ci: build and publish docker images to ghcr.io from GitHub Actions master
Replaces the (now-removed) GitLab kaniko image builds with a GitHub Actions workflow that publishes to the free ghcr.io registry. Pushes on `next` and `v*` tags; pull requests build everything but skip the push, so the Dockerfiles stay validated without publishing. Images (all tags of ghcr.io/streamplace/streamplace): - :next / :<version> / :latest release image, multi-arch amd64+arm64 - :next-mistserver / ... MistServer companion, amd64 only (upstream MistServer is x86-64) - :bunny leak-test fixture image, amd64 - :builder / :builder-<sha> cross-compile toolchain, amd64 only (clang/llvm/aptly/winehq are x86-64), pullable for complex local builds The release/mistserver images bake in the streamplace binary that the workflow just cross-compiled (uploaded between jobs as an artifact) rather than curl-ing it from a package registry, so they have no external download dependency. New docker/*.ghcr.Dockerfile files do this; the existing release.Dockerfile/mistserver.Dockerfile are left untouched for the GitLab no-push follow-up. The release image only runs `streamplace self-test` on the native arch, skipping it under arm64 QEMU emulation. Auth is GITHUB_TOKEN (no secrets needed). Builds validated locally with podman. Caveats worth a look before relying on it: - builder image is large; cached to a dedicated ghcr registry tag. - the binaries job cross-compiles both arches in one runner — watch disk on ubuntu-latest (Maximize build space step frees ~25GB). - overlaps compile work with build.yaml; could later be merged. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>