- .gitea/workflows/ci.yml: on every push/PR, run Django checks + the full
backend suite against MariaDB/Redis services and the frontend
lint/type-check/build. Runs on the nitro-ci runner (ubuntu-latest).
- .gitea/workflows/publish.yml: manual dispatch; multi-arch build+push of
both images as :latest and :<short-sha> with GIT_HASH baked in.
- push_*.sh: non-interactive registry login for CI (REGISTRY_USER/
REGISTRY_TOKEN) and a PLATFORMS override.