docs(apsuflow): explain external demand

This commit is contained in:
tmk241
2026-08-17 03:55:19 +02:00
parent 98a0200c71
commit 8d43de8f9e
+13
View File
@@ -82,6 +82,19 @@ replacement IaC from a backup, SQLite, or inferred live state. A manual restart
may be an emergency diagnostic action, but the durable repair belongs in IaC and
must converge after re-apply.
For provider machines managed by an external scheduler, declare `scheduler:
external`, one immutable provider-native `image`, and finite `capacity` in the
pool. An administrator mints the pool-bound credential as `token create --name
demand-POOL --role demand`; that credential can only read and write that pool's
demand. Submit count plus bounded TTL with `apsuflow infra demand POOL COUNT
--ttl SECONDS`. The CLI reads the current revision and sends one conditional
write; on conflict, read current state and decide rather than retrying. Expired
demand converges to zero. External machines never receive Apsuflow releases,
node identities, join credentials, agent configuration, secrets, or startup
payload, and never appear as Apsuflow nodes or workload capacity. Demand zero and
wait for actual provider count zero before changing scheduler/image, removing the
pool, or reducing capacity below use.
## Install and update
For an existing legacy root daemon, use `apsuflow host migrate` rather than