Safety model
Read-only diagnostics establish the current state before any planned mutation. Plans include command shape, risk, rollback, and verification so the user can review the exact effect.
Auth hardening runs a compatibility preflight and recreates configured dynamic nodes. Storage reduction and upgrades preserve exact one-off node ports and stop if a required node definition is incomplete.
local_ydb_pull_status.progressPercent is monotonic layer-based progress: 0-99 while running, 100 after success, and the last value after an error. It is not byte progress.
Private config paths, SSH settings, password files, and database credentials stay in the local MCP client, shell, CI runner, or SSH target.