Adds a flyImage Nix output (backend + bundled web UI with an env-driven
startup config wrapper), a fly.toml with a persistent volume, and a deploy
README. Scanners are disabled and the API key comes from a Fly secret so
nothing sensitive is baked into the image. Also adds flyctl + skopeo to the
dev shell for daemon-less build/push.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>