feat: tenant configs, live signals, and automatic permission management
- infrasynth.configs: typed multi-tenant config store (registry, service,
secrets, cache) + public config_changed/config_reset signals and API
- emit the declared-but-dead signals (features flags/overrides, scheduler
task_completed/task_failed, tenancy tenant_updated, audit model_changed)
and per-model audit field exclusions
- security: permission catalog (security_permission), Django-style
model-derived AutoPermission, PermissionRegistry, RoleAssignment,
global-or-tenant Grant/Revoke, catalog API
- consolidate the permission surface: PermissionRegistry only (drop the
settings dict), IsAuthenticatedAndPermitted aliases HybridPermission,
require_permission replaced by required_permissions + require_all
- packaging: add [build-system]; add Forgejo publish workflow (.forgejo)