v1.2.4
Adds the 's3_backup_agents' => 'backup' entry to AGENT_TABLES so backup.agent's NATS connections resolve through the same generic auth-callout lookup/grant logic every other agent type already uses — no new code path, just one more table in the map.