DEV Community

Avery Li
Avery Li

Posted on

Date the Quota Card Before Generated CI Targets a Free Server

A generated CI job should not target a free model server until a fresh quota card sits beside the change. That card records the allowance a person just confirmed, the server boundary, and the time of the check. A senior pairing kept this single gate after two cheaper ideas failed during the same review. The workflow below is a labeled exercise, not a record of private production metrics or customer results.

The question the pairing had to settle

The working question stayed narrow for a small team that already reviews generated changes before they leave. The pair asked whether a generated workflow could use free model access without a dated local card. The senior also required the current project page, the job boundary, and the failure behavior when either fact was missing. MonkeyCode enters the exercise only as the source of those two operator-supplied availability claims, and the rest of the method stands alone.

Disclosure: This article was prepared as part of MonkeyCode's product outreach.

Questions the senior actually asked

The session log kept four requests, and each request had to be answered with a file or a refusal. The first request demanded the documentation timestamp rather than a recollection of an earlier campaign page. The second request demanded a server name that was not production and was not a shared customer environment. The third request demanded the exit code when the card was missing, stale, or pointed at a forbidden boundary.

The fourth request demanded that campaign numbers stay out of the job file even when a person believed those numbers were still current. Each answer had to fit on the card or in the gate output, because a verbal reassurance was not accepted as evidence. The pairing stopped when those four answers existed as files, and it did not continue into model selection.

Dead ends that looked faster

The first dead end treated an outreach sentence as a permanent quota contract for the build. A quoted token pool, including any large round number in a campaign note, was refused as a build input. Allowances change, and a hardcoded count would become stale without a visible failure at generation time. The second dead end sent the generated job to a shared free server and hid the boundary until afterward.

The decision that stayed

The pairing kept one decision and dropped every faster alternative that skipped the local freshness check. No generated job file may be written unless a local quota card is present, fresh, and explicit about the server boundary. A person fills that card after reading the current project documentation, not the model that drafts the workflow. Free model access and a free server option may be used only inside that recorded boundary, and live docs should be rechecked first.

This exercise does not name models, publish quotas, describe hardware, or promise how long either free option will remain available. Readers should treat every allowance figure in campaign copy as untrusted until a person copies a current observation into the card. The card may say that free model access and a free server option were visible, but it may not invent a token total. A future change in those offers should fail the next review instead of silently riding an old sentence.

Numbered workflow

  1. Open the current project documentation and record only the claims a person can verify on that page today.
  2. Write those observations into a local quota card with a UTC timestamp, a maximum age, and a non-production server label.
  3. Run the gate so a missing, stale, or production-bound card exits non-zero before any workflow file is created.
  4. Allow a generator to draft a job only after the gate prints a success token, and keep the card in the same review.
  5. Re-run the same gate in CI so a card older than the agreed window fails closed instead of spending an unverified allowance.

What the card is allowed to store

The card is a review artifact rather than a billing API, and it is also not a secret store. It may store the check time, the maximum age, the server boundary, and two booleans for the offers a person just saw. It may store a short note that says where the person looked, without pasting a promotional paragraph into the repository. It must not store tokens, passwords, customer identifiers, or a guessed remaining balance from any earlier page.

The gate script

The Python below is a proposed local gate for the exercise, and it has not been presented as a measured production control. The script does not call a network, does not invent a quota, and does not deploy or configure a server. It only accepts or rejects the card a person already wrote after checking the current documentation. Placeholder values in the sample card are not product facts and must be replaced before any real use.

#!/usr/bin/env python3
"""Proposed gate: refuse a generated job until a fresh quota card exists."""
import json
import sys
from datetime import datetime, timedelta, timezone
from pathlib import Path

REQUIRED = (
    "checked_at",
    "max_age_hours",
    "server_boundary",
    "free_model_access",
    "free_server_option",
)
FORBIDDEN = {"production", "prod", "shared-prod"}

def load_card(path: Path) -> dict:
    data = json.loads(path.read_text(encoding="utf-8"))
    missing = [key for key in REQUIRED if key not in data]
    if missing:
        raise SystemExit("CARD_MISSING_FIELDS")
    return data

def assert_fresh(card: dict, now: datetime) -> None:
    checked = datetime.fromisoformat(card["checked_at"])
    if checked.tzinfo is None:
        raise SystemExit("CARD_TIME_NAIVE")
    age = now - checked
    limit = timedelta(hours=float(card["max_age_hours"]))
    if age > limit or age < timedelta(0):
        raise SystemExit("CARD_STALE")

def assert_boundary(card: dict) -> None:
    boundary = str(card["server_boundary"]).strip().lower()
    if not boundary or boundary in FORBIDDEN:
        raise SystemExit("CARD_BOUNDARY_REFUSED")
    offers_ok = (
        card["free_model_access"] is True
        and card["free_server_option"] is True
    )
    if not offers_ok:
        raise SystemExit("CARD_OFFER_UNCONFIRMED")

def main() -> int:
    card = load_card(Path(sys.argv[1]))
    assert_fresh(card, datetime.now(timezone.utc))
    assert_boundary(card)
    print("CARD_OK")
    return 0

if __name__ == "__main__":
    raise SystemExit(main())
Enter fullscreen mode Exit fullscreen mode

A sample card follows. Replace every field after a live check, and do not copy a campaign token count into the notes.

