BLU LOOP

Below are reusable execution lanes, not project-specific loops. They are designed for Claude Code /loop and should be saved as durable slash-command snippets or pasted as needed. Claude Code supports custom slash-command workflows, GitLab MRs/issues are the review/change boundary, GitLab CI/CD components are the reusable CI substrate, and 1Password service accounts support op run for automation without exposing raw secrets.

⸻

  1. Release Gate Loop

Use when a package/repo is near release.

/loop 10m /agent MISSION: Release gate loop. Every cycle: 1. Confirm active bead. 2. Confirm repo root and branch. 3. Confirm package identity/version. 4. Run only release gates: - build - test - validate/lint - pack/dry-run - CI status 5. If green, prepare release handoff. 6. If failed, fix only the smallest release-surface failure. 7. Append evidence to bead. Allowed mutations: - package metadata fix - lockfile sync - CI release-surface fix - test/build fix inside scoped package Forbidden: - branch cleanup - unrelated refactor - ownership redesign - new wrappers - secret reads - force push - protected branch merge - publish without approval Receipt: { "loop_type": "release_gate", "bead": "", "repo": "", "branch": "", "package": "", "version": "", "gates": { "build": "", "test": "", "validate": "", "pack": "", "ci": "" }, "mutation": "", "evidence": "", "result": "", "next_action": "" }

⸻

  1. CI Failure Loop

Use when a visible pipeline/job fails.

/loop 10m /agent MISSION: CI failure loop. Every cycle: 1. Confirm active bead. 2. Inspect exactly one failed pipeline/job. 3. Capture failing command and root cause. 4. Apply smallest scoped fix only if root cause is proven. 5. Run equivalent local check. 6. Commit/push only scoped files. 7. Report receipt. Priority: 1. Required failed jobs. 2. Blocking failed jobs. 3. allow_failure jobs only if they hide release risk. Forbidden: - broad CI archaeology - editing shared CI substrate unless failure explicitly names it - changing unrelated jobs - adding new components - branch deletion - force push - secret reads Receipt: { "loop_type": "ci_failure", "bead": "", "repo": "", "branch": "", "pipeline": "", "job": "", "failing_command": "", "root_cause": "", "mutation": "", "local_verification": "", "push": "", "result": "", "next_candidate": "" }

⸻

  1. MR Triage Loop

Use for cleanup across many GitLab MRs without global inventory. GitLab approval rules and Code Owners should remain GitLab-owned boundaries, not custom shell policy.

/loop 15m /agent MISSION: MR triage loop. Every cycle: 1. Confirm active bead. 2. Pick one MR from approved triage queue. 3. Verify MR status directly in GitLab. 4. Execute exactly one safe mutation: - close superseded MR - comment with blocker - link issue/bead - merge approved green MR if allowed - label needs_review/stale/superseded 5. Append evidence to bead. Selection priority: 1. Superseded MR with proof. 2. Approved/resolved green MR. 3. Stale MR needing owner decision. 4. MR missing linked issue/bead. 5. MR needing label/status cleanup. Forbidden: - merge red MR - close without proof - inspect unrelated branch graph - branch deletion - force push - broad cleanup - secret reads Receipt: { "loop_type": "mr_triage", "bead": "", "target_mr": "", "status_checked": "", "evidence": "", "mutation": "", "result": "", "skipped": "", "next_candidate": "" }

⸻

  1. Issue Hygiene Loop

Use to keep Beads/GitLab issues aligned.

/loop 10m /agent MISSION: Issue hygiene loop. Every cycle: 1. Confirm active bead. 2. Pick one stale or completed issue. 3. Verify direct evidence: - merged MR - passing CI - commit SHA - linked bead - explicit blocker 4. Execute exactly one mutation: - close completed issue - update stale issue with blocker - link MR/commit/bead - mark needs_review 5. Append evidence. Forbidden: - closing without proof - speculative status changes - broad issue relabeling - project redesign - branch cleanup Receipt: { "loop_type": "issue_hygiene", "bead": "", "issue": "", "evidence": "", "mutation": "", "result": "", "next_candidate": "" }

⸻

  1. Dependency Drift Loop

Use when scripts reference missing deps, lockfiles drift, or fresh clone breaks.

/loop 10m /agent MISSION: Dependency drift loop. Every cycle: 1. Confirm active bead. 2. Identify one dependency drift symptom. 3. Verify: - script reference - package manifest - lockfile state - failing command 4. Fix only manifest/lockfile mismatch. 5. Run install/check/test. 6. Commit package files only. Allowed mutations: - package.json - package-lock.json - pnpm-lock.yaml - composer.json - composer.lock - requirements/pyproject lock equivalents Forbidden: - dependency upgrades unrelated to failure - new framework packages - broad refactor - generated dist unless release requires it - secret reads Receipt: { "loop_type": "dependency_drift", "bead": "", "repo": "", "branch": "", "symptom": "", "root_cause": "", "files_changed": [], "checks": [], "mutation": "", "result": "" }

⸻

  1. Auth Boundary Loop

Use when auth blocks a lane. 1Password owns secret injection; agents must not inspect resolved values.

