v4.0.0
Each connector can now declare what its producer promised to send, in schemas//v.yaml, loaded as an ordered registry. Fields are checked as they arrive rather than coerced, dotted paths like fields.region work, and the first violation wins.
Loading the registry refuses a breaking change between consecutive versions. A version may loosen what it accepts and never tighten it, so making a field required, narrowing a type, introducing an enum or dropping values from one, and introducing or lowering a max_length are all rejected, while dropping a field, relaxing required, widening integer to number, adding enum values and adding an optional field are accepted. conduit schema check prints the registry and exits 2 on a break.
There is a third queue per connector, conduit--quarantine, created by Terraform beside the work queue and the dead-letter queue. A payload that fails the schema or the mapping rules is moved there with a note recording the stage, field, reason and detail, instead of being acknowledged and dropped the way v2 did it. The dead-letter queue keeps its old meaning: deliveries the handler could not complete, replayed when the target is healthy again. Neither queue ever feeds the other.
conduit quarantine list shows what is set aside and why, and conduit quarantine redrive puts it back once the schema or the producer is fixed, keeping the idempotency key and clearing the note so a fixed task still lands exactly once. Redrive only moves what the queue held when it started, because a worker that still rejects the payload re-quarantines it inside the call.
conduit_rejected_total is replaced by conduit_quarantined_total with stage and reason labels, the worker stat rejected by quarantined, and DeliveryStatus.REJECTED by QUARANTINED. Tests are 159 unit and 23 LocalStack plus terraform, covering the compatibility rule in both directions, a bad payload quarantined rather than dead-lettered, a mapping failure carrying its own stage, and a quarantined message redriven and delivered after the fix.