Infrastructure-as-code for running lance.blue

Add the Terraform foundation: state bucket, prod root, network master

bootstrap/ creates the S3 bucket that holds environment state, keeping its own state on local disk because a bucket cannot store the state of its own creation. No DynamoDB table - Terraform 1.10 added S3-native locking and 1.11 deprecated the table, so `use_lockfile = true` is now the supported shape. Versioning is the actual recovery path and costs cents at these file sizes. modules/network is the no-NAT decision made concrete: public subnets across three AZs, an internet gateway, and the free S3 gateway endpoint. Private subnets are deliberately absent rather than present and empty. The default security group is emptied, since a default-open group that nothing references is still waiting for something to reference it. envs/prod composes modules and declares no resources of its own. The provider pins allowed_account_ids, so a wrong-profile apply fails before it plans rather than after it bills. Validated with `terraform validate` against 1.15.8 and AWS provider 6.57 - which checks HCL and required arguments, not whether AWS accepts the combination. Nothing has been planned against an account. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>