forked from EduCraft/curriculum-project-hub
docs: define SaaS capacity controls
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
# Define initial abuse and capacity controls
|
||||
|
||||
Type: grilling
|
||||
Status: open
|
||||
Status: resolved
|
||||
Blocked by: 02, 03
|
||||
|
||||
## Question
|
||||
@@ -9,3 +9,35 @@ Blocked by: 02, 03
|
||||
Which request limits, file limits, concurrency limits, agent budgets, tenant
|
||||
quotas, and backpressure policies are mandatory for the accepted initial
|
||||
production boundary, and which values or behaviors remain product decisions?
|
||||
|
||||
## Answer
|
||||
|
||||
The initial production service requires layered, fail-closed capacity controls:
|
||||
every mandatory dimension has a versioned non-overridable platform ceiling,
|
||||
while an Organization may configure only a lower policy limit. Agent work uses
|
||||
a durable bounded queue, fair scheduling across Organizations, FIFO within an
|
||||
Organization, explicit overload/expiry/cancellation states, and no automatic
|
||||
whole-run replay after execution starts.
|
||||
|
||||
Hard controls cover request rate/body size, concurrency and queueing, files and
|
||||
archive expansion, Project/Organization storage and entity counts, run/tool
|
||||
budgets, and process resources. Reaching a limit blocks new growth without
|
||||
deleting or hiding existing data. Token and provider cost remain attributed
|
||||
soft-alert signals in the pilot, not hard spend controls; unknown cost is not
|
||||
zero. Platform administrators also receive audited `DRAIN` and `STOP_NOW`
|
||||
workload brakes.
|
||||
|
||||
The full current-state inventory, accepted behavior, and release evidence are
|
||||
recorded in [Initial abuse and capacity controls](../assets/initial-abuse-capacity-controls.md),
|
||||
with the durable decision in ADR-0022 and `Spec.System.Capacity`. Numerical
|
||||
ceilings remain open until production-like calibration.
|
||||
|
||||
The implementation frontier is:
|
||||
|
||||
- [Implement layered limits and multi-dimensional request rate limiting](32-layered-limits-rate-limiting.md)
|
||||
- [Build the durable Organization-fair admission scheduler](33-durable-fair-admission-scheduler.md)
|
||||
- [Enforce file, archive, storage, and entity budgets](34-file-storage-budgets.md)
|
||||
- [Enforce Agent Run and process resource budgets](35-run-runtime-budgets.md)
|
||||
- [Implement provider-mode usage attribution and soft alerts](36-usage-soft-alerts.md)
|
||||
- [Add audited emergency workload brakes](37-emergency-workload-brakes.md)
|
||||
- [Calibrate and prove production capacity ceilings](38-calibrate-production-capacity.md)
|
||||
|
||||
Reference in New Issue
Block a user