- Added Secure Link proxying over persistent multiplexed HTTP/2 relay lanes with mTLS identity forwarding and immutable relay grants. - Added automatic migration and reconciliation of legacy Docker alias upstreams. - Added route-level traffic telemetry including active streams, stream rate, bidirectional traffic, HTTP responses, upstream latency, and last activity. - Added atomic Gateway-managed TLS bundle deployment, versioned certificate replicas, certificate inventory, legacy export, cleanup, and rollback-safe reloads. - Improved tunnel lifecycle, retry and keepalive handling, stale session cleanup, bounded pooled reads, log tailing, and daemon upgrade recovery. - Hardened relay grant validation, nginx configuration ownership, certificate identifiers, and failure fallback behavior.