Rework the installer so it doubles as an updater:
- Idempotent throughout: `install -d` for dirs, apt source lists rewritten
in place, `gpg --dearmor --yes`, fallback cert generated only if missing,
repo cloned or fast-forwarded, and `ln -sfn` symlinks.
- Config is now symlinked straight from the checked-out repo instead of
wget-ing raw files from GitHub. /etc/openresty/{nginx.conf,autossl.conf,
sites-enabled/000-proxy}, the targetinfo.lua lualib, and the systemd unit
all point at $REPO_DIR/ops, so an update is just `git pull` + reload with
no re-copying. This also drops the external t42-common raw-file
dependency (autossl.conf / proxy.conf now come from this repo).
- Validate `openresty -t` before reloading so a bad config can't take the
proxy down; reload if running else restart.
- Fix prior bugs: stray `curl sudo apt-get update`, duplicate openssl cert
line, and `cd ../nodejs` (now cd $REPO_DIR/nodejs). Require root; add a
BRANCH override (default master).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>