{
  "checked_at": "2026-10-08T09:00:00+00:00",
  "max_age_hours": 24,
  "server_boundary": "scratch-free-server",
  "free_model_access": true,
  "free_server_option": true,
  "notes": "Confirmed from current docs on the check date."
}
Enter fullscreen mode Exit fullscreen mode
python3 quota_gate.py quota_card.json
Enter fullscreen mode Exit fullscreen mode

Decision table the senior kept

Situation Gate result Next action
Card file missing Fail closed Read current docs, then write a card
Required field absent Fail closed Fill only observed fields
Timestamp older than max age Fail closed Repeat the live check
Boundary is production Fail closed Use a named scratch server
Offer flags are not true Fail closed Do not assume free access remains
Card fresh and boundary explicit CARD_OK Review the job with the card

Reviewing the job after the gate

A passing card does not approve the generated workflow by itself, because the boundary can still be wrong. The reviewer still checks that the job name matches the server boundary and that no secret is interpolated into the steps. A proposed job fragment, which was not executed in this exercise, should stay this small on purpose. Anything broader than a scratch command belongs in a separate review rather than in the first free-server trial.

# Proposed fragment only. Do not run until the quota card prints CARD_OK.
name: scratch-free-server-check
runs-on: scratch-free-server
steps:
  - name: show-boundary
    run: printf '%s\n' "$SERVER_BOUNDARY"
Enter fullscreen mode Exit fullscreen mode

The fragment intentionally has no model call, no deploy step, and no credential file in the first trial. Adding those later requires a new card and a new decision, not an edit hidden inside the same diff. The senior treated that separation as part of the kept decision rather than as optional polish for later. A generator that wants a richer job can propose it, but the gate still runs before that proposal is accepted.

Test plan for the exercise

Reviewers should run five local fixtures before they trust the gate during an ordinary repository review. A missing file should fail, and a card without a timestamp should fail with a field error. A timestamp older than the stated maximum age should fail, and a production boundary should fail as well. A fresh scratch-server card should print the success token and should not claim anything about model quality or capacity.

A short proposed test can encode those expectations without touching a network or a remote host. The test below is unexecuted example code for the exercise, and a team should run it locally before relying on the messages. Failure strings stay stable so a later workflow can match them without parsing free-form prose from the gate. Passing this file does not prove that a remote free server is healthy or that an allowance remains.

"""Proposed local checks. Unexecuted here; run only after a local review."""
from datetime import datetime, timedelta, timezone
from quota_gate import assert_fresh, assert_boundary

def expect_exit(fn, code):
    try:
        fn()
    except SystemExit as exc:
        if str(exc) != code:
            raise SystemExit("CHECK_MISMATCH")
    else:
        raise SystemExit("CHECK_MISSING")

def main():
    now = datetime.now(timezone.utc)
    stale = {
        "checked_at": (now - timedelta(hours=30)).isoformat(),
        "max_age_hours": 24,
    }
    expect_exit(lambda: assert_fresh(stale, now), "CARD_STALE")
    refused = {
        "server_boundary": "production",
        "free_model_access": True,
        "free_server_option": True,
    }
    expect_exit(lambda: assert_boundary(refused), "CARD_BOUNDARY_REFUSED")
    print("LOCAL_CHECKS_OK")

if __name__ == "__main__":
    main()
Enter fullscreen mode Exit fullscreen mode

Limitations and who should skip it

This gate does not prove that a free allowance remains available after the card was written. It does not select a model, estimate cost, authorize sensitive data, or replace human review of the generated workflow. A team that cannot spare a person to refresh the card should not adopt the approach for unattended generation. A team that needs a contractual quota, a named support window, or a production server should not treat a free option as that contract.

The pairing also refused to store campaign copy, including any round token figure, inside the generated job definition. Secrets, private repositories, and customer payloads stay out of the scratch job even when the card is fresh. The script can be wrong if the operator types a false confirmation, so the card belongs in the same review as the job. None of these checks measure latency, accuracy, or how many requests a free server will accept.

Where the review stops

The useful outcome is a small refusal that keeps generated CI on the laptop until the quota card is fresh. Teams that already separate a proposal from execution can place the script beside that existing review. Others can confirm the live docs still match the card before they accept a scratch job in the change. That confirmation is the only invitation this exercise offers, and it stays optional until the card is honest.

Top comments (0)