Replace pnpm-lock.yaml with package-lock.json. allowBuilds and
pnpm.onlyBuiltDependencies collapse into package.json#allowScripts, which npm
11 gates the same way; sharp is omitted because it is not in the tree.
cloudflare-worker/.github/workflows/ci.yml is updated for consistency even
though it never runs: GitHub only reads workflows from the repository root.
The three deployment variants now live in one repository: GitHub Actions
at the root, the Go daemon under self-hosted/, the Worker under
cloudflare-worker/. Update comparison tables, clone instructions, and the
Go module path (binary builds as 'self-hosted'); GHCR image name is
unchanged.
Comment out [triggers].crons in wrangler.toml — migrated this routine to
cron-job.org (free, verified) to keep the CF cron-trigger free-tier quota
available for other workers. Worker code, secrets, and observability
config stay intact so re-enabling is one toml uncomment + redeploy.
README restructured: lead with cron-job.org setup (signup → headers → JSON
body), demote CF Worker setup to a secondary path under "Using Cloudflare
Workers" for users who specifically want CF infra.