/loop 10m /agent MISSION: Auth boundary loop. Every cycle: 1. Confirm active bead. 2. Test the approved auth wrapper only. 3. If auth fails, classify failure: - unresolved op reference - expired session - missing service account token - missing GitLab permission - wrong env var name 4. Report unresolved reference names only. 5. Do not print secret values. 6. If safe, fix only non-secret env reference names/docs. Approved wrapper: op run --account blueflyiollc --env-file= -- Forbidden: - raw token reads - ~/.tokens - env dumps - printenv - vault enumeration - pasted PATs - glab auth login/refresh/logout Receipt: { "loop_type": "auth_boundary", "bead": "", "command_class": "", "auth_wrapper": "", "failure_class": "", "unresolved_reference_names": [], "mutation": "", "result": "", "next_action": "" }

⸻

  1. Canonical Ownership Loop

Use post-release only. It classifies duplicate ownership; it does not build.

/loop 15m /agent MISSION: Canonical ownership loop. Every cycle: 1. Confirm active bead. 2. Pick one capability from approved ownership queue. 3. Identify: - canonical owner - authorized adapters - duplicate owners - consumers - deletion candidates 4. Execute one safe mutation only: - add ledger entry - add migration note - mark duplicate as deprecated - create/link consolidation bead 5. Do not delete code unless explicitly authorized. Capability rule: One capability. One canonical owner. Many adapters. Many consumers. Zero competing authorities. Forbidden: - building new implementation - deleting without migration note - touching release lanes - broad audit - ontology debate - wrapper creation Receipt: { "loop_type": "canonical_ownership", "bead": "", "capability": "", "canonical_owner": "", "authorized_adapters": [], "duplicate_owners": [], "consumers": [], "mutation": "", "result": "", "next_candidate": "" }

⸻

  1. QMD Knowledge Capture Loop

Use after discoveries. This prevents knowledge from being trapped only in chat or commits.

/loop 10m /agent MISSION: Knowledge capture loop. Every cycle: 1. Confirm active bead. 2. Identify one durable operational discovery. 3. Write one QMD/library entry. 4. Run qmd update. 5. Query to verify retrieval. 6. Commit only the knowledge artifact and index changes if required. 7. Append receipt to bead. Capture only: - operational rule - recurring failure pattern - proven fix sequence - ownership decision - release decision - auth boundary - CI failure class Forbidden: - dumping chat logs - secrets - unresolved speculation - broad memory imports - duplicate docs without redirect - unrelated cleanup Receipt: { "loop_type": "knowledge_capture", "bead": "", "discovery": "", "qmd_path": "", "qmd_update": "", "query_verification": "", "commit": "", "result": "" }

⸻

  1. Onboarding Guardrail Loop

Use for new developers and 100-dev scaling. No product code.

/loop 15m /agent MISSION: Developer onboarding guardrail loop. Every cycle: 1. Confirm active bead. 2. Pick one repo onboarding gap. 3. Add or update exactly one guardrail artifact: - CODEOWNERS - onboarding doc - MR guardrails doc - issue template - contributing doc 4. Verify no product code changed. 5. Commit/push branch. 6. Report MR-ready receipt. Forbidden: - production config - secrets - runtime infra - broad governance rewrite - new tooling - branch deletion - force push Receipt: { "loop_type": "onboarding_guardrail", "bead": "", "repo": "", "branch": "", "artifact": "", "files_changed": [], "checks": [], "mutation": "", "result": "" }

⸻

  1. Runner Queue Loop

Use only when pipelines are pending. Pending means “not yet assigned/executing,” not a code failure. Treat it as queue state until proven otherwise.

/loop 10m /agent MISSION: Runner queue loop. Every cycle: 1. Confirm active bead. 2. Poll exact pipeline IDs only. 3. If pending, report queue state. 4. If running, report active jobs. 5. If failed, switch to CI failure loop for failed job only. 6. If success, switch to release gate receipt. Forbidden: - branch archaeology - runner redesign - gitlab_components cleanup - repo edits - tag/publish before success - broad infra debugging unless pending exceeds operator-defined threshold Receipt: { "loop_type": "runner_queue", "bead": "", "pipelines": [], "statuses": {}, "mutation": "none", "result": "", "next_action": "wait|ci_failure_loop|release_gate_loop" }

⸻

Master Dispatcher Loop

Use this as the only general-purpose loop.

/loop 10m /agent MISSION: Bluefly sustainable execution dispatcher. Every cycle: 1. Confirm active bead. 2. Determine lane from bead metadata. 3. Run exactly one lane loop: - release_gate - ci_failure - mr_triage - issue_hygiene - dependency_drift - auth_boundary - canonical_ownership - knowledge_capture - onboarding_guardrail - runner_queue 4. Execute one verified action or produce one verified blocker. 5. Append receipt to bead. 6. Move to next ready bead only if current bead is blocked. Global rules: - No bead, no work. - No canonical owner, no build. - No broad audits during release lanes. - No branch deletion. - No force push. - No raw secrets. - No ~/.tokens. - No stage-all. - No new wrappers. - No laptop-local Claude infrastructure unless bead explicitly says developer-tool cleanup. - If blocked, classify and move to next approved ready bead. - One action per loop. Receipt: { "dispatcher": "bluefly_sustainable_execution", "active_bead": "", "selected_loop": "", "repo": "", "branch": "", "capability": "", "canonical_owner": "", "action": "", "mutation": "", "evidence": [], "blocked": false, "blocker": "", "next_ready_bead": "" }

The sustainable set is: Release Gate, CI Failure, MR Triage, Issue Hygiene, Dependency Drift, Auth Boundary, Canonical Ownership, QMD Capture, Onboarding Guardrail, Runner Queue, and the Master Dispatcher. Everything else should be a bead-specific instantiation of one of these, not a new loop.