Add Tangled knot deployment with shared backup infrastructure
Deploy knot server at knot.sans-self.org with SSH ingress on port
2222, daily S3 backup cronjob, and TLS via cert-manager.
Refactor PDS backup to use a shared shell script driven by env vars,
eliminating duplication between PDS and knot backup jobs. Move S3
credentials to k8s/shared/ and generate per-namespace secrets from
the root kustomization.