What changes vs private
- MicroVM isolation is required for any tenant-shared roost.
- Signed dispatch — every dispatch is signed by the gateway and verified by the roost before spawn.
- Scheduler-backed leases — re-scheduling on roost failure is authoritative, not advisory.
- Per-second metering — every grant emits a usage record for billing pipelines.
- Postgres coordinator — multi-replica gateways read from a shared coordinator.