InferCrane feature qualification matrix
This is the authoritative inventory for whole-product qualification.AUTOMATED_QUALIFIED means the strongest safe local boundary is green in repository CI. AWS_REAL_PASSED records the narrower real L40S boundary in AWS real-infrastructure evidence; SCALEWAY_BREZEL_REAL_PASSED records the bounded private-computer lifecycle in Scaleway Brezel evidence. Neither qualifies another provider, topology, model, or failure mode. REAL_INFRA_REQUIRED and MANUAL_REQUIRED remain explicit and are never satisfied by fixtures. Fixture evidence never qualifies real provider or GPU behavior.
| Feature | User-visible / operational behavior | Implementation | Existing evidence/tests | Qualification level and automated strategy | Manual requirement | Current status |
|---|---|---|---|---|---|---|
| CLI bootstrap/config contexts | init, context selection and missing-config remediation | cmd/infercrane, internal/config | command/config tests | Unit + local API CLI E2E | None expected | AUTOMATED_QUALIFIED |
| Doctor | Dependency, auth and configuration diagnostics | cmd/infercrane, internal/doctor, control API | doctor/API/CLI tests | Deterministic fixture + malformed config | Provider credential validity is external | AUTOMATED_QUALIFIED |
| Fleet inbox | Rank persisted endpoint/deployment attention without mutation | CLI over tenant-scoped fleet APIs | command/model tests + live local API | Severity/order/limits/unknown state/partial-read fail-closed/content exclusion | Fresh diagnosis and provider truth remain explicit follow-up | AUTOMATED_QUALIFIED |
| Semantic plan | Side-effect-free deployment diff | internal/planning, CLI/API | planning and command tests | Unit + stack assertion of zero mutation | Provider price display needs sourced data | AUTOMATED_QUALIFIED |
| Intent plan | Resolve bounded user text to one exact reviewed model and an editable architecture/configuration, or return explicit missing choices | intentplan, control API | intent planner and API tests | Strict 16 KiB JSON, deterministic recipe matching, no silent model substitution, exact deployment-comparable provider price ranking separated from connection readiness, sourced per-replica price disclosure, and explicit unmeasured performance/unknown capacity | Natural-language breadth is intentionally limited; arbitrary Hugging Face discovery, real capacity, and performance qualification remain separate | AUTOMATED_QUALIFIED (DETERMINISTIC CONTRACT) |
| Hermetic product demo | One command proves adoption through rejected-candidate cleanup | scripts/demo-product.sh, Docker stack, public CLI | acceptance safety + black-box execution | Isolated Compose project, fixture label, exact active-revision invariant, zero provisioning commands | Cannot qualify GPU, provider, model quality, or performance | AUTOMATED_QUALIFIED |
| Deployment apply/deploy | Durable provider-neutral lifecycle | internal/workflows, store, control API | workflow/store/stack/fault suites | PostgreSQL + fixture provider E2E/restart | Real provider lifecycle | AUTOMATED_QUALIFIED |
| Durable operations | Watch/resume/cancel after disconnect with a persisted current phase | internal/operations, store, CLI | operations, failure recovery, acceptance | State-machine + process restart + CLI disconnect, semantic checkpoint deduplication, exact current-step API/CLI rendering | Real in-flight provider call crossed create/restart/cancel/cleanup on the bounded RunPod GLM transfer; successful runtime completion remains tuple-specific | AUTOMATED_QUALIFIED / REAL_INFRA_REQUIRED |
| Provider ensure adoption | Lost-create-response and exactly-one intent | internal/provision, workflows, conformance | provider contracts/fault fixtures | Fault injection + repeated idempotency | Real provider adoption semantics | AUTOMATED_QUALIFIED |
| Readiness/model identity | Health plus intended served model | runtime, reconcile, workflows | runtime/reconcile/stack tests | Fake vLLM malformed/delayed/wrong identity | AWS vLLM/SGLang/custom OCI passed; other providers remain separate | AUTOMATED_QUALIFIED / AWS_REAL_PASSED |
| Safe delete/orphans | Route withdrawal, drain, idempotent cleanup, inventory | workflows/store/routes/acceptance | fault and acceptance fixtures | Restart/delete boundary + inventory equality | AWS worker and root-volume cleanup passed; other providers remain separate | AUTOMATED_QUALIFIED / AWS_REAL_PASSED |
| Immutable DeploymentSpec/revisions | Versioned strict spec, immutable candidate history, and exact accelerator type/count | spec, store, domain | spec/migration/store tests | Schema/property + topology persistence tests | None expected | AUTOMATED_QUALIFIED |
| Rollout/provision/promote/reject/rollback | Safe revision lifecycle | workflows/releaseguard/routes | rollout/guard/fault tests | E2E active/candidate and stale action rejection | Real generation-safe GPU rollout | AUTOMATED_QUALIFIED |
