On miss, resolve the tenant origin binding, compose the physical object id, and fetch with a per-tenant backend client whose credentials come from credential_ref. Fail closed on unknown/disabled/unbound tenants (no default fallback). Bound the per-tenant client count.
Part of #555. Design: #554.
🤖 Generated with Claude Code
On miss, resolve the tenant origin binding, compose the physical object id, and fetch with a per-tenant backend client whose credentials come from
credential_ref. Fail closed on unknown/disabled/unbound tenants (no default fallback). Bound the per-tenant client count.Part of #555. Design: #554.
🤖 Generated with Claude Code