Approval and safety
The spend, secret, replay, and cleanup rules an unattended agent must follow.
Read and write actions are different
amics gpu options reads live capacity. It does not create a resource or choose
a GPU.
amics run may acquire paid compute. An agent must not infer approval for the
second action from a request for the first.
Approve one acquisition envelope
Before an unattended acquisition, establish:
| Bound | CLI option | What it controls |
|---|---|---|
| Maximum hourly rate | --max-hourly-price | Compute and its attached runtime disk |
| Command deadline | --max-runtime | How long the remote command may run |
| Warm reuse window | --keep-warm | How long compatible compute may remain after the command; billing can extend from each run that requests it |
| Host class | --host | any by default; includes datacenter and verified community-operated hosts |
--yes records that approval already exists. It does not create approval.
Community-operated hosts may have weaker physical and operational security.
Use --host datacenter when the source or environment values require
datacenter-only handling.
For auto-acquired compute, the maximum exposure is the hourly ceiling multiplied by the command deadline plus any warm reuse window. For example, an 8-hour warm window at $1.50/hour adds up to $12 of exposure even when no command is running.
Forward workload secrets explicitly
Amics does not read the agent login, Git credentials, SSH keys, cloud credentials, or model credentials from their standard locations. A credential inside the selected source snapshot still goes remote, as does an environment value explicitly named by the caller. Forward one value by local name only when the workload needs it:
export HF_TOKEN=...
amics run [OPTIONS] --env HF_TOKEN -- python train.pyDo not place secrets in command arguments. In particular, --api-key can leak
through process listings, shell history, and CI logs; prefer AMICS_API_KEY or
the saved login. The remote command can still leak a forwarded value if it
prints it. --env keeps the value out of arguments and run records, but does not
hide it from the remote host; use --host datacenter for sensitive credentials.
For a multi-run loop, request --keep-warm only on the priming run. Reuse its
compute_id on later runs without repeating --keep-warm, or obtain renewed
approval for a longer window.
Treat unknown as possibly executed
If Amics cannot prove the command outcome after an interruption, the run becomes
unknown. Inspect the accepted run:
amics runs get RUN_ID
amics runs logs RUN_ID --followDo not submit a replacement until a person or policy decides that replay is safe. This matters for commands with non-repeatable side effects.
Separate cleanup decisions
- Auto-acquired compute stops after the command unless a warm lease was approved.
--detachdoes not extend the command or warm deadline.- Compute passed with
--computeis user-supplied and is not stopped implicitly. amics runs cancel RUN_ID --stop-computeis appropriate only when stopping the resource is also intended.
Agent checklist
Before execution, an agent should be able to state the command, source root, GPU requirement, price ceiling, command deadline, warm lease, forwarded environment names, host class, output mode, and cleanup behavior.