Point rss to the Hetzner box and reverse-proxy/SNI-passthrough back to
the home cluster so cert-manager keeps owning the certificate. Move
stalwart's HTTPS listener to 127.0.0.1:8443 so nginx can take :443 and
dispatch by SNI.
- Add LDAP directory backend in Stalwart pointing to ldap.rubenhensen.nl
- Expose Authentik LDAP outpost externally via LoadBalancer service
- Add ldap.rubenhensen.nl DNS record