From 3fd81620fcd2773af93c8ef6b5e291a70d663f36 Mon Sep 17 00:00:00 2001 From: tmk241 Date: Sun, 9 Aug 2026 15:52:26 +0200 Subject: [PATCH] docs(skill): define support by host capabilities --- skills/apsuflow/SKILL.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/skills/apsuflow/SKILL.md b/skills/apsuflow/SKILL.md index 4e2b4ff..5cf32cc 100644 --- a/skills/apsuflow/SKILL.md +++ b/skills/apsuflow/SKILL.md @@ -45,9 +45,10 @@ in the same change when applicable requirements or CLI behavior change. - The unprivileged service daemon owns OCI children inside its delegated cgroup v2 subtree. A supervisor may prepare root-owned host networking/firewall state, but the long-running daemon must not gain root merely to bypass a failed - profile. Stable host profiles target Debian glibc/systemd and Void Linux - musl/runit; advertise one only after its complete isolation and golden path - pass. Routine CLI use remains unprivileged and authenticated. + profile. Stable host support is defined by Linux capabilities rather than a + distribution, libc, or init brand; advertise a concrete profile only after its + complete isolation and golden path pass. Routine CLI use remains unprivileged + and authenticated. - `.apsu` contains desired workloads and infrastructure, never secret values or mutable runtime state. - Services are continuously reconciled. Jobs are finite run-to-completion work.