DL-319
The Compass native app is DUAL-MODE again: mode="embedded" returns as the low-friction onboarding / local-dev front door — the app spawns/supervises a LOCAL stack via rootless podman on the user’s own machine (macOS via podman machine, Linux native; Windows/WSL deferred) — ADDED ALONGSIDE the fully-surviving client mode, which stays first-class and is the RECOMMENDED steady-state for real self-host (always-on VPS/EC2 running compass-stack up, reached over TLS). Rationale is the trust model (DL-318): single-tenant operator-own-code needs no KVM isolation; podman is a permanent supported tier (microVM recommended where the host has KVM). Supersedes DL-235 (the “client is the ONLY mode” thesis — the exclusivity dies, the client surface survives whole) and the app-never-spawns half of DL-236 (whose standalone-compass-stack half stays Active and load-bearing); restores the dual-mode SHAPE of DL-106 by citation, and partial-supersedes DL-259’s KVM-floor clause by citation (funnel entry 2’s podman tier runs on a KVM-absent VPS)
Status: Active (Matt, 2026-09-01)