skills/ito-training/SKILL.md
ito-training is the canonical ECC skill for training on Itô compute. ECC
never runs a trainer, scheduler, or data pipeline of its own; it never books,
reserves, or spends. This skill chains off a completed booking from
ito-compute.
Managed training is unavailable today. The ECC bridge exposes only login,
logout, auth, find, status, and explicitly gated evals. It has no
train verb, and the canonical CLI's run verb and desk training-run
backend remain scaffolds. The locally enforceable guarantee is that ECC rejects
train before resolving or spawning the credential-bearing canonical client.
Therefore stop before authentication or any command invocation. Report the missing capability and return to the originating agent. Never substitute a local trainer, SSH helper, browser workflow, or purchase endpoint.
When training is implemented, its first gate is a server-verified completed booking. Harness memory, an RFQ, a quote, node IPs, or SSH access are not proof of entitlement. The backend must return fresh training eligibility bound to the authenticated account, booking, GPU topology, region, fabric, and term. Expired, revoked, mismatched, incomplete, or already-released bookings fail closed before confirmation.
The intended command name is train. The future handoff must be equivalent to:
ecc ito train \
--booking <server-verified-booking-id> \
--manifest <absolute-reviewed-json-file> \
--confirmation-ref <opaque-non-authorizing-reference> \
--idempotency-key <stable-retry-key> \
--json
The reviewed manifest must identify the model size and revision, data references with decontamination provenance, training target, post-training recipe, budget ceiling in USD, checkpoint policy, and maximum incremental cost. No raw API key, SSH key, node password, bearer token, or dataset credential belongs in arguments, manifests, logs, MCP results, or chat.
The client must canonicalize the manifest path, reject symlinks, open a regular file without following links, require appropriate ownership and restrictive permissions, enforce a bounded size, and hash bytes from the opened descriptor. That digest must exactly equal the digest bound into confirmation before any workload mutation. A path swap, digest mismatch, oversized file, or mutable unsafe file fails closed.
The canonical API—not ECC—must own workload creation and return structured JSON
with ok, live_api_contacted, notice, and either data or error.
Training data must include stable booking, run, manifest, and idempotency IDs
plus a state enum. Errors must include a stable code and safe message without
secrets.
Before workload creation, require all of the following:
Authentication is identity, not workload authority. A login, API key, quote, or completed booking never substitutes for the training confirmation. Inspection and plan generation must not create a workload. Cancel and cleanup are separate mutations with their own scoped confirmation and idempotency boundaries.
The production surface is incomplete until the same canonical client exposes tenant-scoped status, logs, metrics, checkpoint listing, cancel, and cleanup. Every operation needs bounded connect and overall timeouts, revocation-aware errors, and structured output. After an ambiguous transport failure, query status by the idempotency key before retrying; never create a second run merely because the first response was lost. A revoked credential stops polling and returns control to the originating agent without starting login automatically.
Report stage gates honestly; never override a failed eval gate. Cleanup must be observable and must not release or modify the underlying booking unless that separate economic action was explicitly authorized.
These stages describe the future backend (Layer 0.3), not code that exists in ECC:
The backend emits desk telemetry (goodput, interruption rate, checkpoint bandwidth) so the desk prices training blocks honestly.
Until every gate and lifecycle operation above exists in the canonical runtime, this skill remains a fail-closed availability check and documentation handoff.