Part of #583. Depends on unknown-session protection and indexed inventory.
Problem
Retention exists internally but operators cannot safely preview or manually apply cleanup across large stores.
Acceptance criteria
- Extract one deterministic side-effect-free planner shared by automatic retention and manual cleanup.
- Dry-run is the default and returns family/kind/state, modified time, reason (
age/cap), estimated bytes where supported, and protected/live/unknown counts—never transcript content.
- Unknown is excluded by default; any inclusion is a separate explicit scope.
- Apply requires a confirmation token bound to the plan generation.
- Recheck ownership, kind, state, liveness, and lease immediately before each deletion.
- Sessions becoming live after planning are skipped.
- Partial failures are accurately reported and retryable.
- Existing sidecar-first/snapshot-last ordering remains.
- Unsupported backends report unsupported, not zero results.
- Execution is server-side; no unsafe offline deletion while a daemon may write.
Part of #583. Depends on unknown-session protection and indexed inventory.
Problem
Retention exists internally but operators cannot safely preview or manually apply cleanup across large stores.
Acceptance criteria
age/cap), estimated bytes where supported, and protected/live/unknown counts—never transcript content.