v4.0.0: canary routing and outlier ejection
Routes can name a canary subset of replicas and a traffic weight; that share of requests is served by the subset, the rest avoids it, a header forces either side, and canary traffic falls back to the stable replicas when no canary can take it. Every replica keeps a window of recent outcomes, and after each health-check round a replica whose error rate or mean latency stands out from its peers is ejected for an escalating cool-down, never beyond half the pool and never when the whole service is failing alike. New metrics for canary requests, ejections and the ejected gauge; the chaos summary reports ejections. 101 tests.