- nginx: add strict ciphers+curves, keep TLS1.2/1.3 only - nginx: route /api,/admin to localhost:8100 - DOCS: mark applied/partial items and next steps