diff --git a/skills/apsuflow/SKILL.md b/skills/apsuflow/SKILL.md index 8ea3398..ab513e6 100644 --- a/skills/apsuflow/SKILL.md +++ b/skills/apsuflow/SKILL.md @@ -82,6 +82,19 @@ replacement IaC from a backup, SQLite, or inferred live state. A manual restart may be an emergency diagnostic action, but the durable repair belongs in IaC and must converge after re-apply. +For provider machines managed by an external scheduler, declare `scheduler: +external`, one immutable provider-native `image`, and finite `capacity` in the +pool. An administrator mints the pool-bound credential as `token create --name +demand-POOL --role demand`; that credential can only read and write that pool's +demand. Submit count plus bounded TTL with `apsuflow infra demand POOL COUNT +--ttl SECONDS`. The CLI reads the current revision and sends one conditional +write; on conflict, read current state and decide rather than retrying. Expired +demand converges to zero. External machines never receive Apsuflow releases, +node identities, join credentials, agent configuration, secrets, or startup +payload, and never appear as Apsuflow nodes or workload capacity. Demand zero and +wait for actual provider count zero before changing scheduler/image, removing the +pool, or reducing capacity below use. + ## Install and update For an existing legacy root daemon, use `apsuflow host migrate` rather than