docs(skill): define support by host capabilities

This commit is contained in:
tmk241
2026-08-09 15:52:26 +02:00
parent b186f31e9b
commit 3fd81620fc
+4 -3
View File
@@ -45,9 +45,10 @@ in the same change when applicable requirements or CLI behavior change.
- The unprivileged service daemon owns OCI children inside its delegated cgroup
v2 subtree. A supervisor may prepare root-owned host networking/firewall state,
but the long-running daemon must not gain root merely to bypass a failed
profile. Stable host profiles target Debian glibc/systemd and Void Linux
musl/runit; advertise one only after its complete isolation and golden path
pass. Routine CLI use remains unprivileged and authenticated.
profile. Stable host support is defined by Linux capabilities rather than a
distribution, libc, or init brand; advertise a concrete profile only after its
complete isolation and golden path pass. Routine CLI use remains unprivileged
and authenticated.
- `.apsu` contains desired workloads and infrastructure, never secret values or
mutable runtime state.
- Services are continuously reconciled. Jobs are finite run-to-completion work.