| Release Guard | Deterministic persisted accept/reject/monitor/rollback, with threshold or seeded paired-bootstrap quality comparison | releaseguard, store, API/CLI | unit/store/API/acceptance | Strong local candidate E2E; deterministic 10,000-resample bootstrap records seed/sample counts/interval; insufficient or overlapping evidence waits | Real performance/cost/quality evidence; InferCrane enforces signed external semantic evidence but does not itself judge answer quality | AUTOMATED_QUALIFIED |
| External task-quality evidence | Ingest aggregate evaluator results or bounded content-free paired score distributions, bind/sign/attach exact revision evidence | qualityevidence, evaluation CLI, control API | strict schema/content/tamper/key/API tests | Versioned distribution schema, sample-count equality, pairing digest, finite bounds, unknown fields, oversize/trailing JSON and attachment failures fail closed | Evaluator calibration, pairing validity, representative private datasets, key custody and real task quality remain customer evidence | AUTOMATED_QUALIFIED |
| Router supervision/generations | Instance-owned router lifecycle and safe generations | router, routes, workflows | router/routes/HA tests | Process crash/restart and active stream route swap | Real long-running vLLM stream | AUTOMATED_QUALIFIED |
| OpenAI Chat Completions | Buffered and streaming proxy | gateway, openaicompat | gateway/stack/SDK tests | Local fake runtime E2E success/failure/cancel | Real vLLM compatibility | AUTOMATED_QUALIFIED |
| Responses API | Faithful capability-gated proxy | gateway/runtime contract | gateway/protocol tests | Qualified fixture, malformed/upstream errors | Qualified real runtime | AUTOMATED_QUALIFIED |
| Embeddings | Faithful capability-gated proxy | gateway/runtime contract | gateway/protocol tests | Qualified fixture and dimensional payload preservation | Qualified real model/runtime | AUTOMATED_QUALIFIED |
| Completions | Legacy compatible proxy | gateway/runtime contract | gateway/protocol tests | Fixture contract + streaming | Qualified real runtime | AUTOMATED_QUALIFIED |
| Chat batch | Online batch proxy/capability | gateway/runtime contract | gateway/protocol tests | Fixture body/response/error preservation | Qualified real runtime | AUTOMATED_QUALIFIED |
| Tool calling/structured output | Protocol pass-through and capability claim | gateway/integration profiles | acceptance/contract tests | Local schema/tool payload preservation | AWS vLLM/Qwen path passed; every additional runtime/model pair remains separate | AWS_REAL_PASSED / REAL_INFRA_REQUIRED |
| Request IDs/tracing/retries | Stable request/trace identity and bounded retries | gateway/telemetry/admission | gateway tests | Failure sequence, cancel and no streaming retry | None expected | AUTOMATED_QUALIFIED |
| Telemetry/metrics | OTel GenAI identity, latency/token/error/cold metrics plus fresh revision-bound hardware evidence | gateway/metrics/store/control API/CLI | metrics/gateway/store/API/CLI tests | Local request E2E, bounded DCGM parsing, tenant/revision/idempotency/freshness, and content exclusion | Real DCGM/GPU field availability and complete fleet labeling | AUTOMATED_QUALIFIED |
| Stable logical models/environments/endpoints | Stable app identity independent of backend | store/routes/API/CLI | endpoint/store/API tests | Tenant/reference/digest/route E2E | None expected | AUTOMATED_QUALIFIED |
| Backend bindings/serving plans | Active/candidate/fallback plus exactly-two-provider active-active weighted plan compilation | store/routes/control API | endpoint/routes/PostgreSQL tests | Same explicit upstream model, distinct provider identities, deterministic weights, health decay/recovery hysteresis and generation pinning | Real cross-provider network, health propagation, streaming continuity and failover timing are unqualified | AUTOMATED_QUALIFIED (LOCAL CONTRACT) / REAL_INFRA_REQUIRED |
| Managed external endpoint bindings | Stage authenticated OpenRouter or generic OpenAI-compatible capacity behind a stable endpoint without browser-visible credentials | external/store/reconcile/control API/CLI | strict policy, tenant, budget, credential-reference, authenticated model-probe and route-compilation tests | PostgreSQL-backed hard reservation, fail-closed consent, candidate-only console flow, successful-probe caching | Real provider protocol, streaming and billing semantics remain target-specific | AUTOMATED_QUALIFIED |
| Managed Model API prepaid billing | Reserve customer wallet funds before supplier transmission, settle from returned token usage, and preserve unknown usage for operator reconciliation | managedbilling, gateway, store, control API, console | deterministic calculator, insufficient-funds/no-supplier-call, buffered/SSE settlement, PostgreSQL idempotency, append-only ledger, pending-usage listing, explicit settlement, verified-no-charge release, fixed-price Stripe Checkout, signed-webhook mode/amount/tenant verification, duplicate-event/session tests, immutable cost-basis/margin validation, and expired-rate no-transmission | Tenant routes cannot set retail prices; only signed paid events grant balance; browser redirects never grant credit; request content excluded; missing usage never becomes an invented charge or an automatic release; supplier cost basis stays private | Stripe sandbox journey, live payment collection, tax, refunds, automated supplier invoice reconciliation, overhead allocation, and real supplier usage semantics remain unqualified | AUTOMATED_QUALIFIED (LOCAL BILLING CONTRACT) / REAL_INFRA_REQUIRED |
| Managed Model API discovery catalog | Present a curated model shelf and one InferCrane service contract without exposing procurement routing | modelapicatalog, control API, console | strict versioned catalog validation, bounded filters/pagination, curated default shelf, customer-contract redaction tests, expired-rate downgrade, responsive browser journey | No supplier identity, internal offer ID, region, adapter, URL, credential, or upstream rate provenance crosses the customer API; missing or expired rate/context remains unknown | Managed availability, real pricing, performance, and production qualification require a separately operated supply catalog and real evidence | AUTOMATED_QUALIFIED (LOCAL CATALOG CONTRACT) / REAL_INFRA_REQUIRED |
| Managed Model API supply planning | Compile private offers into an immutable primary/fallback plan for one exact logical model | modelapisupply, modelapicatalog, control API | deterministic order-independent plans, content digest, exact-model/protocol/capability/region gates, freshness/health/rate/margin rejection, exact-tuple minimum-sample SLO evidence, supplier-diverse fallback, no-workload no-cost-ranking tests | Missing or stale evidence fails closed; no silent model substitution; a price rank is emitted only for a declared token shape; suppliers remain private | Real supplier availability, billing semantics, correlated failure domains, streaming failover, reconciliation and sustained gross margin remain unqualified | AUTOMATED_QUALIFIED (LOCAL PLANNING CONTRACT) / REAL_INFRA_REQUIRED |
| Managed Model API RunPod routing and COGS | Move one stable logical model gradually onto a private RunPod Serverless vLLM target while retaining upstream fallback and exact economics | modelapitarget, modelapirouting, modelapiqualification, modelapireconciliation, supplieradapter, store | immutable offer-bound target bindings, endpoint-config digest checks, strict buffered/SSE usage contracts, deterministic basis-point selection, future-request circuit fallback, exact-tuple measurement digest, integer micro-USD COGS/margin reconciliation, PostgreSQL migration and store tests | RunPod candidates cannot publish without one current exact binding; no retry occurs after supplier transmission; supplier rate identity is pinned before execution; ambiguous usage stays unsettled | A real RunPod endpoint, supplier credential, representative load, cold-start behavior, invoice reconciliation, and progressive production canary remain required | AUTOMATED_QUALIFIED (LOCAL CONTRACT) / REAL_INFRA_REQUIRED |
| External agent sandbox composition | Reference an externally owned sandbox and issue one expiring endpoint-scoped inference credential | integration catalog, store, control API, gateway | PostgreSQL identity/TTL/rotation/revocation, endpoint-scope enforcement, metadata content exclusion and no-external-mutation tests | InferCrane does not run commands, store files/content, claim isolation, or treat plain containers as a hostile-code boundary | Managed sandbox, gVisor, Kata and Kubernetes Agent Sandbox adapters each require real isolation, egress, cleanup, snapshot and credential-injection qualification | AUTOMATED_QUALIFIED (COMPOSITION CONTRACT) / REAL_INFRA_REQUIRED |
| InferCrane private computers on Brezel | Give one InferCrane tenant persistent isolated CPU workspaces through approved immutable environments | brezelsandbox, sandboxprovider, control API, metadata store, usage ledger, console proxy | Customer-ID ownership checks, cross-tenant rejection, HTTPS and owner-only token enforcement, durable workspace compensation, incremental command NDJSON, bounded file streaming, re-brokered preview leases, content-free receipts/events/usage, lifecycle idempotency, provider-identity redaction, no-internet default, plus bounded production lifecycle evidence | Private-tenant preview only; no shared-hosted, GPU, PTY/SSH, arbitrary OCI, controlled arbitrary egress, host-loss durability, or hardware-attestation claim; usage is not an invoice | Production creation, commands, files, preview, receipts, pause/resume persistence, model connector, usage and cleanup passed; host-loss recovery, capacity exhaustion, host restart, preview-expiry timing and adversarial isolation remain separate drills | SCALEWAY_BREZEL_REAL_PASSED (BOUNDED CPU LIFECYCLE) / REAL_INFRA_REQUIRED |
