- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>