vastai-reference-architecture

v2026.09.24

Design a governed Vast.ai GPU control plane that separates planning, paid mutation, execution, recovery, evidence, and teardown. Use when reviewing a production architecture spanning instances or Serverless. Trigger with: "design a Vast.ai architecture", "govern GPU workload lifecycles", "review a Vast.ai platform".

GitHub
Install command
npx skhub add jeremylongshore/vastai-reference-architecture
Markdown
SKILL.md

Governed Vast.ai GPU Workload Architecture

Overview

Center the architecture on an immutable run or release manifest and a lifecycle ledger. Search and planning are read-only; paid resource creation crosses an approval boundary; execution writes recoverable state externally; teardown closes both cost and evidence.

Prerequisites

  • Batch, training, interactive, or Serverless workload inventory with SLOs
  • Data, model, image, credential, region, reliability, and spend policies
  • Owners for approval, execution, recovery, billing, security, and platform incidents

Instructions

Step 1: Define the immutable intent

Create a signed or versioned manifest containing workload bytes, image/template/model identity, GPU policy, data/checkpoint routes, SLOs, budget, and expiry.

Step 2: Separate planner and mutator

Let a read-scoped planner evaluate offers or Serverless profiles. Require explicit approval before a narrowly scoped mutator creates, updates, transfers credit, or destroys.

Step 3: Choose the executor

Use an instance lifecycle for bounded jobs or dedicated services; use Serverless endpoint/workergroup control for managed inference scaling and rolling updates.

Step 4: Externalize durable state

Keep datasets, checkpoints, artifacts, event ledgers, and evidence outside disposable root disks with checksums and recovery objectives.

Step 5: Observe and reconcile

Combine provider states, signed notifications, bounded polling, workload SLOs, balance, charges, and resource inventory; reconcile events against periodic reads.

Step 6: Close every lifecycle

Accept output, copy evidence, destroy disposable resources, revoke temporary access, reconcile charges, and leave an auditable handoff for retained resources.

Authentication

Use native Teams roles and distinct scoped keys for planning, mutation, monitoring, and administration. Workload storage and registry credentials must never inherit control-plane authority.

Tool Discipline

Use Read and Grep to inspect manifests, configuration, provider output, and existing tests before proposing a mutation. Use Write or Edit only for the approved plan, implementation, test, or redacted receipt; do not create, update, destroy, or fund Vast.ai resources without explicit operator approval.

Output

  • Trust-boundary and component decision record
  • Immutable manifest, lifecycle ledger, recovery, and observability contracts
  • Threat, failure, cost, rollback, and teardown evidence plan

Return workload classes, chosen executors, authority boundaries, immutable artifacts, recovery targets, SLOs, budgets, event reconciliation, and lifecycle owners.

Examples

A planner selects verified offers but cannot rent; an approved mutator creates from a signed run manifest; the training executor checkpoints externally; a signed event plus reconciliation loop detects failure; a finalizer destroys the instance and closes the charge ledger.

Error Handling

FailureResponse
One service can plan, fund, mutate, and erase evidenceSplit authority and add independent approval and audit.
Durable state exists only on an instanceMove it to an external verified store before production.
Event stream is treated as completeAdd periodic resource reconciliation and idempotent processing.
Resource has no expiry or cleanup ownerReject the architecture until the lifecycle can close.

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/vastai-reference-architecture

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8