A4 — Install Forgejo on M1 + create repos (infra, portal, billing)
A3 — Deploy Caddy on M1 + automate Let's Encrypt for public services
A2 — Harden M1 OS: SSH key-only, firewall, audit
A1 — Create Nix Flakes repo & deploy-rs skeleton
A0 — Prep & inventory (machine specs, network, domains, SSH keys)