Feasibility registry

The compatibility matrix for RL-planner infeasibility: which infeasibility list belongs to which site and software versions, and which list each site is running. Mission Control pulls its CSV from here.

Every endpoint except /healthz requires Authorization: Bearer <token>. Tokens are per caller (CI, Fleet Config, Mission Control, site leads) and each only allows what that caller needs.

Environment: test. Mode: passive (consumers pull). Source and docs: the feasibility-matrix repo on GitLab.