Datastore schema migrations
The clean version-1 baseline owns one canonical metadata schema marker. Privileged Datastore creation bootstraps that schema through the libpq adapter.
Production clients do not receive direct migration, adoption, or reset authority. A database with missing, unexpected, or historical migration state fails preflight or startup. Repair it through a reviewed deployment migration, or provision a new configured Datastore and move governed data explicitly.
This keeps schema mutation behind Trusted-runtime authority and prevents user processes from recovering administrator credentials or direct database handles.