Skip to main content

max / makenotwork

8.7 KB · 221 lines History Blame Raw
1 //! SyncKit developer billing: pricing formula and constants.
2 //!
3 //! Two modes:
4 //!
5 //! bulk, price = storage_gb_cap × $0.03
6 //! per_key, price = key_cap × gb_per_key × $0.03
7 //!
8 //! Both are pure GB-based pricing. Egress and ingress are absorbed by the
9 //! storage rate's margin against Hetzner Object Storage (~$0.0065/GB), where
10 //! SyncKit blobs are hosted in the `synckit` bucket.
11 //!
12 //! Invoices are floored at a Stripe-fee-cover threshold so we never lose money
13 //! on a transaction. See `BASE_FLOOR_CENTS` for the math.
14
15 /// Storage rate in cents per GB per month. Runs ~4.6× the Hetzner Object
16 /// Storage cost behind it (€5.99/TB/month, ~$0.0065/GB at 1.09 USD/EUR, with
17 /// 1 TB of egress included per TB stored). That spread absorbs any
18 /// ingress/egress variance, so we don't need a separate egress price. See
19 /// `mnw-biz-synckit-pricing` in the wiki.
20 pub const STORAGE_RATE_CENTS_PER_GB: i64 = 3;
21
22 /// Upper bound on a developer-billing storage cap, in GB. Applies to the bulk
23 /// `storage_gb_cap` and to the `key_cap × gb_per_key` product in per_key mode.
24 /// 10 TiB, matches the end-user `MAX_CAP_BYTES` and the picker slider's `max`.
25 /// Without it, `validate_knobs` would accept any value `> 0` and a developer
26 /// could provision a Stripe subscription priced in the billions per month.
27 pub const MAX_STORAGE_GB: i64 = 10 * 1024;
28
29 /// Stripe-fee-cover floor in cents. Stripe charges 2.9% + $0.30 per
30 /// successful charge. We pick the smallest invoice `F` (cents) such that the
31 /// remainder after Stripe fees is non-negative:
32 ///
33 /// F × (1 − 0.029) − 30 ≥ 0 ⇒ F ≥ 30 / 0.971 ⇒ F ≥ 30.9¢
34 ///
35 /// Round up to 31¢. At the floor, MNW nets ~$0, covered, not profitable.
36 pub const BASE_FLOOR_CENTS: i64 = 31;
37
38 /// Warning thresholds (percent of storage cap). Matches CHECK constraint on
39 /// `sync_app_usage_current.last_warning_pct`. Only storage is enforced, so
40 /// these thresholds apply to storage usage only.
41 pub const WARNING_THRESHOLDS_PCT: &[i16] = &[75, 90, 100];
42
43 /// Compute the monthly Stripe invoice amount in cents for a given knob set.
44 ///
45 /// In bulk mode: `storage_gb_cap` is set, others are `None`.
46 /// In per_key mode: `key_cap` and `gb_per_key` are set, `storage_gb_cap` is `None`.
47 ///
48 /// Floors at `BASE_FLOOR_CENTS` so we never invoice below the Stripe-fee
49 /// break-even amount.
50 pub fn monthly_price_cents(
51 enforcement_mode: crate::db::SyncEnforcementMode,
52 storage_gb_cap: Option<u32>,
53 key_cap: Option<u32>,
54 gb_per_key: Option<u32>,
55 ) -> i64 {
56 use crate::db::SyncEnforcementMode::{Bulk, PerKey};
57 // Pure integer-cents arithmetic. The rate is a whole number of cents and
58 // the caps are whole GB, so there is no fractional money to round; the old
59 // `(gb as f64 * 3.0).ceil()` was an unnecessary trip through f64. Saturating
60 // multiplies keep absurd admin-set caps from overflowing i64 instead of
61 // wrapping to a negative invoice. The match is exhaustive over the sealed
62 // enum, there is no unknown-mode arm that could silently price at the floor
63 // (Pay-S2); an invalid mode can't reach here because the column is
64 // CHECK-constrained and the type is parsed at the API boundary.
65 let gb: i64 = match enforcement_mode {
66 Bulk => i64::from(storage_gb_cap.unwrap_or(0)),
67 PerKey => {
68 let k = i64::from(key_cap.unwrap_or(0));
69 let g = i64::from(gb_per_key.unwrap_or(0));
70 k.saturating_mul(g)
71 }
72 };
73 let raw = gb.saturating_mul(STORAGE_RATE_CENTS_PER_GB);
74 raw.max(BASE_FLOOR_CENTS)
75 }
76
77 /// Storage cap in bytes for the given GB cap.
78 pub fn storage_cap_bytes(storage_gb: u32) -> i64 {
79 i64::from(storage_gb) * 1024 * 1024 * 1024
80 }
81
82 #[cfg(test)]
83 mod tests {
84 use super::*;
85 use crate::db::SyncEnforcementMode::{Bulk, PerKey};
86
87 // `validate_knobs`' bound tests in `routes/synckit/billing.rs` are written
88 // against the constant itself, so they hold whatever it says. Pin the value
89 // once, against the end-user cap it is documented to match: the two ceilings
90 // drifting apart is the failure that would otherwise be invisible.
91 #[test]
92 fn developer_storage_ceiling_matches_the_end_user_one() {
93 assert_eq!(MAX_STORAGE_GB, 10 * 1024, "10 TiB, in GiB");
94 assert_eq!(
95 MAX_STORAGE_GB * 1024 * 1024 * 1024,
96 crate::payments::synckit_app_pricing::MAX_CAP_BYTES,
97 );
98 }
99
100 #[test]
101 fn bulk_mode_pricing() {
102 // 100 GB bulk → 100 × 3 = 300 cents.
