feat(ops): production deployment stack for tdpl.io master
- docker-compose.prod.yml: postgres + migrate one-shot + server sharing one locally-built image, server gated on successful migration; joins the external coves-prod-network so the Coves Caddy can front tdpl.io. communities.yaml rides a DIRECTORY bind mount to dodge the single-file inode trap — git pull alone deploys follow-list changes. - /.well-known/tidepool-tls-ask: cert-issuance gate for on-demand TLS. Handle subdomains sit two labels below the apex where no single wildcard cert reaches; Caddy asks here per hostname and only resolvable bridged handles get certificates. - .env.prod.example documents the required secrets and the DNS-only wildcard requirement; repo-committed /deploy runbook with <PROD_HOST> placeholder (resolved from memory, never committed). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>