docs: add design spec Architecture plan the v1 implementation followed: verified upstream facts, schema, access matrix, remotesapi/auth design, browse subsystem, config + nginx wiring, phase breakdown, and the post-deploy verification script.