diff --git a/11-Features.md b/11-Features.md index b57e438..fcfe1c8 100644 --- a/11-Features.md +++ b/11-Features.md @@ -5095,8 +5095,32 @@ fleet use this id at all", and `enabled` answers "may it use it right now". Remo instead of turning it off makes every profile naming that model fail validation, and the whole reload is refused. -`fleet_profiles` and `GET /profiles` report the off set, so a lead can see the gate state without -reading the config file. +### Seeing the gate's own state + +`fleet_profiles` and `GET /profiles` report the gate, so a lead can see it without reading the +config file. Two fields, and you need both: + +| field | meaning | +|---|---| +| `modelGateArmed` | is there a `models:` block at all. Always present, `true` or `false`. | +| `modelsOff` | which model ids are off right now. Absent when nothing is off. | + +The off set alone cannot answer the question you usually have. An empty off set means one of two +very different things — there is no `models:` block on this host, so nothing is gated and nothing +can be; or there is a block, it is working, and right now nothing is turned off. `modelGateArmed` +separates them, which is why it is reported even when it is `false`. + +The daemon logs the same three states at startup, from the same read: + +``` +model gate (fleetd #422): not configured (no models: block — nothing is gated, and nothing can be) +model gate (fleetd #422): armed (models: block present; 0 models currently turned off) +model gate (fleetd #422): armed (2 model(s) turned off: [openai/gpt-5.6-terra, sol/x]) +``` + +Both the log line and `modelGateArmed` come from one `PeerLauncher.modelGateState()` call, which is +the same accessor the spawn gate itself reads. So the status can never claim more or less than the +gate enforces, and a reload landing between two reads cannot make them disagree. **The knob.** `models.allow[].enabled`. Absent means on.