Capture that refusing at capacity is the default, not absolute: an operator may opt into valet over-capacity (customer hands over keys, operator stacks the car into custody). Manned-only, new custody/session shape. Deferred; not built into the entry flow. Made capacity-occupancy's FULL gate a soft policy knob.
2.3 KiB
type, tags, sources, updated, status
| type | tags | sources | updated | status | ||||
|---|---|---|---|---|---|---|---|---|
| concept |
|
2026-06-15 | open |
Capacity & Occupancy
How many vehicles are inside, how many spaces remain, and what happens when the lot is full.
Occupancy is a projection (like everything else)
occupancy = count(open [[parking-session|sessions]]) — an entry with no matching exit. It is a
fold over the signed append-only-event-chain, never a hand-maintained counter (a counter is
editable and drifts; the chain is the truth). Spaces-free = capacity − occupancy.
capacityis admin-set per site (and per zone/level if the lot has sections — model azoneon capacity + on the entry so multi-level is a later addition, not a rewrite).- Permit concurrency (
maxConcurrent, see permit) is the same kind of fold, scoped to one permit's open sessions.
Full → refuse entry + FULL sign
- When
occupancy ≥ capacity, the entry flow refuses (novehicle_entry, no barrier open) and can drive a "FULL" sign (a relay/output, via the device adapter layer). - Safety/policy nuance: "full" blocks entry only — exit always works (fail-state-safety: exit fails open; never trap a vehicle). Permit holders may be allowed in past a "transient full" threshold (reserve spaces for subscribers) — an optional policy knob.
- Counting drift is real: tailgating (two cars, one entry) and missed reads make the live count diverge from physical reality. The count is the system's occupancy; periodic ground-truth (a loop count, or the opencv-anpr-service count) reconciles it — surfaced as an anomaly, not silently corrected.
"Full" is a soft, operator-configurable policy
Refusing at capacity is the default, not an absolute. An operator may opt into valet-overcapacity — accept the car into operator custody (keys handed over, stacked beyond the marked count) instead of refusing. So the FULL gate is a policy knob (refuse vs. valet-accept), set by the operator per site. Valet is a manned-mode feature with its own custody/session shape — see valet-overcapacity (deferred).
Open
- Zone/level granularity at launch vs. single capacity number.
- Reserve-for-permits threshold.
- The valet over-capacity mode + custody model (valet-overcapacity).