TLS-ALPN-01 needs 80/443 open to the whole internet for renewal, which fails
silently behind the user-IP firewall. Switch the letsencrypt resolver to
DNS-01 with the IONOS provider (token from host .env, git-ignored) and public
resolvers for the propagation check. acme.json is preserved; existing certs
renew via DNS-01 before 2026-10-28.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>