One permanent mode, two system-state storage choices
The single-server quick start and installed single-server service both use permanent standalone. For a planned multi-server deployment, use cluster installation instead. A cluster's first bootstrap node is not a single-server product mode.
Default: authority on data drives. Metadata, WAL, identity, queues, and other system state use the fixed disk-journal quorum. The system/cache root is disposable. With D=0 there is only one journal copy; select independent drives and D>0 for redundancy.
Optional: one dedicated metadata drive. Add --metadata ABSOLUTE_EMPTY_DRIVE_PATH --acknowledge-no-metadata-redundancy during setup. This stores authoritative system state and WAL on exactly one drive. There is no metadata redundancy: losing that drive can make all objects unrecoverable even if their shards and snapshots survive. Data-drive tolerance does not protect this drive. The choice cannot be changed by editing cached configuration.
Permanent standalone uses --deployment-mode standalone, an explicit disk-failure tolerance, and a protected journal membership. It cannot enroll another server or convert to distributed mode. Existing distributed installations must not be converted by editing configuration; use a separately planned export/reset/recreate/import workflow if changing format.
External KMS availability, encryption keys, backups, and object-shard survival remain separate responsibilities in both formats.