# Consumption-mode enforcement Work record: `RAILIANCE-WP-0017-T01` Signal owner: `resource-control` (`docs/resource-procurement-facility.md`) Terms: `resource-control/docs/TermsOfResourceProcurement.md` § 11.4 `resource-control` publishes `open` / `restricted` and the remaining transfer-price allowance. This repo refuses **new orders** and **elastic usage** that would exceed that allowance. It does not throttle a running cluster and does not cancel a committed provider contract (OQ-2). ## Signal Default file: `data/consumption-mode/current.json` Shape (one record or a list): ```json { "schema_version": "0.1", "record_type": "consumption_mode", "financial_entity_id": "entity:coulomb", "period": "2026-09", "consumption_mode": "restricted", "new_transfer_charges_allowed_eur": "45.83", "terms_version": "0.1" } ``` Refresh after a settlement close by writing that file (or pointing `CONSUMPTION_MODE_FILE` at a settlement-statement JSON — the helper projects `next_month_allowance_eur`). An empty list means no entity is restricted. Missing mode is **not** `open` and **not** `restricted`; it does not refuse. `entity:railiance` is the procuring entity and is never restricted. ## Check ```bash make consumption-preflight \ CONSUMING_ENTITY=entity:coulomb \ ESTIMATE_EUR=20 \ CONSUMPTION_CLASS=new-order ``` | Class | Restricted behaviour | | --- | --- | | `new-order` / `elastic` | Refuse if estimate is missing or greater than the allowance | | `safety` | Admit; print an exception line (backup, identity, ingress needed to avoid data loss) | | `committed` | Admit; flag for human financial authority (do not cancel) | ## Where it is wired | Target | Class | Notes | | --- | --- | --- | | `make consumption-preflight` | caller-supplied | required on any new consuming order | | `make apps-pg-deploy` | `new-order` | only when `CONSUMING_ENTITY` is set (a new consumer, not a re-apply) | | `make valkey-deploy` | `new-order` | already gated; would still have to pass this check | | Backup / restore deploys | `safety` | continue under restriction; overage is an exception | A restricted entity cannot place a new order that would exceed the published allowance. An `open` entity is unchanged.