Deployment Guide
The full deployment guide — Docker (all-in-one image), bare-metal install,
the app_* env reference, backups, and the security notes (including why
LDAPS shouldn’t be port-forwarded to the internet) — lives in one place to
avoid two copies drifting out of sync:
See also Configuration for the config layer merge order, and LDAP for the directory layout and connecting a 3rd-party app.