GET /retrieve/{cid} redirects only: every valid CID is looked up on
cid.contact. A PieceCID v2 302s to a storage provider's /piece/{cid} and
any other (payload) CID 302s to {provider}/ipfs/{cid}?format=car, in
each case the first provider advertising the matching transport with an https
address (404 when no such provider is indexed, 502 when the indexer is
unavailable). Nothing is fetched, proxied or served here.