CRI persistence and recovery

Stackie persists pod sandboxes, containers, image references, CNI allocations, process start identities, events, stream tokens, idempotency keys, failed bundles, caches, and persistent-volume sentinels in the CRI plugin’s own data namespace. Forward-only migrations are atomic. Daemon restart reconciliation validates actual state before changing it, while entitlement loss, reset, and uninstall preserve persistent volumes.