redis.call('TIME') as the fleet clock.
Claims, leases, token spending, fairness charges, concurrency, and quarantine decisions are
committed atomically.
Capability boundary
Redis supports the core runtime and inspection contracts but does not pretend to provide SQL application transactions. Transaction-dependent APIs such asstep_once decline with
an explicit capability error.
Operational notes
- Use a distinct key prefix for each headgate instance.
- Test isolation uses
SCANplus boundedDELbatches—neverKEYSorFLUSHDB. - Store time avoids worker clock skew in refill and lease decisions.