Repository navigation
Enforce aggregate user and target-group egress budgets #66
Description
Activity
- addedFeatureA specific missing product behavior.A specific missing product behavior.P2Follow-on improvement or optional expansion after core requirements.Follow-on improvement or optional expansion after core requirements.Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.Current source evidence checked; no new runtime reproduction claimed by backlog creation.Traffic policy and attributionConsistent traffic policy, aggregate budgets and evidence-backed packet attribution.Consistent traffic policy, aggregate budgets and evidence-backed packet attribution.
on Sep 24, 2026 - added a commit that references this issue
on Oct 7, 2026 Implemented in #409. Aggregate grants now reserve payload rate/burst/volume, connection attempts and pinned target counts across each account, executor and every matching destination group. Admission is atomic with the existing job and queue limits; a refusal rolls back both reservations.
Owned Linux regressions cover competing accounts/executors, rotating DNS, configuration reductions, database reopen, authenticated retirement and real TCP/TLS/UDP/ICMP plus accepted TCP replies. See the budget contract and shared-budget tests.
Budgets are opt-in and conservatively reserve full run grants. Unknown execution authority remains charged until authenticated retirement; cancellation does not refund the window. These are guest payload and connection-admission budgets, not an on-wire packet guarantee.
Merged as a9d865d. All 17 checks passed on the exact candidate (guest source check) and the identical merged main (guest source check).
Problem
Destination accounting is keyed by exact destination strings. Separate addresses, aliases or cooperating users can be individually admitted without sharing an operator-defined target-group or user traffic budget.
Proposed change
Add explicit aggregate user/node/target-group network rate and volume budgets in addition to per-destination and per-run allocations. Account concurrent-work and queued-storage admission remain separate controls.
Acceptance criteria
Current evidence
unimplemented aggregate policy; source inspection only, no new runtime reproduction. Backlog classification is based on source inspection; this issue does not claim a new runtime reproduction.
Dependencies
Related work
These are integration points, not prerequisites for starting this issue.
Priority context
Required before accepting untrusted users or advertising the corresponding protected capability; not a blocker for the trusted local TEST alpha.
Validation must use owned local fixtures on supported Linux environments. Record the implementing merge request and relevant test results before closing this issue.
Imported from GitLab issue 65. Originally opened 2026-09-10. Historical GitLab links may require access to the original project.