ultimate with
gitlab_components - [x]
agent-buildkitrepo - [x]
iac/repo with Terraform/Ansible - [x]
blu-clirepo (scaffolded) - [x] Drupal 11 expertise
- [x] Gas City installed locally (for authoring)
Phase 1: Gas City on Oracle¶
- IaC playbook: install
gc,dolt,tmux,jq,beadson Oracle gc init— create the Bluefly city- Verify:
gc statusreturns healthy city - Verify: Supervisor API accessible via Tailscale (
curl http://oracle:PORT/v0/cities) - Receipt:
{phase: 1, status: "city_running", host: "oracle", timestamp: ...}
Phase 2: Core Pack¶
- Author
bluefly-core-pack/pack.tomlwith Bluefly agent definitions gc pack import ./bluefly-core-pack- Verify: agents registered, hooks installed
- Test: sling a trivial bead, confirm execution + receipt
- Receipt:
{phase: 2, status: "core_pack_installed", agents: [...], timestamp: ...}
Phase 3: First Template¶
- Build
nonprofittemplate (recipes, theme, content model, config, tests) - Test locally with DDEV:
ddev start, apply recipes, verify content model - Commit to GitLab, pipeline passes
- Receipt:
{phase: 3, status: "template_verified", template: "nonprofit", timestamp: ...}
Phase 4: Site Factory Pack¶
- Author
bluefly-site-factory-pack/pack.tomlwith formulas - Implement
create-site-from-templateformula gc pack import ./bluefly-site-factory-pack- Test:
gc formula run create-site-from-template template=nonprofit name=demo-site env=dev - Verify: Drupal site running at target URL
- Receipt:
{phase: 4, status: "factory_operational", site: "demo-site", url: "...", timestamp: ...}
Phase 5: blu-cli Integration¶
- Wire
blu site create→gc formula run create-site-from-template - Wire
blu observe→gc events --follow - Test full flow:
blu site create nonprofit acme-nonprofit --env=dev - Verify: site created, receipt emitted, observable
- Receipt:
{phase: 5, status: "cli_operational", command: "blu site create", timestamp: ...}
Phase 6: Customer-Ready¶
- Add remaining formulas (upgrade, backup, recover, decommission)
- Add governance (Cedar pre-checks on formula execution)
- Add monitoring (site health checks on schedule)
- Build second template (pick based on pipeline — likely Higher Education or Municipality)
- Write customer-facing docs
- Price it
9. WHAT THIS IS NOT¶
- ❌ A Gas City tutorial
- ❌ A custom Drupal installer
- ❌ An Acquia Site Factory competitor (different layer)
- ❌ A hosting company pitch
- ❌ A framework
10. WHAT THIS IS¶
A product: Bluefly Site Factory Built on: Gas City (orchestration) + Drupal (platform) + GitLab Ultimate (CI/CD) + Oracle (runtime) Sold as: Templates (one-time) + Provisioning (per-site) + Lifecycle (monthly) Delivered via: Formulas (automated) through blu-cli (governed)
The factory runs without the workstation. Close the laptop, sites keep running, backups keep happening, monitoring keeps checking.