Stable state
The commitment provides predictable accounting to the shared system.
Investigation 035 - Distributed Systems Economics
A workload already holds an authoritative capacity commitment. Later reports no longer resemble the assumptions that informed it. What, if anything, may legitimately change?
Prologue
At time T0, a workload received a legitimate commitment of 20 units. Other decisions can rely on that accounting fact. At T1, delayed and partial reports repeatedly describe behavior near 30. The evidence is real. Its meaning, ownership, and authority are unresolved.
The commitment provides predictable accounting to the shared system.
Reports suggest that execution no longer resembles the assumptions represented at T0.
What path may let evidence challenge the commitment without letting observation become authority?
First Principles
Execution consumed some amount during an interval.
The platform learns a delayed and partial account of that event.
What, if anything, may the report establish about future capacity?
Who may seek a change, and is that responsibility the same as observing?
What boundary must hold before shared capacity accounting may rely on a revision?
The report exists. Its meaning, owner, and authority have not yet been earned.
Naive Architecture
The commitment remains fixed regardless of later evidence. This preserves stable accounting and avoids unnecessary coordination. It is often the correct design for stable workloads, deliberate limits, weak signals, or infrequent change.
The Architecture That Almost Worked
Compare the newest received demand signal with the current commitment. If the report is higher, increase the commitment. If lower, decrease it. The design is responsive, direct, and appears economically efficient.
The latest report now has a powerful role. What does it actually establish?
Breaking Our Design
Episode 01 starts from direct adaptation. Each later episode unlocks only after the preceding discovery creates its reason to exist.
One accurate report changes an authoritative commitment, then the next report changes it back.
Start with commitment 4 and receive one accurate report.
Persistent evidence strengthens confidence but still cannot determine what commitment an owner seeks.
Feed the persistent report sequence into the direct architecture.
A legitimate request for change reaches a shared account that cannot support it.
Establish the shared account before presenting a legitimate change.
Three legitimate changes each fit alone. Their combined demand does not.
Present three independently owned changes to one finite pool.
The Turning Point
The Elasticity Contract
Seven responsibilities preserve the path from changed evidence to an accepted capacity revision.
Identify the evidence used without presenting it as complete present truth.
An interpreted requirement explains evidence; it does not declare a change.
Intended change exists before other decisions may rely on it.
Revision uses existing version and admission boundaries.
Accepted revisions obey the declared finite-capacity model.
A legitimate request does not manufacture missing capacity.
Elasticity exposes scarcity; it does not rank legitimate owners.
Only Now: Kubernetes
Horizontal Pod Autoscaling obtains resource, custom, or external metrics and applies policy to compute desired replica count. Metrics remain reports; tolerance, stabilization, and scaling rates remain policy. Updating desired replicas does not itself allocate node capacity, and new Pods may remain unplaced.
Vertical Pod Autoscaling makes recommendation distinct from application, especially when recommendations are not automatically applied. In-place Pod resize further separates desired, allocated, actuated, and actual resource states.
These mechanisms realize different portions of the contract. None turns observation into universal authority or makes finite capacity disappear.
Engineering Reflection
Demand is stable, changes are infrequent, signals are weak, or predictable cost matters more than automatic responsiveness.
Changed demand is frequent, consequential, observable enough to interpret, and worth the added policy, state, and coordination cost.
Reports must be collected and remain delayed and partial.
Policy must assign meaning without masquerading as architecture.
Non-authoritative revisions need identity and lifecycle.
Revisions cross version, admission, and capacity boundaries.
Responsiveness can create repeated writes and execution changes.
Legitimate claims may remain unsatisfied without becoming false.
Investigation Exercise
Given reports 31, 29, 32, 30, 31 and commitment 20, identify what follows directly.
Classify each conclusion as observation, interpreted requirement, intent, or capacity compatibility.
Only repeated behavioral difference follows directly from the reports.
Explain why more samples strengthen evidence without proving intent or availability.
Bridge to INV-036
On what basis should finite capacity be allocated among independently owned legitimate claims that cannot all be satisfied?
Feedback control separates measurement, target, decision rule, and actuator. Borg separates resource requests from observed use. Kubernetes realizes portions through autoscaling controllers, resource requests, and resize state. INV-035 derives the broader evidence-to-authority contract without crediting one mechanism as its origin.