Go SDK 0.10.1
Adds opt-in external-worker mTLS with persistent authentication selection, restart-safe renewal after lost responses, and separate server/workload certificate trust.
Existing bearer workers retain their default behavior. Commission the compatible control plane and dedicated runtime mTLS endpoint before enabling AGNT5_WORKER_MTLS_ENABLED=true; use a private persistent AGNT5_WORKER_SESSION_DIR.
Validated with the complete race-tested Go suite and pull-request CI. Production commissioning is separate from this SDK release.