Durable store-and-forward
Once we acknowledge an image, we own delivering it.
- Seal-then-ack: every received instance is written to a durable, encrypted spool before the association is acknowledged
- A background drain forwards off the receiving association, so a slow or unreachable destination never blocks intake
- Restart-surviving retry with backoff — the spool and its queue outlive a service restart or a host reboot
- Dead-letter on exhaustion instead of silent loss: guaranteed delivery, never accept-and-drop