Nothing sits in storage without an owner, or a reason to ask.
Cocoapuff is governance for Walter: it answers the question neither Walter nor Peanut can answer on their own, who's actually publishing to storage, and what's sitting there that doesn't belong to anyone anymore.
A file store that just accepts uploads has no idea, on its own, which files are still needed and which are dead weight nobody remembers uploading. Multiplied across every app that publishes to it, that turns into exactly the kind of storage nobody trusts enough to clean up by hand. Cocoapuff turns "is anything still using this?" from a guess into an actual cross-referenced answer, without ever deleting anything itself.

Everything in storage, filterable, each item tagged with its ownership status.
Every registered publisher, each app allowed to claim files in storage, reports back what it still references: on a schedule, through a scoped API Cocoapuff can pull from, or, as a last resort for a system that can't do either, through tightly scoped direct access. Cocoapuff combines every publisher's claims into one set, and anything sitting in storage that isn't in that set becomes the orphan report. A file only counts as orphaned if no registered publisher claims it, not just the one app someone happened to check, so something only one obscure app still uses is correctly recognized as owned, not flagged as garbage because a different app's records don't know about it.

An orphaned asset: clearly labeled, one click from being managed or removed.
Nothing gets deleted automatically. The orphan report is a candidate list, not a verdict: a human reviews it before anything is removed, every time. The same collected claims also answer a question that didn't have one before, how much of storage each publisher actually accounts for.
Registering a new publisher isn't just bookkeeping. It's how an app gets both its storage credentials and protection from having its own files mistaken for garbage: the moment it's registered, its claims count toward the orphan calculation, and its own uploads stop looking abandoned just because nothing else knows about them yet.
What it does
- An orphan is a cross-system judgment: a file only counts as orphaned if no registered publisher claims it
- Three ways for a publisher to report in: a scheduled push, a scoped API, or tightly scoped direct access as a last resort
- A report, never an auto-delete: claims are compared against each other, and a human reviews before anything is removed
- Storage attribution for free: the same collected claims show how much of storage each publisher actually accounts for
- A searchable, thumbnail-grid Browse view of everything in storage, each item tagged with its ownership status
- Works with or without a cluster: the same orphan logic runs against one instance or an aggregated view across every shard
- Registering as a publisher is how an app gets its storage credentials in the first place, and protection from being flagged as garbage
