gitea gains the package-registry provision: serves/receives/grants, an admin own-secret, a postgres-shaped build, and a provisioner that creates a gitea user per consumer with the mesh-minted password and seals nothing (hq ADR 0048). The builder takes its registry credential as an own-secret rather than a resolved provision, because gitea-as-module needs the base to build its provisioner and so cannot resolve before the base — a cycle the own-secret avoids. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx