Inherited
Reclamation authority exists; observation is delayed and partial; a policy result is not authoritative state.
Investigation 038 - Distributed Systems Economics
The platform may legitimately reclaim a commitment held by healthy work. That authority does not by itself establish that exercising it is safe for the work being displaced. What availability boundary must constrain intentional disruption?
Coordinated service
3 expectedReclamation authority exists. Safety does not — yet.
Prologue
Healthy accepted work is committed and serving its purpose. Another legitimate demand cannot be satisfied without changing that commitment. INV-037 already settled whether the platform may reclaim it. The harder question is what happens if it does: refusing every disruption can block legitimate progress indefinitely, while exercising authority whenever it exists can interrupt work that was running correctly.
Reclamation authority exists; observation is delayed and partial; a policy result is not authoritative state.
Count intentional displacements and treat the count as the availability boundary.
What must the boundary protect, and where does its authority stop?
First Principles
An ownership fact. It does not describe the useful work that depends on the resources.
Delayed evidence about health, not the physical condition of the work right now.
Authority to act. It does not establish the consequence of acting.
A platform-caused event, distinct from failures the platform did not cause.
What availability is requested, what health is observed, what disruption is permitted, what displacement occurred, and what recovery is later observed are five different facts.
Naive Architecture
If the platform never intentionally displaces healthy work, it never needs to ask whether that displacement is safe. Reclamation, maintenance, and rebalancing all wait. The availability question disappears because the action that would create it never happens.
The Architecture That Almost Worked
Relax the absolute rule by exactly one step. The platform may perform one active intentional displacement. A second must wait for the allowance to free up. The count is bounded, so the risk appears bounded too.
The candidate does not claim one displacement is harmless. It claims only that intentional disruption will be limited to one active action. Whether that bounds availability risk is untested.
Breaking Our Design
Episode 01 starts from the one-displacement candidate. Each later episode unlocks only after the preceding discovery creates its boundary.
The candidate allowance is free, but the affected work is already degraded for an unrelated reason.
Observe the workload before proposing an intentional displacement.
The same allowance and the same action count are applied to differently related work.
Apply the same candidate to both arrangements.
Reclamation, maintenance, and rebalancing each evaluate their own intentional displacement independently.
Let each path propose its own intentional displacement.
An event outside the governing authority affects the same work while a governed displacement is being considered.
Propose one governed intentional action before introducing an independent event.
The Turning Point
The Availability Protection Contract
Intentional disruption remains legitimate under INV-037's reclamation authority. This contract constrains what may be honestly claimed about exercising that authority.
Bounding the number of intentional actions does not, by itself, bound their availability consequence.
The same action count can mean different things depending on the relationship among the affected executions.
Overlapping intentional paths cannot each make a complete availability claim about the same work in isolation.
Protection cannot honestly claim authority over events outside the system governing the intentional disruption.
Reclamation authority is not availability safety. Action count is not availability consequence. Governed protection is not a universal guarantee.
Only Now: Kubernetes
An owner selects a set of Pods and declares a minimum available or maximum unavailable count. The disruption controller evaluates that policy against observed Pods and records how many disruptions are currently allowed. API-initiated eviction is checked against this budget before proceeding.
Participation has a visible limit. Direct Pod deletion and workload rollouts can bypass budget evaluation. Involuntary failures count against the budget's picture but cannot be prevented by it. The mechanism is one concrete policy realization, not the architectural invariant itself.
A configured budget does not prove that every path capable of disrupting the selected work will honor it.
Engineering Reflection
Healthy work is never intentionally displaced, operational change can wait, or another environment absorbs the workload.
A shared platform must make intentional progress while several forms of work carry different availability expectations.
The system needs more contextual information than a bare action count to reason about consequence.
Independent local decisions can no longer be treated as complete in isolation.
Legitimate reclamation authority may still wait on the availability protection boundary.
The platform cannot promise protection from events it does not govern.
Investigation Exercise
State whether a bounded action count alone tells you the availability consequence of the next intentional displacement.
Vary the relationship among affected executions and the number of overlapping intentional paths while holding the count fixed.
Record whether an independent event outside the governing authority changes what the protection can honestly claim.
Separate the architectural boundary from the health signal, threshold, or coordination mechanism a concrete system chooses.
Bridge to INV-039
How can a corrective system remain live when work must be reconsidered, without allowing repeated attempts to consume shared capacity without bound?
Borg treated high availability as a property of workload relationships, placement, and correlated-failure policy rather than a single global action count. Omega showed that independently legitimate decisions over shared state can interfere. Control theory distinguishes controlled inputs from external disturbances a controller does not own.