Missed-event recovery plan
- Reproduce dropped NATS events on disposable SQL/NATS/Aeron fixture and retain evidence.
- Strengthen archive continuity checks and add stable-boundary recovery export using production serializers. Preserve migration export.
- Add bounded local peer call, operator recovery service/controller and additive checkpoint migration. Preflight all historical identity/economics before writes; transaction covers source-order application, derived positions and checkpoint.
- Add SQL rollback/retry/conflict/isolation controls and real service/transport outage fixture. Regenerate YU18 sequentially and verify last-wins parity.
- Record executable proof/evidence hashes and honest limits; commit owned paths and hand off.
YU18 owns operative ClusterRecon, ClusterNodeMain, TradeService, registry and order projection overrides. Earlier same-basename layers remain unchanged. No state-root generation inputs are placed under components. No NATS configuration-only fix: Core NATS cannot replay publisher-side loss. Existing frozen migration witness requires a permanently frozen source, so the additive endpoint brackets replay with stable applied state and uses identical archive source.