| Hosted control-plane deployment profile | Run the API, gateway, reconciler, and durable-operation worker on one always-on Fly.io CPU machine with external PostgreSQL behind a provider-neutral host contract | Docker image, deploy/fly/control-plane.toml, production config, portable hosting contract | TOML and portable-host invariant tests, production Compose/entrypoint checks, readiness and shutdown contract tests | No embedded secret, app name, shared replica identity, host volume, or scale-to-zero; Fly is not GPU supply; PostgreSQL remains the durable boundary; Render/ECS/Kubernetes are portability targets, not qualified deployments | Real Fly deployment, restart, region loss, database interruption, cost, external-client traffic shift, and two-machine rolling upgrade | CONFIGURATION_QUALIFIED / REAL_INFRA_REQUIRED |
| Reusable provider connections | Configure Baseten, Fireworks, OpenRouter, or an operator-supplied OpenAI-compatible Modal, RunPod Serverless API, Fly.io service, or generic endpoint once and bind it without exposing credentials or silently authorizing spend | store/control API/CLI | tenant/idempotency/adapter/credential-reference/binding compilation and authenticated discovery tests | Reference-only persistence, bounded bearer-authenticated /v1/models discovery, explicit per-binding consent and hard budgets, non-destructive delete; provider labels do not imply provisioning | Real provider credential, generation/streaming, availability, performance, and billing semantics | AUTOMATED_QUALIFIED (PROTOCOL CONTRACT) / REAL_INFRA_REQUIRED |
| Endpoint Release Guard | Compare and govern serving plans | store/releaseguard/API | endpoint guard tests | Deterministic persisted candidate comparison | Real cross-backend evidence | AUTOMATED_QUALIFIED |
| Import/adopt ownership | Observe-only then traffic-managed adoption | store/control API/CLI | adoption/API/route tests | Ownership enforcement and idempotent atomicity | Real existing endpoint | AUTOMATED_QUALIFIED |
| Bare-metal GPU discovery | Read-only concrete local NVIDIA inventory before endpoint adoption | nodediscovery, CLI | parser/command-boundary/CLI tests | No shell, five-second deadline, bounded output/count/fields, explicit unavailable state, no lifecycle transfer or compatibility claim | Real NVIDIA driver matrix; AMD/ROCm and remote hosts unavailable | AUTOMATED_QUALIFIED (LOCAL CONTRACT) / REAL_INFRA_REQUIRED |
| Request Inspector | Reconstruct request metadata without content | store/API/CLI | diagnostic/store/API tests | Tenant/content exclusion E2E | Provider-hidden timing | AUTOMATED_QUALIFIED |
| Deterministic Doctor/explain | Evidence-backed operational findings | doctor, explain CLI/store | doctor/CLI tests | Rule coverage + stale/missing evidence | None expected | AUTOMATED_QUALIFIED |
| Signed alerts | Policy evaluation and signed webhook retry | alert, store/API/CLI | alert/API tests | Local TLS webhook failure/retry/signature | Slack/PagerDuty adapters not implemented | AUTOMATED_QUALIFIED |
| Admission control and request deadlines | Concurrency/queue/size/token/priority/load shedding plus one endpoint-wide latency budget | admission, gateway, store, CLI/API/console | admission/gateway/store/API/CLI/browser tests | Concurrent local E2E, cancellation, queue expiry, bounded buffered retries, streaming expiry, PostgreSQL persistence, and cancelled-context evidence recording | Real-runtime cancellation and overload calibration remain exact-tuple evidence | AUTOMATED_QUALIFIED / REAL_INFRA_REQUIRED |
| Tenant request quota | Distributed bounded lease without DB data path | requestquota, store/gateway | quota/store tests | Concurrency/property/failure tests | Multi-host timing at scale | AUTOMATED_QUALIFIED |
| Async inference | Idempotent encrypted queued jobs, cancel, signed webhook | asyncinference, API/CLI | async/API tests | Worker/restart/deadline/retry/cancel E2E | Real long-running inference | AUTOMATED_QUALIFIED |
| Autoscaling | Min/max, SLO-aware replica target from persisted request attainment and exact-tuple one-replica benchmark goodput, safe scale down | autoscale, workflows/store | autoscale/workflow/store/acceptance | Minimum 20 samples, exact immutable model/runtime/version/args/provider/region/GPU tuple, queue fallback with capacity evidence absent, hysteresis/cooldown/router fence and persisted snapshots | Real GPU provider scaling and benchmark calibration | AUTOMATED_QUALIFIED (DECISION CONTRACT) / REAL_INFRA_REQUIRED |
