- Added Secure Link proxying over persistent multiplexed HTTP/2 relay lanes with mTLS identity forwarding and immutable relay grants.
- Added automatic migration and reconciliation of legacy Docker alias upstreams.
- Added route-level traffic telemetry including active streams, stream rate, bidirectional traffic, HTTP responses, upstream latency, and last activity.
- Added atomic Gateway-managed TLS bundle deployment, versioned certificate replicas, certificate inventory, legacy export, cleanup, and rollback-safe reloads.
- Improved tunnel lifecycle, retry and keepalive handling, stale session cleanup, bounded pooled reads, log tailing, and daemon upgrade recovery.
- Hardened relay grant validation, nginx configuration ownership, certificate identifiers, and failure fallback behavior.