Address review feedback on PR #490:
- Add `restart: unless-stopped` to postgres-federated, valkey-federated,
step-ca services so they auto-recover after host reboot / docker restart.
- Update FED-M2-04 acceptance: must wire federation.tpl template into
mosaic-fed provisioner config AND include unit/integration test asserting
issued certs contain BOTH custom OIDs (grantId + subjectUserId). Carry-
forward guard from M2-02 review against silent OID stripping.