| External governed fallback | Explicit privacy plus hard request/cost budget | external, store/gateway/CLI | external/store/gateway tests | Concurrent budget reservation and fail closed | Real external provider | AUTOMATED_QUALIFIED |
| Burst Guard | Fresh sustained health/queue/cost bounded overflow | burstguard, store/API/CLI | burst unit/API contracts | State transitions, stale evidence and budget boundary | Real overflow/provider cost | AUTOMATED_QUALIFIED |
| Provider-native serverless | Durable endpoint, zero/warm/cold/cancel/delete | provision/workflows/gateway | serverless fixture/fault acceptance | Lost response, cancellation, orphan fixture | RunPod Serverless real cycle | REAL_INFRA_REQUIRED |
| Cold-start intelligence | Grounded timing boundaries, exact-tuple per-stage history, and explanations | gateway/store/metrics/planning | cold-start/store/planning/explain tests | Provider markers only; per-stage p50 after 3 successes and p95 after 20 matching immutable model/runtime/version/args/provider/region/GPU observations; absent stages remain unknown | Real provider marker completeness and hidden stages | AUTOMATED_QUALIFIED (EVIDENCE CONTRACT) / REAL_INFRA_REQUIRED |
| ModelArtifact/HF identity | Resolve public, private, or gated mutable HF ref to an immutable artifact | artifact, store | artifact unit/HTTP fixture/store/workflow | Tenant-scoped secret reference, token passed only through child environment, immutable revision, cache metadata validation | Real gated HF/Xet transfer and provider-native runtime secret delivery | AUTOMATED_QUALIFIED |
| Artifact cache observations/prefetch | Expiring evidence, delegated idempotent intent, and explicit bounded provider preparation workflows | artifactcache, store/API, guarded scripts | artifactcache/provider/API and hermetic script safety tests | PostgreSQL tenant/idempotency/expiry, stable lost-response adoption, exact-model AWS snapshot, GCP zonal disk, Kubernetes PVC, RunPod identity-named network-volume attachment, resumable RunPod population plan with hard cost/watchdog/cleanup gates | Real provider attachment, byte integrity, filesystem behavior, cache-hit timing, and node-local/provider-native caches remain external | AUTOMATED_QUALIFIED (CONTRACT) / REAL_INFRA_REQUIRED |
| AIPerf benchmark/history | Explicit reproducible measurement | benchmark, store/API/CLI | benchmark/API/store tests | Fake AIPerf process + exact args/results/failure | AWS L40S qualification samples passed; representative performance campaigns remain separate | AWS_REAL_PASSED / REAL_INFRA_REQUIRED |
| Recipes | Immutable content-addressed verified serving recipe | recipe, store/API/CLI | recipe/store/API tests | Evidence matching/digest/idempotency/tenant | Community/public registry not implemented | AUTOMATED_QUALIFIED |
| Inference Lab | Compare measured candidate evidence | lab, store/API/CLI | lab/store/API tests | Measured-only/no hidden provisioning/no invented cost | Real candidate catalog evidence | AUTOMATED_QUALIFIED |
| Optimization proposals | Generate bounded immutable catalog or modeled candidates without mutation | optimizer, pinned AIConfigurator adapter, integration/recipe catalogs, CLI | optimizer/CLI tests plus real upstream package contract | Multi-model catalog, deterministic inputs, typed evidence state, immutable custom-runtime profiles, exact GPU type/count, credential scrubbing, bounded process output, explicit fallback, topology/mutation-owner safety, strict loadable specs, no modeled-as-measured claim | Estimator calibration and real-hardware candidate qualification | AUTOMATED_QUALIFIED / REAL_INFRA_REQUIRED |
| Optimization campaign coordination | Persist, inspect, approve with an expiring hard cost cap, advance proof boundaries durably, rank measured exact-workload candidates, cancel and clean candidates, and require explicit durable activation or guarded promotion | optimizationcampaign, Lab, store, control API, CLI | state-machine/coordinator/composite-driver/ranker/operation/store/API/CLI tests plus black-box modules journey | Exact sourced price authority, PostgreSQL durability, explicit new-endpoint versus evolve-endpoint intent, no fabricated guard baseline, mandatory guard for evolution, direct-revision AIPerf, idempotency conflict, stale transition fencing, all-candidate measurement barrier, proposal-order independence, workload/cost/SLO fail-closed ranking, distinct benchmark/quality/Lab/guard evidence, lost-response adoption, approval expiry-to-cleanup, cancellation fencing, tenant isolation, transactional stable-alias publication, route-generation wait, explicit activation, and zero implicit promotion | Real provider/GPU execution, runtime performance, and cleanup remain separate qualification | AUTOMATED_QUALIFIED (LOCAL CONTROL PLANE) / REAL_INFRA_REQUIRED |
