- Replaced the slim artifacts-only image with a full pi-base image (python + bun + rustup + natives + omp_rpc + omp shim).
- Moved robomp Dockerfile to repo root as Dockerfile.robomp, extending pi-base instead of copying from a scratch artifacts image.
- Renamed PI_ARTIFACTS_IMAGE to PI_BASE and updated all npm scripts and compose config accordingly.
- Split .dockerignore into per-Dockerfile shadows (Dockerfile.dockerignore, Dockerfile.robomp.dockerignore).
- Added `omp auth-gateway serve/token/status` — a forward-proxy injecting broker credentials for OpenAI Chat, Anthropic Messages, and OpenAI Responses wire formats.
- Added `GET /v1/usage` to auth-broker and auth-gateway; usage cache switched to 5-min per-credential TTL with jitter and last-good fallback on failure.
- Added `AuthStorage.setConfigApiKey/removeConfigApiKey/clearConfigApiKeys` so `models.yml` `apiKey` beats OAuth tokens without overriding `--api-key`.
- Added `omp auth-broker migrate --from-local` for idempotent upload of local SQLite/env credentials to the broker.