feat: add public isolation infrastructure (atcr.io, Tangled, Docker Compose)
Add CI pipeline step to push images to atcr.io public registry after
Gitea build. Add Tangled sync script that strips private paths
(.gitea/, scripts/, CLAUDE.md, service.json) and Tailscale hostnames
before force-pushing to the public mirror. Add Docker Compose template
for operator self-hosting.