| Optimization capability registry | Compile only exact qualified model/runtime/version/precision/GPU mechanisms and fail closed on unknown or conflicting combinations | optimizationcapability, servingcontract, runtime profiles, optimizer | registry/compiler/deferred-translation and multi-model tests | Exact tuple matching and conflict rejection; LMCache and Dynamo/NIXL prefill-decode are registered as Deferred for argument translation but compilation always fails closed | LMCache and NIXL execution, transport, routing, failure and GPU performance require mechanism-specific qualification; no support claim | AUTOMATED_QUALIFIED (CURRENT TUPLES; DEFERRED REGISTRATION) / REAL_INFRA_REQUIRED |
| Accelerator Lab | Profile exact target, plan bounded kernel opportunities, optionally generate profile-bound source, build in Brezel, qualify on target hardware, and stop before promotion | acceleratorlab, kernelplanner, brezelexecutor, operations/control API | engine/client/catalog/workflow/Brezel/config/API tests | Worker-declared capability catalog; immutable model/runtime/workload/hardware/topology; 24-hour authority and spend cap; same-origin content-addressed artifacts; existing-first source search; generated-source profile binding; hidden/adversarial shapes; sanitizer, quality, serving replay, end-to-end, memory and cost gates; no implicit promotion | Deploy the baked optimization runner and exact NVIDIA/AMD/TPU/Neuron worker pools; collect per-tuple profiler, multimodal quality, topology and serving evidence | AUTOMATED_QUALIFIED (ORCHESTRATION AND FAIL-CLOSED GATES) / REAL_INFRA_REQUIRED |
| Optimized artifact provenance | Plan and attest immutable quantized checkpoints, speculators, and TensorRT engines through external digest-pinned builders | optimizedartifact, store, control API, CLI | artifact state/store/API/CLI tests | Immutable base/tool/config/calibration/hardware/license identity, duplicate/tamper/failure/cross-tenant checks, exact deployment/revision/base-model binding, mismatched-model rejection, and mandatory signed quality evidence | Real LLM Compressor, ModelOpt, Speculators, and TensorRT builds plus GPU qualification | AUTOMATED_QUALIFIED (PROVENANCE) / REAL_INFRA_REQUIRED |
| Production telemetry import and Inference Replay | Import bounded content-free OTel/Datadog/Baseten/Fireworks request shapes, then capture immutable replay history | replay, gateway/store/API/CLI | import/replay/gateway/store/API tests | Strict unknown-field rejection, deterministic retry identity, content exclusion, digest/window, tenant-scoped list + opt-in CLI/console | Source-specific managed pull adapters, real workload/GPU approximation, and content-bearing shadow traffic | AUTOMATED_QUALIFIED (CONTENT-FREE CONTRACT) / REAL_INFRA_REQUIRED |
| Capacity Intelligence | Tenant-scoped observed success/failure/latency plus deterministic cache-aware placement | store/workflows/API/CLI, capacity | workflow/store/capacity contracts | PostgreSQL aggregation partitioned by exact GPU type/count, sparse samples, percentiles, expired-cache rejection, readiness/reliability/cost objectives, readiness SLO, and inventory-order independence | Real provider distributions and automatic multi-provider placement remain external | AUTOMATED_QUALIFIED (DECISION CONTRACT) / REAL_INFRA_REQUIRED |
| SLO/recommendations | Qualified deterministic serving recommendation | decision, store/API/CLI | decision/store/API tests | Missing/stale/cost/qualification fail closed | Real evidence quality | AUTOMATED_QUALIFIED |
| FinOps | Sourced dated hourly cost, no invented savings | finops, OpenCost parser, store/API/CLI | finops/store/API/CLI tests | Exact allocation selection, currency/source/window/expiry, active-revision binding, retry conflicts, persistence | Real OpenCost deployment and invoice reconciliation | AUTOMATED_QUALIFIED |
| Advisory Autopilot | Immutable recommendation plan and human approval, no mutation | store/API/CLI | API/contract tests | Idempotency/tenant/state/audit/no side effects | Execute candidate manually | AUTOMATED_QUALIFIED |
| Inference Passport | Signed canonical offline release evidence | passport, store/API/CLI | passport/store/API tests | Sign/verify/tamper/byte preservation/tenant | Organizational key custody | AUTOMATED_QUALIFIED |
| Context Passport/session affinity | Durable logical identity, reliability-first hints, no KV promise | contextpassport, routes/store/API/CLI | directory/routes tests | Persistence/expiry/tenant/route fallback E2E | Multi-instance snapshot propagation and real worker loss | AUTOMATED_QUALIFIED |
