Compare while holding the budget constant
The first experiment had two shared slots. The second retains two total slots but assigns one to batch and one to critical work. It holds the batch job on its Event and lets critical work finish. The comparison therefore does not attribute its result to a hidden capacity increase. The script observes batch still active when confirming critical completion. This demonstrates local admission; all workers still share one process and machine. The design reserves neither CPU nor memory nor actual database connections. Use the observation to formulate an isolation hypothesis that can subsequently be tested on the target system.
Explain the cost of a reservation
After critical work finishes, its slot is idle. A second batch job is still rejected because the batch pool is full and pools do not lend slots. That result is intentional: the reservation preserves capacity for the next critical request. It also means total utilization may be lower than with a shared pool. In the project decision, relate this cost to availability objectives and the workload distribution. If the team proposes temporary borrowing, it must define reservation recovery and the behavior of already admitted jobs. This lab implements no preemption, borrowing or priority guarantee.
Follow the shared dependency
A third case represents separate front-end admissions that converge on one shared downstream slot. Batch acquires its own slot and the downstream slot. Critical work acquires its front-end reservation but cannot acquire the next resource. All three counters are local; this case opens no database connection. Its purpose is to expose the boundary that remains shared. On an operational map, follow connections, locks, queues and call limits through to the dependent service. Approving only front-end pools leaves the behavior of layers that can reconnect the paths unproven.
Separate concurrency, rate and queue
The script executes twelve sequential jobs in a one-slot pool. All enter and finish; peak remains one and admitted reaches twelve. It measures no requests per second and imposes no time-based quota. This result prevents interpreting a concurrency limit as a rate quota. There is also no waiting queue on the rejection path: a failed attempt creates no worker. When designing a real solution, specify simultaneous work, arrivals per interval and maximum waiting requests separately. Include remaining useful time before consuming capacity with a request that has already lost its value to the consumer.
Plan cancellation without inventing it
Workers in this script end only when the Event is released, the injected error occurs or the experiment guard expires. They receive no caller cancellation signal. A cooperative solution would need a contract defining who signals, where workers check and which actions may already have happened. Cancellation acknowledgement must distinguish receipt of the request from work actually stopping. If durable effects exist, reconciliation and operation identity remain relevant. Do not extrapolate a timed join into a claim that a particular library or database cancels requests. Add tests of that library and observations at the destination before making such a claim.
Define evidence for handover
For a fictional APS handover, provide a pool diagram, dependency limits, rejection semantics and recovery procedure. Show both critical queries during batch saturation and recovery after removing load. Compare total capacity, request mix and success criteria across versions. The local report includes twelve groups, a script hash and terminated-thread counts; it does not replace metrics from a representative application. Add owners, alerts, reversal criteria and joint development and operations review. Approval should state exactly what was observed and leave unperformed load, security and human review work explicitly outstanding.
python3 content/labs/micro-capacity/run.py --output /tmp/dr-capacity-new-run.json
# Use a new output path for each run; existing reports are not overwritten.A reserved slot lets the critical query complete while batch work remains held; a shared dependency can block both again.
Common pitfalls
Treating two semaphores as CPU isolation; lending reservations without a contract; confusing concurrency with rate; declaring cancellation without confirmation.
Related topics: Capacity planning · Availability and dependencies
A reservation protects only the resource it controls. Acceptance must follow the whole path and show recovery, cost and consumer effects.
Reference: Bulkhead pattern · Microservice architecture patterns and scoped platform examples; primary guidance consulted 2026-09-30