Allow one server-audited onboarding polish request without credits and make the certificate gate temporarily reversible while preserving application authentication.
Enforce mTLS and least-privilege runtime boundaries while adding repeatable MySQL 8.4 and Docker smoke checks that require no production secrets.