| Request survival capability | Delegated qualified backend claim | integration contract | integration test | Invalid/unknown/unqualified matrix | Real Dynamo/qualified backend migration | REAL_INFRA_REQUIRED |
| Existing-target provider | Register and route customer-managed endpoint | store/routes/API/CLI | target/store/stack tests | Local fake OpenAI endpoint E2E | Customer network endpoint | AUTOMATED_QUALIFIED |
| RunPod elastic adapter | Elastic GPU lifecycle/inventory | provision/workflows profiles | fixtures/contracts | Deterministic provider HTTP fixture | Real RunPod GPU | REAL_INFRA_REQUIRED |
| RunPod native OCI Pods | Immutable image/argv/GPU lifecycle without SSH for built-in vLLM/SGLang and custom OCI workloads | provision/workflows profiles | native REST fixture/contracts + bounded GLM evidence + Qwen evidence | Lost-response adoption, conflict, redaction, exact-region and identity-bound network-volume attachment, persistent Hub/materialized-model paths, delete fixture; exact Qwen3-8B/vLLM 0.22.1/L40S durable deploy, buffered/streaming requests, c1/c8/c32 benchmark, guard rejection, restart-delete, and zero inventory passed | Every other image-model-runtime-GPU-region tuple; Qwen3.8 TP2 B200 remained nondeterministic and is unqualified | RUNPOD_REAL_PASSED (EXACT BASELINE TUPLE) / REAL_INFRA_REQUIRED |
| RunPod serverless adapter | Provider endpoint lifecycle | provision/workflows profiles | fixtures/fault proxy | Deterministic API fault fixture | Real RunPod Serverless | REAL_INFRA_REQUIRED |
| AWS EC2/ASG/EKS/SageMaker/Bedrock profiles | BYOC and imported/managed product boundaries | provision/integration profiles | contract/manifest tests | CLI/API fixture and translation conformance | AWS account/GPU/private network | REAL_INFRA_REQUIRED |
| GCP Compute/MIG/GKE/Vertex profiles | BYOC and managed product boundaries | provision/integration profiles | contract/manifest tests | CLI/API fixture, immutable dependency preflight, Private Google Access enforcement, observed regional/global GPU quota fail-fast with unknown preservation, exact-model zonal Persistent Disk verification and read-only retained attachment, translation conformance, and leak-inventory safety | GCP account/GPU/PSC, stock and real cache mount | REAL_INFRA_REQUIRED |
| CoreWeave CKS profile | Kubernetes-first provider profile | integration/Kubernetes | contract/manifest tests | Manifest/provider contract | CoreWeave account/GPU | REAL_INFRA_REQUIRED |
| SkyPilot boundary | Infrastructure provisioning reuse contract | integration/provision docs | profile/contract tests | Ensure core remains adapter neutral | Real SkyPilot/provider execution | REAL_INFRA_REQUIRED |
| vLLM runtime | Default inference runtime and router | runtime/integration/router | runtime fixture/stack + RunPod Qwen evidence | Local fake runtime protocol/health/drain; exact RunPod Qwen3-8B/vLLM 0.22.1/L40S buffered, streaming, benchmark and cleanup passed | Other models, providers, GPUs and representative repeated performance campaigns require fresh qualification | RUNPOD_REAL_PASSED (EXACT BASELINE TUPLE) / REAL_INFRA_REQUIRED |
| SGLang runtime | Second qualified runtime profile | runtime/integration | profile/conformance tests | Hermetic runtime contract | AWS L40S SGLang 0.5.12 passed; smaller runtime image and other providers remain separate | AWS_REAL_PASSED / REAL_INFRA_REQUIRED |
| Custom OCI runtime | Digest-pinned portable workload contract | runtime/spec/provision | conformance/spec/provider tests | Complete executable argv, entrypoint override, validation/translation/probes/cancel/drain, and exact GPU count on AWS/GCP/Kubernetes/SkyPilot compilers | AWS L40S portable vLLM workload passed historically; every other image/model/provider/topology tuple needs real qualification | AWS_REAL_PASSED / REAL_INFRA_REQUIRED |
| Provider/runtime conformance kit | Idempotency, adoption, inventory, capability evidence | conformance, integration | contract qualifier | Run all deterministic adapters repeatedly | Real provider qualification tier | AUTOMATED_QUALIFIED |
| Kubernetes provider | Namespace/SSA/RBAC/restart/delete lifecycle | provision/manifests/tools | manifest + Kind suites | Real Kind API, restart/lost response/zero resources, operator pre-pull contract with fail-closed imagePullPolicy: Never, exact-model PVC | GPU scheduling and node-level pre-pull timing | AUTOMATED_QUALIFIED |
| KServe integration | Standard CRD-gated single-owner inference service | provision/manifests | manifest/Kind tests | Missing/present CRD and field ownership | Real KServe GPU runtime | AUTOMATED_QUALIFIED |
