fix(router): explicitly bind public Caddy sites to router.ip too master
Caddy groups vhosts into separate HTTP servers by their exact set of listen addresses. Private (diekvoss.net) sites bind 127.0.0.1/[::1]/ router.ip explicitly; public (toyvo.dev) sites only bound 0.0.0.0/[::]. Since a specific IP bind wins over the 0.0.0.0 wildcard for connections addressed to that exact IP, any request straight to router.ip with SNI for a public host (e.g. git.toyvo.dev) landed in the private server, which has no matching route, and Caddy answered 200 with an empty body. Traffic via Cloudflare hit the WAN IP instead, which only the public server's wildcard bind covers, so it worked - masking this for months. Add router.ip to the public listenAddresses so public sites are present in whichever server ends up owning that address.