Explains the request lifecycle (Origin → Bearer → Caller → MCP), multi-issuer auth (static bearer / Authentik / k8s SA tokens per ADR-0011), the owner allowlist + caller-attribution footer, the single-service-PAT upstream client, the ~60 tools + input-hygiene layer, config, health, and the CI/CD + netpol-pilot deployment. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>