v2.0.0
Adds canary routing. POST /admin/canary sends a fixed share of live traffic to a candidate version, using a deterministic weighted split so a 5% weight really is every 20th request. The router keeps a rolling window of error rate and p95 inference latency per version and rolls the canary back on its own when the candidate exceeds the primary by the configured margin; a failing candidate answers from the primary for that request, so rollback happens with 0 dropped requests. 67 tests, load test with canary plus mid-run swap passes with 0 drops.