Cri

Stackie’s CRI endpoint uses the official Kubernetes CRI v1 wire contract. Every RuntimeService and ImageService RPC is generated from the pinned upstream proto and delegated to a documented, injected capability. Image classification remains Mocker-owned; CRI lifecycle and observability remain plugin-owned; workload execution remains Stackied-owned. Unsupported optional capabilities return an explicit protocol status rather than false success.