Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
image to the SHA for idempotent rollbacks.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Mirror the pr_reviewer deployment pattern: Gitea Actions builds a multi-arch
image in the gitea-runner namespace, pushes to git.aridgwayweb.com, recreates
the steward namespace with regcred + env secret, and applies kube manifests.
Add .omo/ to .gitignore.
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)
Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>