| NVIDIA Dynamo DGD adapter | One immutable parent graph for the aggregated baseline; disaggregated NIXL intent is Deferred and fails before mutation | servingcontract/provision/workflows/spec | contract, fixture, API, persistence, strict DGD-subset Kind and fail-closed translation tests | Lost apply response, changed intent, stale/failed status, exact ownership, server-side dry-run/apply/delete-to-zero for aggregated mode | Real operator/GPU; NIXL transport, disaggregated routing, cache allocation, streaming rollout and performance are unqualified | AUTOMATED_QUALIFIED (AGGREGATED ONLY) / REAL_INFRA_REQUIRED |
| PostgreSQL persistence/migrations | Source of truth, upgrade safety, concurrency/checksum | store, 51 migrations | store/migration/restore tests | Every-prefix, concurrent startup, downgrade/checksum | Customer managed HA database | AUTOMATED_QUALIFIED |
| HA/fencing/mixed-version | Stateless API, leased workers, stale writer rejection | store/operations/serve | HA/failure/restore suites | Multi-process Docker crash/reclaim/protocol overlap | Multi-host customer topology | AUTOMATED_QUALIFIED |
| Backup/restore | Guarded backup, ledger preservation, reconcile startup | scripts/store/compose | safety + Docker drill | Corrupt/mismatch/restore/reconcile | Customer backup system/RTO | AUTOMATED_QUALIFIED |
| TLS/mTLS/private identity | Production secure transport and rotation checks | config/safehttp/serve | config/production tests | Local TLS/mTLS invalid/rotation | Customer CA/network/IAM | AUTOMATED_QUALIFIED |
| Authentication/RBAC/scopes | Principal auth, hosted Clerk organization identity, roles, scopes, rotation/revocation | authn/authz/store/API/console | auth/API/store/browser tests | Boundary matrix, tenant mapping, deny-by-default entitlement, and concurrent revoke | Production SAML/OIDC domain verification, SCIM, and IdP lifecycle require hosted qualification | AUTOMATED_QUALIFIED / MANUAL_HOSTED |
| Tenant isolation/audit | Every resource scoped and mutation audited | store/API/gateway | store/API security tests | Cross-tenant route/API/property tests | None expected | AUTOMATED_QUALIFIED |
| Secret references/redaction | Reference-only secrets and no leakage | secrets/store/API/logging | secret/security tests | Canary secret through errors/logs/reports | External secret manager access | AUTOMATED_QUALIFIED |
| Embedded terminal UI | Read/operate workspace, responsive navigation | CLI UI | UI snapshot/interaction tests | PTY sizes, empty/error/action handoff | Human visual/keyboard review | MANUAL_REQUIRED |
| Browser console | Endpoint-first stable identity, workload, operation, evidence, API-key and team UI | separate web app/control API | unit + contract fixture tests | Production build + protected auth + responsive Playwright + axe + visual baselines + disposable real Go/PostgreSQL control-plane browser qualification | Hosted Clerk/private-preview and final hosted visual review | AUTOMATED_QUALIFIED / MANUAL_HOSTED |
| OpenAPI route contract | Server/API schema parity | apicontract/codegen | route drift tests | Generate/check every route/schema | None expected | AUTOMATED_QUALIFIED |
| Python SDK | Generated API plus streaming client/package | sdk/python | unittest/wheel/stack | Package and local stack E2E | Public-beta PyPI package; stable publication remains release-gated | AUTOMATED_QUALIFIED |
| TypeScript SDK | Generated API plus streaming client/package | sdk/typescript | node tests/npm pack/stack | Package and local stack E2E | Public-beta npm package; stable publication remains release-gated | AUTOMATED_QUALIFIED |
| Terraform provider | Deployment/SLO CRUD/import/adoption | integrations/terraform | provider tests/automation | Protocol tests against deterministic API | Public-beta GitHub binaries; Terraform Registry publication deferred | AUTOMATED_QUALIFIED |
| GitHub delivery integration | CI/release plan and evidence artifact handling | .github/workflows, scripts | repository/release checks | Static workflow validation + local scripts | Hosted Actions run | MANUAL_REQUIRED |
| Documentation/Mintlify | Accurate navigation, links, API and commands | docs | docs check/context drift | Mintlify build/link/claim audit | Hosted Mintlify rendering | MANUAL_REQUIRED |
| Release packaging | Multi-arch archives/checksums/SBOM/native/Homebrew | release scripts/GoReleaser | qualify/release verification | Exact version build and native smoke | Public-beta GitHub/Homebrew distribution; stable publication remains release-gated | AUTOMATED_QUALIFIED |
| Docker images/Compose | Provider-neutral control plane and opt-in overlays | Dockerfiles/compose | container/stack/production tests | Build/start/health/stop and config matrix | GHCR candidate publication deferred until the release vulnerability gate passes; exact runtime/provider qualification remains separate | AUTOMATED_QUALIFIED |
| Acceptance orchestration | Approval lock, run identity, resume, cleanup, report | acceptance scripts | safety tests/local qualification | Shell fault/safety and dry local workflow | Paid suites with user | MANUAL_REQUIRED |