Forgejo registry unreachable from worker nodes (network isolation + host-to-ClusterIP routing gaps). Both management-service and queue-operator now ship from the same public GHCR image, with queue-operator selected via command override.
- Kafka 3-broker cluster (RF=3, min-ISR=2) - kmsvc SQS-like API on Kafka - Redis dedup (standalone, can extend to HA) - Temporal workflow orchestration (Cassandra backend)