pub enum CapacityClass {
Assured,
BestEffort,
}Expand description
Which execution-capacity class an account’s work belongs to (GL-99).
A separate axis from EnforcementMode, and the two must not be
conflated. Enforcement mode answers whether an account can fund a
request; this answers whether an instance should start an already-valid
request with the compute capacity it has right now. An assured account may
be strict, and a best-effort account still spends quota and emits ordinary
usage whenever it does execute.
The vocabulary is deliberately semantic rather than commercial. Tollgate
has no Paid/Free and no open-ended priority integer: the product maps
its plans onto these two, and which customers are assured is a decision
that stays outside an enforcement substrate.
§Assured is the default, and that is a compatibility choice
An account that states no class gets the availability every account has
today. The unsafe direction would be defaulting to BestEffort, which
would silently make existing traffic sheddable the moment a capacity gate
was enabled — the same reasoning that makes AccountStatus required at
construction and EnforcementMode default to Strict.
Variants§
Assured
Work that may use the whole instance, including the reserve kept for it. The default.
BestEffort
Work that may use only capacity not reserved for assured traffic, and is shed first under load.
Implementations§
Source§impl CapacityClass
impl CapacityClass
Sourcepub const fn as_str(self) -> &'static str
pub const fn as_str(self) -> &'static str
The one spelling of each class: serde’s, the ledger column’s, and the operator-facing one.
The same three-consumer argument AccountStatus::as_str makes — the
tollgate_accounts.capacity_class CHECK constraint, the JSONB
predicate deciding which snapshots a class change rewrites, and the
admin wire DTO all compare these strings, so they all read from here.
It is also the metric label: capacity counters distinguish the classes
by these two tags and nothing else, which is what keeps their
cardinality bounded (GL-99).
Sourcepub const fn may_use_assured_reserve(self) -> bool
pub const fn may_use_assured_reserve(self) -> bool
Whether work of this class may draw on the assured reserve.
Stated once, here, rather than re-derived as == Assured at each pool
decision: the reserve’s whole purpose is that exactly one class reaches
it, and a second spelling of that rule is how the two drift.