Which zone, domain and ingress are a mesh's facts, not the module's — so they are settings merged into a config file the mesh manages, read by fromEnv, rather than the empty env placeholders I wrongly baked in. The token stays the one own-secret. The module now describes a Cloudflare registrar; which zone is a setting, so the same description serves every mesh. Typechecks; manifest parses.