--dry-run it generates the verified target only in a bounded shadow workspace and reports a canonical plan/artifact diff. Without --dry-run it first inspects that target, creates a native Kopia snapshot plus an owner-signed executor-state recovery checkpoint, stages and verifies the rollback data without activating it, and only then installs and executes the exact target generate/apply/verify transaction. A failed target transaction can restore and verify the prior executor only before target Apply is admitted. After Apply, prior-runtime restart is blocked until verified prior-data activation exists; isolated Kopia staging alone does not authorize it. A completed target commit keeps its success proof for explicit finalization. Fresh upgrades require support in the embedded CUE Kit policy; recovery of an existing operation follows its signed journal and checkpoint.
Examples
