Each workflow is copied under a cloud- prefix, runs from cloud/ through a
workflow-level defaults block, and resolves pnpm and the Node cache against
cloud/package.json and cloud/pnpm-lock.yaml. Display names are unchanged
because the recovery chain matches on them; every reusable call, gh dispatch,
and jq run-path check was repointed to the prefixed filenames.
Every job that can start on its own is gated on the repository variable
ORCA_CLOUD_OPERATIONS_ENABLED, so both scheduled triggers and every manual
dispatch skip without running a step until the owner enables them. Reusable
jobs inherit the caller's gate rather than restating it. A new contract test
pins the gate, the three chained display names, and the absence of any
repository secret other than the automatic token.