target/:
compiled/, manifest.json, and
streambuild_dag.json individually with atomic filesystem operations and rollback on publication
failure. The three owners are not exposed as one graph-atomic snapshot. Runtime artifacts under
target/run/ are preserved. Sensitive Kafka broker userinfo and source settings are redacted.
compile works in both modes and remains connection-free.
