System service running as the desktop user (already in docker group); starts
at boot, auto-restarts, auto-claims queued jobs. WorkingDirectory under $HOME
because snap Docker can't read build contexts outside home. README step 5 now
covers binary install, registration, and enabling the service.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Edge reverse proxy (TLS + label routing) and self-hosted Forgejo (git +
Actions + container registry) for joshbairstow.com, plus the desktop runner
config and the one-time bootstrap runbook.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>