The Docker Socket Proxy note raised the idea of gating socket access for future
monitoring/utility containers (Traefik-adjacent services) with least privilege.
Open decision: do we deploy it on the VPS? If yes, which API sections would the
first consumer need (e.g. EVENTS, read-only CONTAINERS)?