You do not attach a domain, a webhook, or a customer queue to a host you do not own. A free model route and a free server are a lease for a spike, not a runtime you quietly promote. If the lease card is missing, stale, or silent on exit, the change fails closed and the spike stays in quarantine.
That rule is narrower than "the tests are green." A green job can still pass on a box that disappears when an allowance ends or a terms page changes. You are gating ownership and exit. You are not gating the color of CI.
Name the blast radius before you name a tool
You are trying to stop one accident. A teammate prototypes an agent on a borrowed host, the demo works, and someone points real traffic at it because the URL already exists. The host was never promised as production. When the lease ends, you lose the process, the disk, or both, and the rollback is a chat thread.
Treat model headlines the same way. A nickname in a news post is not a pin you can deploy. You re-read the offer page on the day of the cutover, and you store that date in the repo. If you cannot point at the page you read, you do not promote.
Keep the spike. Refuse the binding. Those are different changes, and they should not share a commit.
What you may assume
Two availability claims are enough to run the spike, and nothing more. Free model access exists. A free server option exists.
Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode is one place you can use those two options while you fill out the lease card below. This article does not claim a quota, a hardware shape, a duration, a model catalog, a benchmark, or that the offer stays up.
You copy live fields from the current product page into the card. An empty field is a failed gate, not a guess you fill from memory or from an old chat. If you delete the product name, the gates still apply to any borrowed model route and any borrowed host.
Six gates, each with evidence
Copy this list into the pull request that would attach traffic. Each gate needs an artifact in the repo. A verbal "we checked" does not count.
1. Lease card is present and fresh
Evidence is ops/lease-card.yaml with terms_read_on, allowance_note, host_offer, model_route, and reader. Fail closed if the file is absent, if terms_read_on is outside your window, or if allowance_note is blank.
Do not invent a number to make the field pass. A stale figure is worse than an empty one, because reviewers trust it. Write what you read today, including "I could not find a published allowance" if that is the truth.
2. Model route is an identifier, not a headline
Evidence is a route string that matches the page you read, plus a one-line note of where you read it. Fail closed if the route is latest, free, default, or a name you only saw in a roundup.
You can change the pin later. You cannot promote on a moving nickname. Headlines are topic signals, not deploy config.
3. The borrowed host holds no long-lived secret
Evidence is a secret scan log, or a CI check that denies .env files and cloud keys on that path. Fail closed if customer tokens or deploy keys sit on the host.
A free server is a spike box. It is not a vault. A demo login is still a secret, and it does not belong in a notebook you might share.
4. Data exit is rehearsed
Evidence is a dry-run log that copies prompts, logs, and any user content to a place you own, then deletes the spike copy. Fail closed if the only copy lives on the borrowed disk.
"We can export later" is not a rehearsal. Later is when the disk is already gone. If the drill has not been run, the gate is red even if the demo looks fine.
5. Traffic attachment is a separate change
Evidence is a DNS, webhook, or queue diff in its own pull request, and that request links the lease card. Fail closed if one commit both creates the demo and binds production traffic.
Reviewers cannot see the blast radius in a mixed diff. Split it. The demo can merge on Monday. The binding waits for the card.
6. A person owns rollback, and the kill switch was timed
Evidence is a rollback_owner who is a named person, plus a drill note with a duration. Fail closed if the owner is "the team" or the drill has never been run.
You want a human who can unbind the route without asking who has the password. A rotation alias is not a person. Name someone for this cutover.
The checker you run before review
The script below is a proposal. It uses only the standard library. It does not call a vendor, and it does not know your quota. Run it locally, then wire a non-zero exit to the pull request that binds traffic.
# ops/lease-card.yaml
# Example only. Replace every value after you read the live page.
terms_read_on: "2026-10-10"
reader: "oncall-name"
host_offer: "free-server"
model_route: "pin-from-the-page-you-read"
allowance_note: "copied from the current offer page, not from memory"
data_exit: "rehearsed"
secrets_on_host: "no"
traffic_pr: "separate"
rollback_owner: "sam"
rollback_drill_on: "2026-10-09"
#!/usr/bin/env python3
"""Fail closed unless a borrowed-host lease card is complete and fresh.
Proposal only: stdlib, no network, no vendor client.
