Records the decisions the milestone plan already made, with their costs stated rather
than only their benefits:
- 0001 e2ee-trust-model: key hierarchy, the AAD-to-row binding that stops the server
moving ciphertext between rows, and the four-layer public-key trust story. States
plainly that revocation is not retroactive, that Connect cannot be a security
boundary, and that the IdP becomes a key-distribution trust root.
- 0002 minimal-apis: feature modules with explicit registration; capability negotiation
instead of Asp.Versioning, since client and server upgrade independently when
self-hosted.
- 0003 sync-protocol: single write path, revision cursors, and the bigserial
pre-commit sequence gap that silently corrupts sync — plus the per-vault advisory
lock that fixes it and the test that must prove it.
- 0004 relay-authorization: relay forwards bytes rather than terminating SSH, so
zero-knowledge survives; server-resolved target IPs in the ticket to defeat DNS
rebinding; why host addresses must be plaintext when relay is enabled.
- 0005 no-application-layer: why the usual Application/mediator layer earns nothing
here, with the trigger that would make us revisit it.
- 0006 observability-stack: OTel plus built-in ILogger; liveness excludes dependencies
so a database blip cannot restart the container and kill live SSH sessions.
Also adds a README covering layout, build, enforced conventions and milestones.