Investigation 035 - Distributed Systems Economics

The commitment is stable.
The evidence changed.

A workload already holds an authoritative capacity commitment. Later reports no longer resemble the assumptions that informed it. What, if anything, may legitimately change?

Existing commitment20 capacity units
down
Latest reports31 · 29 · 32 · 30 · 31
down
Authorized changenot yet established

Author's Note

Do not smuggle an answer into the word need.

The original placement may have been correct. Later evidence can challenge the commitment without proving the earlier decision wrong. We begin with the weaker, more honest statement: new evidence appears inconsistent with an existing commitment.

What does the evidence establish? Who may assign meaning to it? Who may seek a change? What must remain true before shared authoritative capacity changes? Those relationships remain unresolved until the experiments earn them.

A measurement may justify reconsideration. It does not silently become the replacement decision.

Prologue

The world changed after the decision.

At time T0, a workload received a legitimate commitment of 20 units. Other decisions can rely on that accounting fact. At T1, delayed and partial reports repeatedly describe behavior near 30. The evidence is real. Its meaning, ownership, and authority are unresolved.

Stable state

The commitment provides predictable accounting to the shared system.

Changing evidence

Reports suggest that execution no longer resembles the assumptions represented at T0.

The mystery

What path may let evidence challenge the commitment without letting observation become authority?

First Principles

One report hides several unanswered questions.

Physical event

Execution consumed some amount during an interval.

Received report

The platform learns a delayed and partial account of that event.

Meaning?

What, if anything, may the report establish about future capacity?

Ownership?

Who may seek a change, and is that responsibility the same as observing?

Authority?

What boundary must hold before shared capacity accounting may rely on a revision?

The report exists. Its meaning, owner, and authority have not yet been earned.

Naive Architecture

Never change the commitment automatically.

The commitment remains fixed regardless of later evidence. This preserves stable accounting and avoids unnecessary coordination. It is often the correct design for stable workloads, deliberate limits, weak signals, or infrequent change.

Later evidence31 · 29 · 32
→
No transitionevidence remains evidence
→
Commitment 20authoritative and stable

The Architecture That Almost Worked

Make the commitment follow the latest report.

Compare the newest received demand signal with the current commitment. If the report is higher, increase the commitment. If lower, decrease it. The design is responsive, direct, and appears economically efficient.

Latest reportdelayed and partial
→
Comparereport vs commitment
→
Rewrite commitmentno intermediate state
The latest report now has a powerful role. What does it actually establish?

Breaking Our Design

Four pressures separate evidence from authority.

Episode 01 starts from direct adaptation. Each later episode unlocks only after the preceding discovery creates its reason to exist.

EPISODE 01

The Report That Changed Once

One accurate report changes an authoritative commitment, then the next report changes it back.

Commitment4
Reportnone
Transitionnone
Meaningunresolved

Start with commitment 4 and receive one accurate report.

EPISODE 02

The Report That Did Not Change Back

Persistent evidence strengthens confidence but still cannot determine what commitment an owner seeks.

Commitment20
Reportsnone
Meaning assignednone
Possible owner responsesunexpressed

Feed the persistent report sequence into the direct architecture.

EPISODE 03

The Change Larger Than the Pool

A legitimate request for change reaches a shared account that cannot support it.

Shared capacity100
Available10
Requested increasenone
AuthorityA remains 30

Establish the shared account before presenting a legitimate change.

EPISODE 04

Three Changes, One Pool

Three legitimate changes each fit alone. Their combined demand does not.

Available20
Claim Anone
Claim Bnone
Claim Cnone

Present three independently owned changes to one finite pool.

Review the four experiments

    The Turning Point

    Evidence may challenge a commitment.
    It may not rewrite one by itself.

    Bounded evidence
    →
    Owned meaning and intent
    →
    Authority + finite capacity

    The Elasticity Contract

    Adapt without collapsing responsibility.

    Seven responsibilities preserve the path from changed evidence to an accepted capacity revision.

    1. Bound observation

    Identify the evidence used without presenting it as complete present truth.

    2. Separate interpretation from intent

    An interpreted requirement explains evidence; it does not declare a change.

    3. Represent a non-authoritative claim

    Intended change exists before other decisions may rely on it.

    4. Cross inherited authority

    Revision uses existing version and admission boundaries.

    5. Preserve shared compatibility

    Accepted revisions obey the declared finite-capacity model.

    6. Keep unavailable claims non-authoritative

    A legitimate request does not manufacture missing capacity.

    7. Stop before fairness

    Elasticity exposes scarcity; it does not rank legitimate owners.

    Delayed and partial evidence
    Owned interpretation
    Interpreted requirement
    Declared intent
    Non-authoritative capacity-change claim
    Authority, version, and shared-capacity boundaries
    Accepted revision or unchanged commitment

    Only Now: Kubernetes

    Autoscaling realizes parts of the contract.

    Horizontal Pod Autoscaling obtains resource, custom, or external metrics and applies policy to compute desired replica count. Metrics remain reports; tolerance, stabilization, and scaling rates remain policy. Updating desired replicas does not itself allocate node capacity, and new Pods may remain unplaced.

    Vertical Pod Autoscaling makes recommendation distinct from application, especially when recommendations are not automatically applied. In-place Pod resize further separates desired, allocated, actuated, and actual resource states.

    These mechanisms realize different portions of the contract. None turns observation into universal authority or makes finite capacity disappear.

    Engineering Reflection

    Let evidence challenge a decision without becoming the decision.

    Keep commitments fixed

    Demand is stable, changes are infrequent, signals are weak, or predictable cost matters more than automatic responsiveness.

    Introduce elasticity

    Changed demand is frequent, consequential, observable enough to interpret, and worth the added policy, state, and coordination cost.

    Costs Accepted

    Observation

    Reports must be collected and remain delayed and partial.

    Interpretation

    Policy must assign meaning without masquerading as architecture.

    Claim state

    Non-authoritative revisions need identity and lifecycle.

    Authority

    Revisions cross version, admission, and capacity boundaries.

    Churn

    Responsiveness can create repeated writes and execution changes.

    Incomplete satisfaction

    Legitimate claims may remain unsatisfied without becoming false.

    Investigation Exercise

    Which claim does the evidence establish?

    Prediction

    Given reports 31, 29, 32, 30, 31 and commitment 20, identify what follows directly.

    Experiment

    Classify each conclusion as observation, interpreted requirement, intent, or capacity compatibility.

    Observation

    Only repeated behavioral difference follows directly from the reports.

    Reflection

    Explain why more samples strengthen evidence without proving intent or availability.

    elasticity trace
    Complete all four experiments before running the synthesis trace.

    Bridge to INV-036

    Every claim is legitimate.
    The pool cannot satisfy them all.

    Several legitimate capacity-change claims converge on one finite shared pool, exposing the unresolved fairness problem
    On what basis should finite capacity be allocated among independently owned legitimate claims that cannot all be satisfied?

    Intellectual Lineage

    Feedback control separates measurement, target, decision rule, and actuator. Borg separates resource requests from observed use. Kubernetes realizes portions through autoscaling controllers, resource requests, and resize state. INV-035 derives the broader evidence-to-authority contract without crediting one mechanism as its origin.

    Deliberate Simplifications Ledger

    Metric, threshold, window, prediction, and adjustment sizePolicy
    Shared-capacity revision realizationDeferred mechanism
    Allocation among legitimate claimsINV-036
    Reclamation and disruptionINV-037-038
    Retry pacing and economic boundednessINV-039