## 1. Capacity Model - [x] 1.1 Add configuration validation for the 2 MiB remote baseline reservation and global active-assignment limit - [x] 1.2 Add and backfill persisted remote bundle reservation bytes in the runtime-safety schema - [x] 1.3 Charge persisted baseline bundle and projection bytes during remote admission while preserving local admission behavior - [x] 1.4 Enforce the global unresolved remote-assignment limit atomically with existing per-user quota ## 2. Actual-Size Expansion - [x] 2.1 Expand bundle capacity atomically to validated actual bytes before remote acceptance - [x] 2.2 Expand projection-job capacity atomically before append and defer without quarantine when capacity is unavailable - [x] 2.3 Update refunds, cleanup, quarantine, and reconciliation to use persisted charged bytes ## 3. Production Configuration - [x] 3.1 Configure a 2 MiB baseline, global limit 50, and keycheck capacity for 50 assignments - [x] 3.2 Update operator documentation with the distinct hard-limit, baseline-reservation, and backpressure semantics ## 4. Verification - [x] 4.1 Add unit and PostgreSQL integration coverage for baseline admission, global quota, bundle expansion, projection expansion, retries, migration, and reconciliation - [x] 4.2 Run targeted worker, pipeline, migration, and packaged-worker tests - [x] 4.3 Validate a bounded 50-assignment production candidate and reconcile capacity and pipeline debt before rollout