"""
from __future__ import annotations
import sys
from datetime import date, datetime
from pathlib import Path
REQUIRED = [
"terms_read_on",
"reader",
"host_offer",
"model_route",
"allowance_note",
"data_exit",
"secrets_on_host",
"traffic_pr",
"rollback_owner",
"rollback_drill_on",
]
BANNED_ROUTES = {"", "latest", "free", "default", "auto"}
MAX_AGE_DAYS = 7
def parse_flat_yaml(text: str) -> dict[str, str]:
data: dict[str, str] = {}
for raw in text.splitlines():
line = raw.split("#", 1)[0].strip()
if not line or ":" not in line:
continue
key, value = line.split(":", 1)
data[key.strip()] = value.strip().strip('"').strip("'")
return data
def age_days(iso_day: str, today: date) -> int:
parsed = datetime.strptime(iso_day, "%Y-%m-%d").date()
return (today - parsed).days
def main(path: str) -> int:
card = parse_flat_yaml(Path(path).read_text(encoding="utf-8"))
errors: list[str] = []
for key in REQUIRED:
if not card.get(key):
errors.append(f"missing or blank: {key}")
route = card.get("model_route", "").lower()
if route in BANNED_ROUTES:
errors.append("model_route is a nickname, not a pin")
if card.get("secrets_on_host", "").lower() != "no":
errors.append("secrets_on_host must be no")
if card.get("data_exit", "").lower() != "rehearsed":
errors.append("data_exit must be rehearsed")
if card.get("traffic_pr", "").lower() != "separate":
errors.append("traffic attachment must be a separate change")
owner = card.get("rollback_owner", "").lower()
if owner in {"", "team", "oncall"}:
errors.append("rollback_owner must be a named person")
today = date.today()
for key in ("terms_read_on", "rollback_drill_on"):
raw = card.get(key, "")
if not raw:
continue
try:
delta = age_days(raw, today)
if delta > MAX_AGE_DAYS or delta < 0:
errors.append(f"{key} is outside the {MAX_AGE_DAYS}-day window")
except ValueError:
errors.append(f"{key} is not YYYY-MM-DD")
if errors:
print("FAIL closed:")
for item in errors:
print(f"- {item}")
return 1
print("PASS: lease card is complete enough to review the traffic PR")
return 0
if __name__ == "__main__":
target = sys.argv[1] if len(sys.argv) > 1 else "ops/lease-card.yaml"
sys.exit(main(target))
python3 ops/check_lease_card.py ops/lease-card.yaml
echo $?
A missing card is not a warning. It is a stop. Do not add a bypass label because the demo is on a call in twenty minutes.
What the drill log must contain
You keep the drill log next to the card, in ops/exit-drill.md. Four lines are enough. Each line is evidence a reviewer can diff.
- Start time and end time, in UTC, so the duration is not a vibe.
- Source path on the borrowed host, and the destination path you own.
- A checksum or file count that matches on both sides before you delete the spike copy.
- The command or console step that unbinds DNS, the webhook, or the queue, plus who ran it.
If any line is missing, gate 4 or gate 6 fails. You do not finish the drill in a ticket and leave the proof in a screenshot nobody can diff. A screenshot can support the log. It cannot replace it.
Also record what you refused to copy. Customer payloads that should never have been on the spike box are an incident note, not a successful exit. The checker will not catch that. A human reading the log will, which is why gate 6 names a person.
Review the traffic pull request in this order
- Open the lease card. Reject it if
terms_read_onis outside your window. - Read
allowance_note. If it looks remembered, send the author back to the live offer page. - Diff secrets. The borrowed host path must not gain a key, a token, or a
.env. - Read the exit log. A path you own must show the copy, and the spike copy must be deleted in the drill.
- Confirm the DNS, webhook, or queue diff is the only production binding in the request.
- Require the named rollback owner to acknowledge the pull request.
- Run the checker. Non-zero means no merge.
Short requests still get the full list. A small webhook is still production traffic if a customer can hit it.
A small decision table
| Situation | Result | What you do |
|---|---|---|
| Card fresh, no secrets, exit rehearsed, traffic change is separate | Review may proceed | Attach traffic only behind the kill switch you already timed |
| Demo works, card blank | Fail closed | Stay in quarantine |
| Allowance copied from memory or an old post | Fail closed | Re-read the offer page and restamp the date |
| One commit creates the app and the DNS record | Fail closed | Split the change |
| Rollback owner is a rotation name | Fail closed | Name a person for this cutover |
| You need a durability promise the page does not make | Do not use this path | Pick a host whose contract you can cite |
Use the table in the pull request comment. Paste the row you matched, and paste the checker output under it. Reviewers should not have to reconstruct your reasoning from a green demo GIF.
Limitations, and who should skip this
This checklist does not make a free server production-grade. It stops you from pretending a spike is a cutover. Skip it for regulated data, long-lived customer secrets, or any workload that needs an uptime promise.
Skip it if nobody will own rollback. A passing script is not a penetration test, a backup proof, or a legal reading of the offer. The 7-day window is a team choice in the proposal, not a vendor rule. Shorten it if the page you depend on changes often.
The checker parses a flat file on purpose so a reviewer can see every failure. It will not understand nested YAML. Keep the card flat. Do not publish quota figures, hardware names, or "unlimited" language in the card. Those claims go stale, and a stale card is how a borrowed host becomes an unowned dependency.
Keep the spike cheap enough to throw away
You can still learn on the borrowed box. Break the prompt. Time your own requests. Write down what failed. Those notes belong in a place you own.
Free model access and a free server are useful because the spike should be cheap enough to discard. Discard only works if exit is rehearsed before the URL leaves the notebook. Cheap is not the same as safe to bind.
If you want a concrete place to try that spike, use MonkeyCode's free model access and free server, copy the current offer into the lease card, and run the checker before any domain change. Stop there until a person reviews the traffic pull request.
Top comments (0)