Queue item (g) — same defect class as DC-111 defect 1, different writer: the caddy access-log tail named every event http.<status>, so forward_auth gate hits were unanswerable in the unified security event store. - resolveCaddyAction() mirrors audit-logger ACTION_MAP vocabulary for BOTH URI shapes (legacy /api/auth/gate/<id> from Caddyfile line 87, canonical /api/v1/... from dashboard JS): auth.credential-injection, auth.app-token-issue, auth.sso-exchange (exact-path match, boundary-tested) - severity escalation now covers the legacy /api/auth/ prefix too - metadata fidelity: caddy logs headers as ARRAYS — old single-value read always produced user_agent:null; added metadata.host (vhost) and duration_seconds (caddy logs seconds; duration_ms kept, no consumers) - dead-path visibility: once-per-process warn when the access log is missing. Live discovery: prod store has 45,912 events, 100% source_type 'api', ZERO 'caddy' — the container has no /var/log/caddy mount, so the worker silently no-ops. Infra wiring queued separately. - new __tests__/caddy-worker-naming-dc112.test.js: 22 pins (real tail + real store, hermetic sinks, both URI shapes, boundary rows, offset persistence, once-warn). Full suite 125/2831 green. Judge: GLM-5.3 cold read round-1 A (deleg_65498358, 3 polish items folded) + round-2 A (deleg_eed9dcbf, judge re-ran suite itself). URN urn:ump:mjbwfcw6z7budx45s2rutovw5fatpp4jyzzspo7tq6nzajayulmq