103 assert_eq!(monthly_price_cents(Bulk, Some(100), None, None), 300);
104 // 1000 GB → $30.
105 assert_eq!(monthly_price_cents(Bulk, Some(1000), None, None), 3000);
106 }
107
108 #[test]
109 fn per_key_mode_pricing() {
110 // 50 keys × 2 GB = 100 GB equivalent → 300 cents. Matches 100 GB bulk.
111 assert_eq!(monthly_price_cents(PerKey, None, Some(50), Some(2)), 300);
112 // 1000 keys × 1 GB → $30.
113 assert_eq!(monthly_price_cents(PerKey, None, Some(1000), Some(1)), 3000);
114 }
115
116 #[test]
117 fn floor_kicks_in_for_small_accounts() {
118 // 1 GB bulk → 3¢ raw, floored to 31¢.
119 assert_eq!(monthly_price_cents(Bulk, Some(1), None, None), 31);
120 // 10 GB → 30¢, also floored to 31¢ (one cent short).
121 assert_eq!(monthly_price_cents(Bulk, Some(10), None, None), 31);
122 // 11 GB → 33¢, above floor.
123 assert_eq!(monthly_price_cents(Bulk, Some(11), None, None), 33);
124 // 1 key × 1 GB → 3¢ raw, floored.
125 assert_eq!(monthly_price_cents(PerKey, None, Some(1), Some(1)), 31);
126 }
127
128 #[test]
129 fn heavy_workload_pricing() {
130 // 10 TB bulk → 10240 × 3 = 30720¢ = $307.20.
131 assert_eq!(monthly_price_cents(Bulk, Some(10_240), None, None), 30_720);
132 // 10k keys × 1 GB → same.
133 assert_eq!(
134 monthly_price_cents(PerKey, None, Some(10_000), Some(1)),
135 30_000
136 );
137 }
138
139 #[test]
140 fn missing_knobs_drop_to_floor() {
141 // Mode is set but no knobs provided, should hit the floor.
142 assert_eq!(
143 monthly_price_cents(Bulk, None, None, None),
144 BASE_FLOOR_CENTS
145 );
146 assert_eq!(
147 monthly_price_cents(PerKey, None, None, None),
148 BASE_FLOOR_CENTS
149 );
150 }
151
152 // (The former `unknown_mode_drops_to_floor` test is gone: `enforcement_mode`
153 // is now a sealed enum, so an unrecognized mode is unrepresentable, the
154 // Pay-S2 fail-open it guarded against can no longer be written.)
155
156 #[test]
157 fn floor_amount_covers_stripe_fee() {
158 // 31¢ × 0.971 = 30.10¢, minus 30¢ fixed fee = 0.10¢ net. Verifies the
159 // documented math: the floor covers Stripe's fee with ~0 margin.
160 let net = (BASE_FLOOR_CENTS as f64) * 0.971 - 30.0;
161 assert!(
162 net >= 0.0,
163 "floor must net ≥ 0 after Stripe fees, got {net}"
164 );
165 assert!(net < 1.0, "floor should be tight, not overshoot, got {net}");
166 }
167
168 #[test]
169 fn storage_cap_in_bytes() {
170 assert_eq!(storage_cap_bytes(10), 10 * 1024 * 1024 * 1024);
171 }
172
173 // ── Edge cases (test-fuzz) ──
174
175 #[test]
176 fn pricing_at_u32_max_does_not_panic() {
177 // u32::MAX GB × 3¢ ≈ 1.3e10 cents, fits in i64. The cast must not panic.
178 let p = monthly_price_cents(Bulk, Some(u32::MAX), None, None);
179 assert!(p > 0, "huge price should be positive, got {p}");
180 }
181
182 #[test]
183 fn per_key_pricing_at_u32_max_saturates_cleanly() {
184 // u32::MAX × u32::MAX overflows f64 precision but Rust's f64-as-i64 cast
185 // saturates at i64::MAX rather than UB. Must not panic.
186 let p = monthly_price_cents(PerKey, None, Some(u32::MAX), Some(u32::MAX));
187 assert!(p > 0, "saturated price should still be positive, got {p}");
188 }
189
190 #[test]
191 fn storage_cap_at_u32_max_fits_in_i64() {
192 // u32::MAX × 2^30 = ~4.6e18, well under i64::MAX (~9.2e18).
193 let bytes = storage_cap_bytes(u32::MAX);
194 assert!(bytes > 0, "u32::MAX GB should produce a positive i64");
195 assert_eq!(bytes, (u32::MAX as i64) * 1024 * 1024 * 1024);
196 }
197
198 #[test]
199 fn bulk_with_zero_gb_drops_to_floor() {
200 // Defensive: validate_knobs rejects gb=0 at the route layer, but the
201 // pure function should still produce the floor rather than 0.
202 assert_eq!(
203 monthly_price_cents(Bulk, Some(0), None, None),
204 BASE_FLOOR_CENTS
205 );
206 }
207
208 #[test]
209 fn per_key_one_dimension_zero_drops_to_floor() {
210 // If only one of key_cap/gb_per_key is 0, the product is 0 → floor.
211 assert_eq!(
212 monthly_price_cents(PerKey, None, Some(0), Some(10)),
213 BASE_FLOOR_CENTS
214 );
215 assert_eq!(
216 monthly_price_cents(PerKey, None, Some(10), Some(0)),
217 BASE_FLOOR_CENTS
218 );
219 }
220 }
221