feat(server): route Nextcloud via Cloudflare tunnel
Move Nextcloud from tailnet-only to public Cloudflare tunnel routing.
Adds Cloudflare IP ranges to Nextcloud trusted_proxies and updates
split-dns/caddy config to reflect the new architecture.
Also updates nixpkgs flake input (tailscale 1.96.5).
👾 Generated with [Letta Code](https://letta.com)
Co-Authored-By: Letta Code <noreply@letta.com>