- Added production-ready Secure Links for Docker-backed proxy hosts, routing traffic through a multiplexed mTLS HTTP/2 relay without exposing Docker ports. - Added automatic migration of legacy Docker container aliases to Secure Links while preserving direct hosts, custom templates, template variables, cache, rate limits, headers, and URL rewrites. - Added adaptive relay admission with route-level fair sharing, reserved capacity for database traffic, hard pressure cutoffs, and configurable runtime parameters. - Added Relay and per-host Link Runtime monitoring with persisted snapshots, background and live refresh, traffic, reliability, latency, throttling, error, and resource-pressure metrics. - Added Gateway-managed TLS distribution with atomic versioned certificate deployment, inventory, legacy certificate migration, replica cleanup, and rollback-safe nginx reloads. - Added configurable per-IP request, burst, and concurrent connection limits to proxy templates, with defaults of 1000 requests/sec and burst 3000. - Added AI Workspace onboarding and interface selection, improved Assistant UX, operational alerts, and hardened AI runtime authorization. - Added shared GPU discovery and NVIDIA, AMD, and Intel GPU assignment support for Docker workloads. - Added SIEM audit export delivery, coordinated graceful shutdown, resilient restart and update screens, and expanded resource monitoring. - Improved managed database relay transport, Docker port mappings with explicit bind address and protocol, Redis 6 compatibility, sandbox recovery, and resource admission. - Hardened Gateway updates and migrations, nginx configuration validation, MFA and WebSocket boundaries, Docker archive and exec handling, webhook authentication, secret handling, audit logging, and ClickHouse credential isolation. - Fixed relay first-start identity races, restart notification propagation, stale dashboard relay alerts, and custom legacy template compatibility during Secure Link migration.