- .env.example lists the keys the scripts actually read (NAS_HOST/NAS_USER/
NAS_SSH_PORT/NAS_DEPLOY_PATH, web build args, Supabase access token and
project ref, CRON_SECRET, Cloudflare token/account/zone/tunnel) and drops
unused ones (DSM_HOST, NAS_DEPLOY_ROOT, NAS_ADMIN_PORT, NAS_LANDING_PORT,
APP_DOMAIN, ADMIN_DOMAIN).
- docs/map/02-infrastructure.md gains a credentials map (names only) with the
matching Forgejo/Supabase/NAS copies, plus the public routing summary.
- Deploy scripts no longer point to the removed /admin static page or portal.