## Why The platform has typed log and artifact routes, but restart recovery is incomplete: log acknowledgements and artifact transfer state are not durable, metrics are derived on demand, and backups and restricted remote adapters have no durable ownership/audit model. This change makes those existing channels operationally durable while preserving the control/job/log/artifact priority boundaries established by earlier changes. ## What Changes - Persist log stream batches, acknowledgement cursors, retention metadata, and bounded queries across Platform restarts; keep Run local spool files retryable and recoverable. - Persist artifact metadata, transfer sessions, chunk manifests, checksums, and content through a restart-safe bounded file-backed store; keep chunk retries idempotent and lower priority than logs/jobs/control. - Add bounded metrics samples and backup records with retention, size limits, recovery status, and audit events; expose only safe projections. - Add declaration-backed remote adapter requests for approved FTP/rsync/run-file/process/database/RCON operations with scoped targets, timeout/cancel/retry/fencing, and audit outcomes. No arbitrary shell, raw socket, unapproved host/credential, or bypass of Platform ownership/endpoint/session checks. - Add Platform and Run protocol/client/runtime contracts plus platform_web safe status projections and regression coverage. ## Capabilities ### New Capabilities - `durable-observability`: durable logs, artifacts, metrics, backups, retention, recovery, and safe query projections. - `scoped-remote-adapters`: declared and authorized remote adapter execution with bounded lifecycle and audit semantics. ### Modified Capabilities - `log-ingest-pipeline`: durable acknowledgement and restart recovery replace the earlier in-memory service assumption. - `artifact-transfer-channel`: transfer manifests and content survive restart and retain idempotent chunk/checksum behavior. ## Impact - Affects `platform/`, independent `run/`, and projection-only `platform_web/` contracts/views. - Adds dedicated domain, DTO, model, repository, service, protocol, validator, and runtime types; no Run source is copied into the main repository. - Does not implement dependency installation, Run self-update, client-manager lifecycle, plugin lifecycle, production scaling/alerts, or real third-party AI provider integration.