Read-only ActivityPub → atproto bridge for the threadiverse using Coves lexicons

chore(ops): schedule nightly Postgres backups with a systemd timer master

pg-backup.sh was documented as a cron job, but the production host has no cron daemon, so it never ran. Changes: - scripts/systemd/: tidepool-pg-backup service and timer (02:17 UTC) with retry on failure, running a root-owned copy in /usr/local/sbin rather than the git checkout. - scripts/pg-backup.sh: verify with a full pg_restore read (--list only reads the table of contents); a failed run keeps one fixed-name partial (mode 600) so retries do not pile up 2GB files; SIGTERM/SIGINT run the cleanup. - scripts/pg-restore-drill.sh: remove the drill container's anonymous volume, which otherwise left a full copy of production data on disk. - DEPLOY.md: systemd install steps in place of the cron line. - .dockerignore: exclude backups/; the root-only dumps broke the production image build with permission denied. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>