Replace manual nginx + SSL certificates with Caddy for automatic Let's Encrypt certificate management. Remove direct HTTP port exposure, route web traffic through Caddy (80/443) via Docker internal network. SSH remains on port 2222.